{"success":true,"data":{"id":"reply-to-differs-from-from-domain","label":"Reply-To / From domain mismatch","description":"The Reply-To header uses a root domain different from the From address, a technique phishers use to intercept credential replies while the displayed sender appears legitimate — Proofpoint TAP 2026 found this pattern in 41% of spear-phishing campaigns; bulk ESP domains are excluded to prevent false positives on mailing list software.","tier":"danger","category":"header","isThin":false}}