Someone Is Sending Emails Pretending to Be Your Business. Here's What's Going On.
It usually starts with a phone call. A customer, or a vendor, or a total stranger asks about an email you never sent. Maybe it's an invoice with someone else's bank details. Maybe it's a "past due" notice. Maybe it's obvious junk with your company name on it. And the first question everyone asks is the same one:
Were we hacked?
Maybe. But in most of these cases, no. Understanding the difference is the whole game, because the two problems have completely different fixes.
Spoofing vs. a compromised account
Spoofing means someone is forging your email address from the outside. They never touched your systems. Email's underlying design, which dates to a more trusting era, allows a sender to write any "from" address they want, the same way anyone can write your return address on an envelope. If your domain hasn't told the world how to check for forgeries, receiving mail systems have limited grounds to reject the fakes.
A compromised account means someone is actually inside a mailbox, sending from the real thing. This is far more serious: they can read mail, watch invoice conversations, and time their fraud.
A few minutes of looking tells you which one you have. Signs that point to compromise rather than spoofing: the fake emails appear in your own Sent folder, replies come back to your real mailbox, recipients include people from your actual contact list, or there are sign-ins you don't recognize. Signs that point to spoofing: the emails exist only on the recipients' side, and the recipients are strangers or scattershot lists.
If it's a compromised account, move now
This is the drop-everything version. Change the account password immediately, sign out every active session, turn on multi-factor authentication if it wasn't on, and check the mailbox rules, because attackers routinely add a hidden rule that forwards or deletes mail to cover their tracks. Then look at what the account had access to, because the mailbox is often the beachhead rather than the target. If invoices or payment details flowed through that mailbox, the people on the other end of those conversations need a phone call, today, before someone wires money to a fraudster's account.
If any of that paragraph felt over your head, this is a moment to get help the same day, not the same month.
If it's spoofing, the fix is three DNS records
Your domain can publish rules that tell the world's mail systems which senders are legitimate and what to do with forgeries. Three records work together:
- SPF lists which servers may send mail for your domain
- DKIM puts a tamper-evident signature on legitimate messages
- DMARC ties them together and, critically, tells receiving systems what to do with mail that fails: let it through anyway, quarantine it, or reject it outright
Here's the part most businesses miss. Having the records isn't the same as having them do anything. A large share of small-business domains either have no DMARC record at all or have one set to "monitor only," which observes forgeries and blocks nothing. We see this constantly when we check local businesses: the paperwork half-exists and the enforcement is off. Until DMARC is set to quarantine or reject, the spoofing you just discovered continues, and there's nothing stopping the next round.
Enforcement isn't a switch you flip blind, though. Turn on "reject" without checking what legitimately sends as your domain, your newsletter tool, your accounting software, your scanner, and you'll block your own mail. The right sequence is: inventory what really sends for you, get SPF and DKIM correct for each, watch the reports DMARC sends back, then step enforcement up.
Check where you stand in about a minute
We built a free tool that grades any domain's email authentication: whether SPF, DKIM, and DMARC exist, and whether they're actually enforcing anything. No signup, no email required. Run your own domain through it, or run the domain from a suspicious email you received.
Check your domain at tools.tech360solutions.com.
If your grade comes back poor and you'd rather have the records fixed by someone who does this routinely, that's often a small, one-time project. Book a 15-minute review and we'll go over what your domain needs.
Tech 360 Solutions provides managed IT and cybersecurity for small businesses in the Kansas City metro. Built for HIPAA, FTC Safeguards, and other regulated environments.