I inbox.consulting avatar inbox.consulting

The Spoofed Invoice: How Weak Email Security Quietly Damages Your Brand

Email Security Spoofing DMARC Brand Protection BEC

A fake invoice went out in your name today

Picture this. One of your customers receives an email. It has your company name in the sender field. Your branding, maybe your logo. A polite message referencing an outstanding payment, and a link to settle it.

They pay it.

The money goes to a scammer. You never sent the email. In fact, you have no idea any of this happened until the customer calls, confused and angry, asking why the payment didn’t register on their account.

This is domain spoofing, and it happens far more often than most business owners think. It doesn’t require anyone to hack your systems, steal a password, or breach your network. The attacker simply sends email that looks like it came from your domain — and if your domain isn’t properly protected, the world’s mail servers have no way to tell the difference.

Why this is a brand problem, not just an IT problem

Most businesses file email security under “IT” and move on. That’s a mistake, because the real damage from spoofing isn’t technical. It’s reputational.

When a customer is defrauded by an email wearing your name, the name they remember is yours. Not the scammer’s. You don’t get a chance to stand up and explain “that wasn’t really us” — the trust is already broken, and the association between your brand and a bad experience is already formed.

The costs compound quietly:

  • Customers who were tricked lose money and blame you
  • Customers who weren’t tricked but received the email now distrust your real messages
  • Your legitimate emails start getting filtered as suspicious, because receiving servers see fraud coming from your domain
  • In regulated industries, a spoofing incident can trigger compliance questions you’d rather not answer

A reputation that took years to build can absorb real damage from a single convincing fraud campaign run in your name.

”But we have nothing worth attacking”

This is the most common reason businesses skip email security, and it’s based on a misunderstanding of how attackers think.

They’re not targeting your data. They’re borrowing your identity. Your domain has something valuable: the trust your customers, suppliers, and partners place in emails that appear to come from you. That trust is the asset being stolen and weaponised.

Small and mid-sized businesses are often more attractive targets than large enterprises, precisely because they’re less likely to have email authentication properly configured. The attacker goes where the door is unlocked.

The two halves of email security

There’s a common assumption that email security is only about receiving — spam filters, phishing protection, keeping bad things out of your inbox. That’s half the picture.

The other half is sending: making sure that only you can send email from your domain, and that anyone impersonating you gets blocked before they reach a single inbox.

This second half is the one businesses overlook, and it’s the one that protects your brand. It comes down to three email authentication standards working together:

  • SPF declares which servers are allowed to send email for your domain
  • DKIM cryptographically signs your emails so they can’t be tampered with or forged
  • DMARC ties the two together and tells receiving servers what to do when an email fails the checks — including the option to reject it outright

When these are configured and enforced, a scammer trying to send email as your domain hits a wall. The receiving server checks your policy, sees the message doesn’t pass, and blocks it.

The catch: most businesses stop halfway

Here’s the part that catches almost everyone. Many businesses do have a DMARC record — but it’s set to p=none.

p=none is monitoring mode. It collects data about who’s sending email as your domain, but it takes no action. Spoofed emails still sail straight through to your customers. It’s the equivalent of installing a security camera that records the break-in but never locks the door.

Real protection only kicks in when DMARC is moved to enforcement — p=quarantine and ultimately p=reject. That’s the setting that actually stops impersonation. And the journey from none to reject is where most businesses stall, usually out of a reasonable fear of accidentally blocking their own legitimate email.

That fear is valid, which is exactly why it’s worth doing carefully rather than not at all. Done properly, the move to full enforcement is a controlled process that protects your domain without disrupting a single real email.

How to check where your domain stands right now

You don’t need to be technical to get a sense of your exposure:

  1. Check whether your domain has a DMARC record at all
  2. If it does, look at the policy — is it none, quarantine, or reject?
  3. If you see none, or no record exists, your domain can currently be spoofed

If that’s the case, you’re not alone — but you are exposed, and the fix is far more straightforward and affordable than most people assume. It’s a configuration project, not a capital expense.

The bottom line

Email security isn’t only about your messages reaching the inbox. It’s about making sure that the only emails the world receives in your name are the ones you actually sent.

The spoofed invoice scenario isn’t rare or hypothetical. It’s a routine attack, run constantly, against domains that left the door open. Closing that door is one of the highest-impact, lowest-cost things you can do to protect your brand.


inbox.consulting helps businesses lock down their domains and reach the inbox — deliverability, anti-spoofing, and full DMARC enforcement. Book a free 20-minute audit and we’ll tell you exactly where your domain stands.