Security

Stop Scammers Sending Emails as Your Business

email security phishing

Someone Could Be Sending Emails as Your Business Right Now

Without any special tools, a scammer can put your domain in the From field, paste in your logo, and send one of your clients an email asking them to pay a fake invoice or update their banking details. The receiving mail server has no automatic way to know the message didn’t come from you.

This is called email spoofing, and it’s one of the most common starting points for business email compromise fraud in Australia. The ACSC flags it regularly in its annual cyber threat reports, and it’s directly relevant to your obligations under the Privacy Act and Notifiable Data Breaches scheme — because when a scammer impersonates your domain to defraud a client, that can quickly become your problem too.

The fix involves three DNS records. Most businesses have one or two of them in place. That’s usually enough of a gap for a spoofed email to get through.

The Three Records That Prove an Email Really Came from You

These records live in your domain’s DNS settings. You configure them once, and receiving mail servers check them on every message you send.

SPF — Who’s Allowed to Send on Your Behalf

SPF publishes a list of the mail servers authorised to send email for your domain. When a receiving server gets a message claiming to be from you, it checks whether the sending server is on that list. If it isn’t, SPF flags it.

DKIM — A Tamper-Proof Signature on Every Message

DKIM adds a cryptographic signature to your outgoing email. The receiving server uses a public key stored in your DNS to verify two things: the message genuinely came from your domain, and nothing was altered in transit. Microsoft 365 supports DKIM natively — it just needs to be enabled and configured for your domain.

DMARC — The Record That Actually Enforces the Rules

DMARC ties SPF and DKIM together and tells receiving servers what to do when a message fails authentication. It also checks that the domain visible in the From address matches what SPF and DKIM verified — which is what stops someone forging your exact address. As a bonus, it sends you reports showing every source sending email as your domain, including the ones that shouldn’t be.

The DMARC Setting Most Businesses Get Wrong

DMARC has three policy options, and this is where a lot of businesses stall:

  • p=none — monitors and sends reports, but does nothing to block spoofed messages
  • p=quarantine — sends failing messages to the recipient’s junk folder
  • p=reject — blocks failing messages before they’re delivered

Many businesses set up DMARC at p=none, get reports for a while, and never move past it. At p=none, your domain is still wide open to spoofing. Real protection only begins at quarantine or reject.

Microsoft’s own guidance recommends working toward p=reject once you’ve confirmed your legitimate mail is passing authentication — which is why the rollout is done in stages, not all at once.

What These Records Won’t Stop

It’s worth being clear about the limits. SPF, DKIM, and DMARC protect your actual domain. They don’t protect against:

  • Lookalike domains — a scammer registers something like yourcompany-invoices.com.au and sends from that
  • Display-name spoofing — the From name reads “Accounts Team” but the actual address is a random Gmail account

For those, staff habits matter: always check the full email address, not just the display name, and verify any request to change payment details by calling a known number — not one provided in the email.

How to Check Where Your Domain Stands

Several free SPF and DMARC lookup tools let you type in your domain and see which records are present. That’s a useful starting point, though it won’t tell you whether the records are configured correctly.

The proper rollout looks like this:

  1. Publish SPF and DKIM covering all your legitimate sending sources (including Microsoft 365, any marketing platforms, and line-of-business apps)
  2. Add DMARC at p=none and review the reports
  3. Move to p=quarantine, then p=reject, once your legitimate mail is consistently passing

Skipping straight to p=reject without checking first is what causes businesses to accidentally block their own emails.

Get Your Email Authentication Right

If you’re not sure whether your domain is properly protected — or you’ve had DMARC sitting at p=none for longer than you’d like to admit — we can help you sort it out properly.

Talk to The IT TechNinjas about getting SPF, DKIM, and DMARC configured correctly, or find out whether your business is ready to scale securely with our Safe to Scale assessment.

Ready to scale safely?

Book a discovery call and we'll map out where you stand and what comes next.