---
title: "Email Impersonation"
slug: "email-impersonation"
updated: 2026-06-09T03:02:29Z
published: 2026-06-09T03:02:29Z
canonical: "help.silentpush.com/email-impersonation"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.silentpush.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Email Impersonation

## Email Impersonation Query

The Email Impersonation query detects domains that target organizations via MX (Mail Exchange) record manipulation, in which attackers disguise malicious emails as originating from legitimate mail servers.

### Execute an Email Impersonation Query

1. 
  1. From the navigation menu, select **Reconnaissance > Email Impersonation**.
2. Enter a domain name in the **Domain Name** box (wildcards are not supported).
3. (Optional) Click **Save** to store the query for future use.
4. Click **Search**.

### Understand Email Impersonation Results

Results are displayed in an Explore table with the following columns:

- **Query**: Domain the result pertains to.
- **Risk Score**: Silent Push Risk Score.
- **Answer**: MX record.
- **First Seen**: Date and time the MX record was first observed.
- **Last Seen**: Date and time the MX record was last observed.
- **MX Hash**: Hash value of the MX record.
- **MX Server Density**: Density of the MX server.
- **WHOIS Created Date**: Domain creation date.
- **WHOIS Registrar**: Registrar of the domain.

### Monitor and Save Results

#### **Monitoring**

Click **Monitor** on the results screen, enter a **Monitor name** and **Description**, then click **Save** to receive daily email alerts.

#### Save to a Feed

1. Left-click one or multiple results.
2. Select Save to in the top-right of the results screen.
3. Use the contextual menu to save to an existing or new collection/feed.

##
