Sending addresses can be forged without any access to your account. The defences are the three domain records that let receiving servers reject forgeries, plus telling customers how you will and will not contact them.

Nothing has to be hacked

The assumption when a customer reports a strange email from you is that your account has been compromised.

Usually it has not. The sender address on an email is simply a field, and it can be filled in with anything, in the same way an envelope can carry any return address you care to write on it.

So somebody can send a message that appears to come from your business, to your customers, without ever touching your systems.

That distinction matters because the response is different. Changing your password does nothing about it.

Establish which it is first

Before doing anything else, because the two situations need opposite responses.

Check your sent items. If the messages are there, the account is compromised and that is an urgent problem: change the password, sign out all sessions, enable two-factor, and check for forwarding rules somebody may have added.

If your sent items are clean, it is almost certainly spoofing, and your account is fine.

Ask a recipient to forward you the original message with its full headers rather than a screenshot, since the headers show where it actually came from.

That check takes ten minutes and determines everything that follows.

The three records that stop most of it

Together they let a receiving mail server reject a forged message before your customer sees it, which is a considerably better outcome than explaining it afterwards.

Getting them set up

This is a job for whoever manages your domain and email, and it is an hour of their time rather than a project.

Most email providers publish exactly what to add for their service, and many will configure the first two automatically if your domain is managed alongside the mail.

The third is the one usually missing, because it needs a decision rather than a default: whether to ask receiving servers to monitor, quarantine, or reject failures.

The sensible approach is to start in monitoring mode, look at the reports for a few weeks to confirm nothing legitimate is failing, then tighten it.

Businesses that jump straight to rejection occasionally discover their invoicing system or mailing platform was sending on their behalf and is now being blocked, which is why the staged approach exists.

Count everything that sends as you

The step that makes the configuration correct rather than approximately correct.

Your mail provider is obvious. Less obvious are the mailing platform, the invoicing software, the booking system, the website contact form, the accounting package, and any scheduling tool that sends confirmations.

Each of those may send using your address, and each needs to be authorised or its messages will start failing once you tighten the rules.

List them before you configure anything, because discovering the sixth one by having invoices bounce is a poor way to find out.

This list is also useful for its own sake, since most businesses have not previously written down everything that emails their customers.

A worked example

A firm heard from three customers in a week about emails they had not sent, one of which asked for payment to an unfamiliar account.

Sent items were clean, so nothing had been compromised.

Their domain had the first record configured incorrectly, listing an old provider, and neither of the other two at all.

Their supplier fixed all three over two days, after listing five systems that sent on their behalf, one of which nobody had remembered.

They also emailed their customer list explaining what had happened and stating that they would never email asking for payment to a new account, and that any change of bank details would be confirmed by phone on a number the customer already had.

Reports stopped within about a fortnight, and two customers replied to say they had nearly paid the earlier message.

Tell people how you will contact them

The half that protects customers regardless of the technical work.

The records reduce forgeries reaching inboxes. They do not stop somebody registering a similar domain, which no configuration can prevent.

So say plainly, in more than one place, how you will and will not communicate: that you will never email a change of bank details, that invoices always come from a stated address, and that anything unexpected should be checked by phone on a number they already have.

Put it on your invoices, in your email signature, and on the site.

A customer who has read that once is far more likely to pause at a convincing forgery than one relying on the message looking wrong.

The staff side

The same technique is used inward as well as outward, and it is more dangerous.

A message appearing to come from the owner, to somebody who processes payments, asking for an urgent transfer, works because it exploits reluctance to question the boss.

The defence is a rule rather than vigilance: any payment instruction arriving by email is confirmed by voice, on a known number, regardless of who it appears to be from and how urgent it sounds.

Say explicitly that nobody will ever be criticised for making that call, since the whole method depends on people not wanting to seem obstructive.

That one rule, stated once and meant, prevents most of what this technique is used for.

The counter-case

This is worth doing and worth keeping in proportion.

The records are a genuine improvement and they are not a complete defence, since a lookalike domain will pass every check because it is a legitimate domain that is not yours.

Registering defensive variations of your domain is occasionally worthwhile and quickly becomes an expensive game you cannot win, given how many plausible variants exist.

And a very small business sending only from one provider may already have the first two configured correctly without knowing it, in which case checking takes minutes and no work is needed.

The durable protection is the rule about confirming payment changes by voice, which costs nothing and works against every version of this.

What to do

  1. Check sent items to rule out a compromise.
  2. Get the full headers from a recipient.
  3. List everything that sends using your address.
  4. Configure all three records, starting in monitoring mode.
  5. Tighten to rejection once reports are clean.
  6. Tell customers how you will never contact them.
  7. Require voice confirmation for any payment change.

Step seven is the one that survives every technique this describes, and it is a sentence rather than a configuration.

Sending properly from your own domain is covered in sending from your own domain.


Frequently asked questions

Does a spoofed email mean I was hacked?

Usually not. The sender address is a field that can be filled in with anything, like a return address on an envelope, so somebody can appear to email as you without touching your systems.

How do I tell the difference?

Check your sent items. If the messages are there, the account is compromised. If they are not, it is spoofing. Ask a recipient for the full headers rather than a screenshot.

What stops it?

Three records in your domain settings: one listing authorised sending servers, one adding a verifiable signature, and one telling receiving servers what to do with failures.

Why start in monitoring mode?

Because businesses that jump to rejection discover their invoicing system or mailing platform was sending on their behalf and is now blocked. List everything that sends as you first.

Do the records stop everything?

No. A lookalike domain passes every check because it is a legitimate domain that is not yours. No configuration prevents that.

What protects customers regardless?

Telling them how you will and will not contact them: that you never email a change of bank details, and that anything unexpected should be checked by phone on a number they already have.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Customers reporting emails you did not send?

Check your sent items first. If they are clean, nothing was hacked and the fix is three domain records.

Start a Conversation