Is That Email Really From Your Boss? How to Spot and Stop Spoofed Email
Did the "urgent, pay this account today" email really come from your boss? How to spot fake emails in 30 seconds, and how SPF, DKIM and DMARC stop criminals from using your company's name.

Contents 7
On a Friday afternoon, the head of accounting gets an email. Sender: the company's CEO. Subject: "Urgent and confidential." The message is short: "We're in the middle of an acquisition, don't discuss this with anyone. A payment must go to this account before end of day. I'm in meetings, don't call, reply by email."
The name is right, the signature is right, the tone is familiar. But the CEO didn't send it.
This is called Business Email Compromise (BEC), one of the cybercrimes that costs companies the most money worldwide. According to the FBI Internet Crime Complaint Center (IC3), reported BEC losses worldwide exceeded $55 billion between October 2013 and December 2023. And the attack involves no virus and no complex technique; just a convincing email.
In short:
- Email's protocol dates back to the 1980s and doesn't verify the sender on its own; anyone can write anything in the "from" field.
- You can spot fake emails by signs like urgency, secrecy, unusual payment requests and lookalike domains.
- SPF, DKIM and DMARC are three DNS records that tell the world who may send email for your domain.
- Since 2024, Google and Yahoo require these records from bulk senders.
Why is email so easy to fake?
SMTP, the protocol underpinning email, was designed in the 1980s, when the internet was a small community where everyone knew each other. Just as anyone can write any return address on the back of an envelope, SMTP doesn't verify on its own that the sender is who they claim to be.
Attackers exploit this gap in three main ways:
- Direct spoofing: the sender address is set to
ceo@yourcompany.comdirectly. If your domain isn't protected, the email may reach the inbox. - Lookalike domains: instead of
yourcompany.com, they register something likeyourcornpany.comoryourcompany-inc.comthat's hard to spot at a glance. "rn" looking like "m" is a classic trick. - Display name games: the sender name reads "John Smith - CEO", but the real address is an unrelated free email account. Many email apps, especially on mobile, show only the display name.
Spotting a fake email in 30 seconds
However good the technical protections, the last line of defense is the person reading the email. Stop if you see even one of these signs:
- Pressure to hurry: "Immediately", "before end of day", "very urgent." Fraudsters don't want to give you time to think.
- A request for secrecy: "Don't tell anyone", "don't call, just reply by email." It's there to block verification.
- An unusual payment request: a new bank account, a "our supplier changed banks" notice, a request to buy gift cards.
- Address mismatch: look at the actual email address, not the display name. On mobile, tap the sender's name.
- A different reply-to address: even if the sender looks right, hitting reply may go somewhere else.
- Unexpected attachments or links: an "invoice attached" email you weren't expecting. Hover over links (without clicking) to see the real address.
The golden rule: verify every request about payments, bank account changes or passwords through a different channel. Call the number you already know, not the one in the email. This single habit defeats most BEC attacks.
Email headers: a look behind the curtain
Behind every email are headers showing the path it took and its authentication results. In Gmail, open an email and choose "Show original" from the three-dot menu to see a summary like:
SPF: PASS (IP address 203.0.113.25)
DKIM: PASS (domain yourcompany.com)
DMARC: PASS
If all three say "PASS", the email really came from servers authorized by that domain. If you see "FAIL", or no result at all, you have good reason to be suspicious. In Outlook, the same information is under "Internet headers" in the message properties.
SPF, DKIM and DMARC: your domain's ID card
So far we've covered the receiving side. How do you stop your own company's name from being used in fraud? The answer is three records added to your domain's DNS settings.
SPF: "These servers may send for me"
SPF (Sender Policy Framework) is the list of servers authorized to send email for your domain. The receiving server checks whether the incoming email came from a server on that list.
yourcompany.com. TXT "v=spf1 include:_spf.google.com include:amazonses.com -all"
This record says: "Only Google Workspace and Amazon SES may send for me; reject everything else (-all)." A domain can have only one SPF record, and it may need at most 10 DNS lookups; watch that limit if you use many services.
DKIM: a digital seal
DKIM (DomainKeys Identified Mail) has the sending server add a digital signature to every email. The public key needed to verify it is published in DNS. By verifying the signature, the receiver knows the email really came from that domain and wasn't changed in transit. Your email provider (Google Workspace, Microsoft 365, etc.) gives you the DKIM record to add.
DMARC: "What to do with those that fail?"
SPF and DKIM run checks, but they don't say what happens to an email that fails. DMARC does exactly that, and also sends you reports:
_dmarc.yourcompany.com. TXT "v=DMARC1; p=reject; rua=mailto:dmarc@yourcompany.com"
The p value sets the policy:
| Policy | Meaning |
|---|---|
p=none |
Just monitor and report; don't touch the email |
p=quarantine |
Send failing email to spam |
p=reject |
Reject failing email outright |
DMARC also checks alignment: the domain in the visible from address must match the domain verified by SPF or DKIM. That's the mechanism that actually blocks direct spoofing.
A safe rollout plan
Starting DMARC straight at p=reject can block mail from a legitimate sender you forgot about, like a billing system or newsletter tool. The recommended path is gradual:
- Start with
p=noneand watch the reports arriving at theruaaddress for a few weeks. You'll see who sends email in your domain's name. - Add all legitimate senders to SPF and DKIM.
- Move to
p=quarantine, then, if all is well after a few weeks, top=reject.
Why do Google and Yahoo now require it?
Since February 2024, Google and Yahoo have tightened their sender rules. Anyone sending more than 5,000 emails a day to Gmail must have SPF, DKIM and DMARC, offer one-click unsubscribe in marketing email and keep spam complaint rates low. Smaller senders need at least SPF or DKIM.
These rules are about deliverability as well as security: a company without these records may see its legitimate email land in customers' spam folders.
You can check your own domain from the command line:
nslookup -type=txt yourcompany.com
nslookup -type=txt _dmarc.yourcompany.com
Frequently asked questions
We're a small company. Would anyone target us?
Yes. Small companies are often more attractive targets, because their payment approval processes are looser and their technical protections weaker. Attackers easily find executives' names on company "About us" pages and LinkedIn.
Is setting up SPF, DKIM and DMARC expensive?
No. All three are free text records added to your domain's DNS. The real effort is finding every service that sends email for your domain and adding it to the list.
Does DMARC stop every fake email?
No. DMARC stops exact spoofing of your domain. It doesn't stop email from a lookalike domain (like yourcornpany.com) or display-name tricks. That's why technical protection and staff training are both needed.
We were tricked and made a payment. What now?
Call your bank right away and ask them to stop or recall the transfer; the first hours are critical. Then change passwords on the affected accounts and report the incident to the authorities.
The strongest defense against fake emails combines correctly configured infrastructure with aware staff. For password security, see our guide to checking whether your password has been leaked. If you want secure email infrastructure and business systems for your company, reach us through our enterprise software development page.


