Helium – AI automation agency logo
Helium – AI automation agency logo
Helium – AI automation agency logo
Helium – AI automation agency logo

Why Someone Can Send Email Pretending to Be You

Without three records on your domain, anybody can send email that appears to come from your business. Most companies have never checked, and the first sign is usually a client asking about an invoice.

A client forwards you an email. It appears to come from your business, with your address in the sender field, asking them to pay an invoice into different bank details.

You did not send it. Your systems were not breached. Somebody simply put your address in the from field of a message, which by default is something anybody can do.

Why this is possible at all

Email was designed without authentication. The sender field is a label, not a credential, in the same way an envelope can carry any return address somebody chooses to write on it.

Three additions fixed this, and all three have to be configured on your domain for the protection to work. Most businesses have one, some have two, and a surprising number have none.

SPF publishes which servers are permitted to send email on behalf of your domain.

DKIM adds a signature proving a message genuinely came from you and was not altered.

DMARC ties the two together and, importantly, tells receiving servers what to do when a message fails. That last part is where most configurations fall short.

The setting almost everybody leaves wrong

DMARC has a policy setting with three possible values. None means take no action. Quarantine means treat suspicious messages as spam. Reject means refuse them outright.

Most businesses that have DMARC at all have it set to none, because that is where you start when configuring it and there is no prompt to move on.

A policy of none provides reporting and no protection. Somebody spoofing your domain will still reach your clients, and you will have a record of it happening rather than a mechanism that stopped it.

It stopped being optional in 2024

From February 2024 Google and Yahoo began enforcing requirements on bulk senders rather than recommending them.

Authentication with both SPF and DKIM, a DMARC record on the sending domain, one click unsubscribe in messages, and low spam complaints. Google states senders should stay below 0.1 percent complaints and avoid exceeding 0.3 percent, and treats around 5,000 messages a day to personal Gmail accounts as bulk.

The threshold matters less than the direction. What was best practice became a condition of delivery, and businesses without it now find a share of legitimate mail simply not arriving, with no bounce explaining why.

Why this is a commercial problem, not an IT one

Two consequences, and the second is the expensive one.

Your mail stops arriving. Quotes, invoices and replies land in spam or nowhere. The failure is silent from your side, which is why it can continue for months.

Somebody uses your name. Invoice fraud against your clients, carried out with your address in the sender field. The financial loss is theirs and the relationship damage is yours, and explaining that your systems were not breached is a conversation that does not go as well as it should.

Businesses that send payment instructions by email are the obvious targets, which covers most of the trades, construction, professional services and broking world.

What to check this week
  • Whether all three records exist on your domain. Your IT provider can answer in minutes and free checkers exist.

  • What your DMARC policy is set to. If it is none, that is a configuration to finish rather than a decision anybody made.

  • Whether every sending service is included in SPF. Your mail provider, your CRM, your invoicing system, your marketing platform. Each one that is missing sends mail that fails authentication.

  • Whether outbound campaigns run on a separate domain, so cold sending volume cannot damage the domain your invoices depend on.

Where AI fits

Not in the configuration, which is a one time job for whoever manages your domain.

Where it matters is monitoring afterwards. DMARC produces reports about who is sending using your domain, and those reports are technical, continuous and read by almost nobody. A system watching them will notice an unfamiliar sender or a change in pattern within a day, rather than the alternative, which is a client asking about an invoice you did not send.

The same monitoring covers deliverability generally, so a domain that starts to slip comes out of rotation before it costs you a quarter of replies.

Tell your clients how you will and will not contact them

The technical protection stops most of it. The remainder is closed by expectation.

Tell clients, in writing at the start of a relationship, that your bank details will never change by email, and that any message claiming otherwise should be verified by phone on a number they already have.

That single sentence in your engagement documents defeats the most common and most damaging version of this fraud, and it costs nothing. Businesses that have been through it always add it afterwards.

Look alike domains are the other half

Authentication protects your exact domain. It does nothing about a domain that merely resembles it.

A character swapped, a word added, a different ending. Those are separate domains, they authenticate perfectly well because the sender genuinely owns them, and to a client glancing at a phone they read as you.

Registering the obvious variations costs very little annually and removes the cheapest route. Monitoring for new registrations resembling your name covers the rest, and is another thing worth watching automatically rather than hoping somebody notices.

Check it again after any change

Authentication breaks quietly whenever the sending picture changes.

A new CRM, an invoicing tool, a marketing platform, a change of mail provider. Each introduces a service that sends on your behalf and needs including, and each is typically set up by somebody focused on getting the tool working rather than on your domain records.

Make it a step in adopting any system that sends email. Otherwise the first sign is a client mentioning that your messages have started going to spam.

Sources
  • Google, Email sender guidelines, bulk sender requirements in force from February 2024, covering SPF, DKIM and DMARC authentication, one click unsubscribe, and spam complaint rate thresholds.

AI Optimize configures the authentication, separates outbound sending from the domain your business runs on, and watches the reports nobody reads. That work sits under Cold Email Outreach.

Related reading

WHAT WE BUILD

This is the part we solve