Overview
Brand impersonation is dressing a message up as a company it does not come from. Sometimes that is outright spoofing of the company's address. More often it is subtler, and built to survive a quick glance.
How attackers abuse it
The two workhorse tricks are the display name and the look-alike domain (the domain is the part of an address after the @). A display name that says “PayPal” can sit on top of any address at all, because the name is free text. A look-alike domain swaps a letter or adds a word, close enough that “yourbank-secure.com” reads as your bank when you are moving fast.
Both tricks aim at the same blind spot: people read names, not domains. The message borrows a brand's trust to set up a phishing ask.
Evidence, not proof
Authentication helps here, but as evidence rather than proof. Mail that genuinely comes from a company usually passes that company's own checks, and a look-alike domain cannot borrow them. The reverse is not absolute: legitimate mail sometimes fails its checks, and an attacker can send perfectly authenticated mail from a domain they control or from a real account they have compromised.
What makes impersonation stand out is the mismatch. A message that claims a brand while the domain behind it has no connection to that brand is one of the clearest warning signs in email.
Passing authentication is evidence a brand is real, not proof. A look-alike domain cannot borrow it, but a compromised real account can still pass every check.
What Sieve shows you
When a message is filed as Malicious because it claims a brand the sender cannot back up, your dashboard shows that reason in this page's vocabulary. The message sits under a label in your Gmail, never deleted, so you can always inspect it yourself.
If the flag is wrong, drag the message back to your inbox or restore it from the dashboard. One correction restores the message and teaches your own filter about that sender.