Osato Umweni · Blog

How a fraudster sends an invoice that looks like it came from you

A supplier emails a client with an invoice, as they have done a dozen times before. Three days later, someone from the client's finance team writes back to confirm the payment has gone out. The supplier never sent a follow-up. There was no follow-up to send. Somewhere in the middle of that thread, a message arrived that looked exactly like it came from the supplier, told finance the bank details had changed, and gave them a new account number.

The money is gone within the hour, usually to an account that is emptied and closed the same day. Nobody hacked a laptop. Nobody guessed a password. The fraud worked because the email looked like it came from a domain the finance team already trusted.

Two ways to fake a sender

There are two different tricks here and small business owners usually only know about one of them.

The first is a look-alike domain. The real domain is acmesupplies.com. The fake one is acme-supplies.com, or acmesuppIies.com with a capital I instead of a lowercase l, or acmesupplies.co. Registering one of these costs less than a coffee and takes five minutes. A tired reader scanning a long email thread on a phone will not catch the difference.

The second is worse, because it does not need a fake domain at all. It puts your real domain in the "From" field. Email was not built to check whether the server sending a message is actually authorised to send on behalf of that domain. Unless you have told the internet which servers are allowed to send as you, and told receiving mail systems what to do when a message fails that check, anyone can type your exact address into the From field and a large number of inboxes will deliver it without complaint.

That second version is the one your own DNS records control. It is also the one most small business domains have left wide open.

Why this keeps working

Business email compromise, the umbrella term for this kind of fraud, is not a niche problem. The FBI's Internet Crime Complaint Center recorded $3.04 billion in verified losses to BEC in 2025, across 24,768 complaints, up from $2.77 billion the year before (source: 2025 IC3 Annual Report, FBI). That figure covers only cases people reported. It does not include the ones written off quietly as a bad debt.

The reason it keeps working is not cleverness. It is that most domains never told the internet who is allowed to send mail on their behalf. Monitoring 1,276,088 domains worldwide in July 2026, DmarcDkim found that 68.7% had no effective DMARC protection in place (source: DmarcDkim, July 2026). That is not 68.7% of small, obscure businesses. That is more than two out of three domains generally, including plenty that send invoices for a living.

What actually stops the spoofed version

Three DNS records work together here, and each one closes a different gap.

SPF lists which mail servers are allowed to send as your domain. Without it, any server anywhere can claim to be you.

DKIM attaches a signature to outgoing mail that proves it was not altered in transit and did genuinely originate from a server you control.

DMARC is the instruction that ties the other two together and tells receiving mail systems what to do when a message fails both checks. This is the part almost everyone skips. A domain can have SPF and DKIM configured correctly and still be fully spoofable, because without a DMARC policy set to quarantine or reject, a failed check is only a suggestion. The message gets delivered anyway.

This is also why Google, Yahoo and Microsoft now require a published DMARC record, alongside SPF and DKIM, for any domain sending over 5,000 messages a day. It is not a courtesy setting anymore. It is table stakes for having mail delivered at all.

DMARC will not stop the look-alike domain trick, because acme-supplies.com is a different domain with its own DNS, entirely outside your control. But it closes the far more common route, the one where the fraud arrives from your actual address, and it is the one thing a business owner can fix once and stop worrying about.

What this looks like in practice

If your domain has no DMARC record, or one set to p=none, a message claiming to be from payments@yourcompany.com can reach a client's inbox even though it did not come from your servers. Nothing on the surface of that email looks wrong. The display name matches. The address matches. The signature block matches, because the fraudster copied it from a real thread. The only thing that does not match is which server actually sent it, and that check is invisible unless the receiving system is told to act on it.

Once DMARC is set to reject, a message spoofing your exact domain fails delivery outright at the receiving server, before it ever reaches an inbox for someone to be fooled by.

What to do about the fraud itself, not just the DNS

Fixing your domain's authentication removes the easiest version of this attack, but it is worth pairing with two habits that cost nothing:

Confirm any change to bank details by phone, using a number you already have on file, never a number given in the email that asked for the change. This single habit defeats both the spoofed-domain and the look-alike-domain version of the scam, because it does not depend on the email looking right.

Watch for near-identical domains during a renewal check, if you want to go a step further. You do not need to register every variant of your own name, but knowing one exists is useful the day a client mentions receiving something odd.

If you want to see where your own domain currently stands, run it through a domain health check and look specifically at the DMARC policy line. If it says none or is missing entirely, that is the gap this whole fraud pattern depends on.

Check your own

Is your domain one of them?

The check is free, takes about thirty seconds, and shows the full result without asking for your email.

Run the free check

Back to all posts

Check domain WhatsApp Call