Okay; with all that test architecture in place, let's go back to our attack scenario. If you recall, Mark received an email from his friend Jim, making him aware of a sale going on at http://www.ems.com/.
When Mark clicked on the link in the email, he seemingly got directed to EMS.com, or did he? When you hover over the link, you can see the actual URL the link will send you to.
Here, it shows the actual URL Mark is directed to is http://www.ems.net/climb. When his browser resolved the website, the following is what showed ...