Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

How to Stop Invoice Fraud and Email Spoofing (SPF, DKIM and DMARC)

In short

Invoice fraud usually starts with a convincing email that looks like it came from a supplier, a boss or you. SPF, DKIM and DMARC are three email settings that make it far harder for criminals to spoof your domain. Roll them out in stages, and always verify any change to bank details by phone using a number you already trust.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

How invoice fraud actually happens

Most invoice fraud does not involve clever hacking. It involves a convincing email and a busy person who has no reason to be suspicious.

The pattern is well worn. A criminal poses as one of your suppliers and emails your accounts team to say their bank details have changed, please use these new ones from now on. Or they pose as your managing director and email a junior member of staff asking for an urgent payment to be made before a meeting. Or they send an invoice that looks exactly like the real thing, because they have been quietly reading email in a mailbox they broke into weeks ago.

This family of scams is known as business email compromise, and invoice fraud is its most common form. UK Finance and Action Fraud report that these scams cost businesses very large sums every year. The reason it works is simple: the email looks right, the request seems normal, and the pressure to act quickly stops people pausing to check.

A key trick criminals use is spoofing your domain, making an email appear to come from your own company address so it sails past suspicion. That is exactly what three email settings, SPF, DKIM and DMARC, are designed to prevent.

SPF, DKIM and DMARC, without the jargon

These three sit in the background of your email domain. You will never see them day to day, but they decide whether the rest of the world trusts email that claims to be from you.

  • SPF (Sender Policy Framework) is a public list of which mail servers are allowed to send email on behalf of your domain. When another mail system receives a message claiming to be from you, it can check that list. If the message came from a server that is not on it, that is a red flag.
  • DKIM (DomainKeys Identified Mail) adds an invisible, tamper-proof signature to every email you send. The receiving system can check the signature to confirm the message genuinely came from your domain and was not altered on the way.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the other two together. It tells receiving systems what to do when a message fails the SPF and DKIM checks, for example send it to spam or reject it outright, and it sends you reports on who is trying to send email as you.

Together they make it far harder for a criminal to send an email that appears to come from your own domain. That protects your customers and suppliers from being scammed in your name, and it protects your reputation.

Roll it out in stages, not all at once

The one mistake to avoid is switching everything to full enforcement overnight. If your records are not quite right, you can accidentally block your own legitimate email, including newsletters, your booking system and invoices sent through third-party tools. A staged rollout avoids that.

  1. Take stock first. List every service that sends email as you: your main mailbox provider, your accounting software, your marketing tool, your booking system, anything. Each one needs to be accounted for.
  2. Set up SPF and DKIM properly. Publish an SPF record that includes all those legitimate senders, and enable DKIM signing on your mail platform.
  3. Start DMARC in monitoring mode. Begin with a policy that takes no action but sends you reports. This shows you what is passing, what is failing and why, without any risk to real email.
  4. Fix what the reports reveal. Add any genuine sender you missed and correct anything misconfigured.
  5. Tighten the policy in steps. Move DMARC from monitoring to quarantine (suspicious mail goes to spam), and finally to reject (spoofed mail is refused). Only move up when the reports are clean.

Done this way, you reach strong protection without ever cutting off your own email. This is the sort of thing we set up as part of managed IT support, particularly for accountants and solicitors who move client money and are prime targets.

The habit that stops the fraud SPF cannot

Here is the honest limit of these settings: they stop criminals spoofing your exact domain. They do not stop an email from a lookalike domain (yourcompany-invoices.com instead of yourcompany.com), or from a free webmail account, or from a real supplier mailbox that has itself been broken into. In those cases the email is technically genuine, it is just controlled by a criminal.

That is why the most important defence is a human one: verify any change to payment details out of band.

No email setting can undo a payment once it has left your account, but a thirty-second phone call to a number you already trust almost always can.

Make it a firm rule that any request to change a supplier’s bank details, or any unexpected urgent payment, is confirmed by phoning a number you already hold on file, never the number or reply address in the email itself. Build in a second pair of eyes for payments over a set amount. Slow the process down deliberately, because urgency is the fraudster’s main weapon.

A note on your email platform

If you use Microsoft 365 or Google Workspace, all three of these controls are supported, but they are not fully switched on for your own domain by default. Someone still has to configure the records and move DMARC to enforcement.

For businesses that want stronger email security from the ground up, we also recommend Proton Mail, which is built around encryption and privacy and is what Dacros uses for its own email. Whatever platform you are on, the fundamentals are the same: authenticate your domain, roll it out in stages, and back it with a strict payment-verification habit.

If you are not sure whether your domain is protected today, book a free IT and security review and we will check your SPF, DKIM and DMARC and tell you exactly where the gaps are. You can also read more about how we approach cyber security.

Frequently asked questions

What is invoice fraud?

Invoice fraud, a form of business email compromise, is when a criminal tricks your business into paying money to their account. They usually pose as a genuine supplier or a senior colleague by email and either send a fake invoice or ask you to change the bank details on a real one.

What do SPF, DKIM and DMARC actually do?

They are three settings on your email domain. SPF lists which servers are allowed to send email as you. DKIM adds a tamper-proof signature to your messages. DMARC ties the two together and tells other mail systems what to do with messages that fail the checks, such as reject them or send them to spam.

Will these settings stop all phishing emails?

No. SPF, DKIM and DMARC stop criminals sending email that appears to come from your own domain, which protects your name and your customers. They do not stop emails from lookalike domains or free webmail accounts, so staff awareness and payment checks are still essential.

We already pay for Microsoft 365. Do we still need this?

Yes. Microsoft 365 and Google Workspace support SPF, DKIM and DMARC, but they are not fully configured by default for your own domain. Someone has to set the records up correctly and move DMARC to an enforcing policy.

What is the single most important habit to prevent invoice fraud?

Verify any request to change bank details out of band, meaning through a separate, trusted channel such as a phone number you already have on file. Never use the contact details in the email that made the request.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.