Blog
Email Spoofing Only Works When the Easy Things Aren't Done
Someone sending email as your company is usually preventable with three free DNS records. If those aren't set up correctly, it's worth asking what else isn't.
A client calls. They just got an invoice from your accounting email with new bank details, and they want to know if it's legitimate. It isn't. Nobody logged into your email. Someone simply put your address in the "from" line, and the receiving server believed it.
That's email spoofing, and here's the uncomfortable part: when it happens using your exact domain, it's almost always because a few basic settings were never configured correctly.
How spoofing works
Email was designed decades ago without any built-in way to prove who sent a message. Anyone can type any address into the "from" line. To tell real email from fake, receiving servers rely on the sending domain to publish rules about which email is legitimate. If your domain doesn't publish those rules, the receiving server is left to guess.
The three records that stop it
SPF lists the services allowed to send email for your domain. DKIM adds a digital signature so receivers can confirm a message really came from you and wasn't changed. DMARC tells receiving servers what to do with email that fails those checks, and sends you reports about who is using your domain.
The part that matters most is DMARC enforcement. With DMARC set to quarantine or reject, receiving servers are instructed to stop email that fails the checks. With no DMARC record, or one set to "none," they're only watching.
These are DNS records, and they cost nothing to publish. Setting them up correctly takes some planning, because you need to know every service that sends email on your behalf (your email platform, your billing system, your newsletter tool). But it isn't advanced security work.
You can see where your domain stands in about 30 seconds with our free Email Security Check.
If the easy things aren't right, the hard things aren't either
This is the part worth sitting with. SPF, DKIM, and DMARC are among the cheapest and most visible security controls a business can have. Anyone in the world can look them up in seconds, including your insurer, your clients, and attackers looking for an easy target.
The controls that do most of the real protecting are harder and invisible from the outside: multifactor authentication on every account, backups that are actually tested, patching that happens on schedule, endpoint protection, and accounts that get shut off the day someone leaves.
If whoever manages your IT didn't get the free, public, easy-to-check items right, it's reasonable to assume the harder, hidden ones deserve a closer look too. It isn't proof of anything. It's a signal, and a useful one. It's also why email security is the first of the six control areas in our security baseline.
Spoofing, business email compromise, and what records don't stop
Business email compromise is the broader term for fraud carried out through email, most often fake invoices and redirected payments. Spoofing your exact domain is one way it happens, and it's the one these records stop. Two others need different controls.
Lookalike domains. An attacker registers a domain that's one letter off from yours and sends from that. Your records protect your domain, not someone else's. The defenses here are external sender tagging, trained staff, and a firm rule that any change to payment details gets verified by phone.
Account compromise. An attacker steals a real password and sends from your actual mailbox. That email passes every check, because it really did come from you. The defenses here are multifactor authentication and monitoring for suspicious sign-ins and mailbox rules.
A well-run environment covers all three. The records are the floor, not the whole building.
If a client got a fake email from you
Tell them not to act on it, and confirm anything involving money by phone, using a number you already have rather than one from the email.
Ask for a copy of the message with its full headers. Their IT contact can forward it. The headers show whether it was spoofed or actually sent from your account.
If it came from your real account, treat it as a compromise: reset the password, confirm multifactor authentication is on, check for forwarding rules and inbox rules you didn't create, and review recent sign-ins. Our guide on what to do after a data breach walks through next steps.
If it was spoofed, check your records and move your DMARC policy toward enforcement.
If any money moved, contact the bank immediately, file a report with the FBI's Internet Crime Complaint Center at ic3.gov, and notify your cyber insurer.
Check your domain
It takes about 30 seconds and only looks at public records. You'll see your grade on screen, and we'll email you the full report with plain-English explanations and fixes for your email platform. Run the free Email Security Check.
Common questions
Questions leadership usually asks first.
Continue reading
Related reading.
Free Email Security Check
See how well your domain is protected in about 30 seconds.
Read more: Free Email Security CheckStandards and security baseline
The non-negotiable controls every supported environment is held to.
Read more: Standards and security baselineMicrosoft 365 security gaps
The settings most businesses never turn on.
Read more: Microsoft 365 security gapsCyber insurance IT requirements
What underwriters expect to see in your environment.
Read more: Cyber insurance IT requirementsNext step
Get a clearer view of your IT environment.
If your domain's grade surprised you, or you'd like a second opinion on the harder controls behind it, schedule an IT Environment Review.
