Anyone Can Send an Email That Looks Like It Came From You
Domain impersonation is cheap, convincing, and mostly preventable
Executive Summary
Most business owners assume their company name and email domain are theirs to use. In practice, without a specific set of controls in place, almost anyone on the internet can send email that appears to come from your domain, and your clients, vendors, and staff have little reason to doubt it. This is how a large share of invoice fraud and executive impersonation begins. The reassuring part is that the core fix is a well established standard your IT team or provider can turn on, and it costs nothing in licensing. The catch is that even a flawless setup leaves gaps only trained people can close. This article explains the problem in plain terms, the standard that handles most of it, and why the human layer still matters.
The Assumption That Costs Companies Money
Ask a business owner whether someone could send an email pretending to be their company, and most will say no, or at least assume their provider prevents it. It feels like the kind of thing that should be locked down by default. For a great many businesses, it is not.
Email was designed decades ago to move messages freely, not to prove who sent them. That original openness never fully went away. Unless a business has deliberately set up the right controls, its domain can be used as the apparent sender of messages the business never wrote. The name on the message is doing a lot of work, and by default nothing is checking whether it is honest.
How Spoofing Actually Works, Without the Jargon
Think of an email like a physical envelope. The return address in the corner is whatever the sender chooses to write. The postal service does not verify it. It simply delivers the envelope and trusts the recipient to judge what is inside.
Email works much the same way. The from address that a recipient sees is, in many cases, just text the sender filled in. An attacker can write your company name and your domain in that field and send the message from their own equipment. If nothing on the receiving end is set up to check, the message arrives looking authentic, complete with a familiar name the recipient already trusts.
Why This Lands on Your Clients, Not Just You
The damage from spoofing often happens outside your walls. A convincing message that appears to come from your company can be sent to your clients, your vendors, or your partners. It might ask them to update payment details, approve an unusual invoice, or open a document. When the request looks like it came from a business they trust, many will comply.
When that goes wrong, the business whose name was used rarely escapes the fallout. A client who is defrauded by an email that looked like yours does not carefully separate the real you from the impersonator. They remember that the loss arrived under your name. Domain impersonation is not only a security issue. It is a matter of reputation, client trust, and sometimes liability.
The Standard That Closes Most of the Gap
The good news is that this problem has a mature, widely adopted solution. It rests on three checks that work together, and a business leader does not need the technical detail to understand what each one does.
- The first check publishes a list of who is actually allowed to send email on behalf of your domain, so a receiving system can spot a sender that is not on the list.
- The second check adds a kind of tamper seal to your messages, so a receiving system can confirm the message truly came from your domain and was not altered on the way.
- The third check ties the first two together and tells receiving systems what to do when a message fails, whether to quarantine it or reject it outright.
That third check is where the real protection lives, and it is where many businesses stop short. It is common to have the checks reporting quietly in the background but never set to actually block anything. Turning them on so that failing messages are rejected is what stops impersonation at the door. The licensing cost is nothing. The work is in the setup and in monitoring the results so legitimate mail keeps flowing.
Where the Standard Stops and People Begin
Even a perfect setup does not end the conversation, because attackers simply change tactics when the direct approach stops working. Several methods sail straight past the technical checks:
- Lookalike domains. A slightly altered spelling that the eye skips over, such as an added letter or two characters that resemble one, passes every check because it is a different domain the attacker legitimately controls.
- Display-name tricks. The visible name is set to your executive or your company while the actual address behind it is unrelated, which looks convincing on a phone where only the name shows.
- Compromised real accounts. When an attacker takes over a genuine mailbox at one of your vendors, the messages are authentic and pass every check, because they truly come from that vendor.
None of these are stopped by authentication, because none of them are technically lying about the domain. They rely on a person reading quickly and trusting what looks familiar. That is why the technical floor matters and why it is never the whole answer.
What Business Leaders Should Do
This is a short list, and most of it is about asking the right questions rather than becoming an expert.
- Ask your IT team or provider a direct question. Is our domain set to reject messages that fail authentication, or is it only reporting? Reporting alone does not protect anyone.
- Make sure someone reviews the authentication reports, so legitimate mail is not accidentally blocked and abuse is caught early.
- Register and watch for obvious lookalike versions of your domain, so impersonation attempts are easier to spot and act on.
- Require out-of-band verification for any change to payment details or bank accounts, on your side and with your vendors, no matter how routine the request appears.
- Train staff to recognize display-name tricks and lookalike addresses, because those are the attacks the technical controls cannot catch.
The Takeaway
You cannot fully outsource trust in your own name. The technical standard that prevents domain spoofing is inexpensive, well understood, and worth turning on properly rather than leaving half configured. But it protects only against the direct version of the attack. The moment it works, attackers move to lookalikes, display names, and compromised partners, and the last line of defense becomes a person who pauses and verifies. Set the floor high, then make sure the people above it know what the floor cannot do.
How Simulint Helps with BlueSphere
Turning on email authentication is the right first move, and it is where most attackers stop trying the direct approach. What they do next is exactly what technical controls cannot see: lookalike domains, display-name spoofing, and messages from vendor mailboxes that have been quietly taken over.
BlueSphere phishing simulations train people to recognize those attacks across email and messaging, using AI-generated scenarios that reflect real tactics and your own context. The goal is a workforce that verifies a payment change or an unusual request by habit, so the gaps left by authentication do not turn into losses.
Learn more about BlueSphere: https://lnkd.in/eE9HTaw8
