Cyber Security & Compliance
Business Email Compromise & Email Spoofing: SPF, DKIM and DMARC Explained
One of the most costly cyber crimes is one you never feel: someone fakes your email address and asks for money. Here's how it happens and how SPF, DKIM and DMARC protect your business name.
The three email authentication standards
SPF
Lists which servers may send email for your domain
DKIM
Digitally signs email to prove it's genuinely from you
DMARC
Tells receivers what to do with failed mail + gives you reports
Imagine a customer receives an email that looks perfectly like it is from you, asking them to pay an invoice into a “new” bank account. Or a staff member gets a “direct message from the boss” asking for a fast transfer. This is business email compromise — a financially motivated scam where attackers fake your identity to steal money or data. The good news is that three industry-standard technologies — SPF, DKIM and DMARC — do a great deal to stop it. Here's what they are and why your business needs them.
What is business email compromise?
Business email compromise (BEC) is a scam in which a criminal impersonates a trusted person or company to trick someone into an action — usually transferring money, changing a payment destination, or sharing confidential information. The attacker may spoof your email address, hack a real account, or simply mimic the tone and style of a real message. Because the request looks legitimate and urgent, it can succeed in a matter of minutes.
Common examples include a clone of a supplier's invoice with a new bank account number, or a message from “your managing director” authorising an urgent payment. When it works, it can cost a business a significant amount of money — and the funds are usually difficult or impossible to recover once sent.
How email spoofing works
A large part of BEC relies on spoofing — making an email look as though it came from a legitimate domain, often your company's. Email was designed decades ago before security was a concern, so by default a receiving server does not automatically prove who really sent a message. Attackers exploit this.
This is why authentication standards exist. They are DNS-based — your domain tells the rest of the internet which sources are genuinely allowed to send email for you, and what to do with messages that fail the checks. The three standards work together:
SPF, DKIM and DMARC — the three lines of defence
SPF (Sender Policy Framework)
Publishes a list of the servers allowed to send email for your domain. Receiving servers check the sender's address against this list.
DKIM (DomainKeys Identified Mail)
Digitally signs each email with a private key. Receiving servers use a public key in your DNS to verify the email genuinely came from you and hasn't been changed in transit.
DMARC (Domain-based Message Authentication, Reporting & Conformance)
Tells receiving servers what to do with email that fails SPF and DKIM — for example, quarantine it or reject it — and gives you reports about what is failing, so you can see abuse and fix it.
None of the three is enough on its own. SPF and DKIM prove who is allowed to send, and DMARC then decides what happens to messages that do not pass. Deployed together, they are a robust defence against spoofing and make it much harder for criminals to send email that appears to come from you.
What to check on your own domain
You can check whether your domain has SPF, DKIM and DMARC records using free public look-up tools. Many businesses are surprised to find they have SPF but no DMARC — which means the policy that actually blocks spoofed mail is missing. If you use Microsoft 365, its documentation explains how email authentication is applied and how to align your email domains under one identity.
If your domain has no authentication in place, that is a real gap — and one attackers actively look for. Getting SPF, DKIM and DMARC configured (and DMARC gradually set to enforce rather than just monitor) is a foundational email security step for any business.
Protect yourself beyond the technology
- ⚠ Treat any payment or bank-detail change received by email with suspicion — verify it by phone or in person first.
- ⚠ Agree a rule: no urgent payments authorised by email alone, especially new bank accounts.
- ⚠ Train staff to recognise urgent, secrecy-requesting messages and to double-check unusual requests.
- ⚠ If money is sent in error, contact your bank immediately and report to the relevant authorities — speed matters.
The bottom line
Business email compromise succeeds because the scam looks real. SPF, DKIM and DMARC make it far harder for criminals to send mail that appears to come from you, and simple business rules stop the human error at the other end. Together they close off one of the most expensive threats your business faces.
Key Takeaways
- ✓Business email compromise fakes your identity to steal money or data
- ✓SPF, DKIM and DMARC work together to stop email spoofing
- ✓DMARC is the piece most businesses are missing — and it blocks the fake mail
- ⚠Verify any payment or bank-detail change by phone, never by email alone
- ⚠Act fast if money is sent in error — contact your bank immediately
Official Sources
Related Services
Other Categories
Want to Check Your Email Is Safe From Spoofing?
StormDotCom can audit your domain's SPF, DKIM and DMARC records, fix what's missing, and help your team avoid business email compromise. Book a free assessment and we'll show you where your email stands today.
Book a Free IT Assessment