Email Security & Fraud Protection for Small Business
Protect your business from invoice fraud, phishing and email scams. A plain-English guide to SPF, DKIM, DMARC, BEC and secure email for UK firms.
Email is where most attacks on small businesses begin — spoofed invoices, phishing links and impersonated bosses. This hub explains the fraud to watch for and the fixes that work: SPF, DKIM and DMARC to stop spoofing, spotting phishing, better deliverability, and moving to properly secured business email. Start with the basics, then dig into each guide.
Why email is the biggest target
For most small businesses, email is the front door — and criminals know it. It is cheap to attack, easy to fake, and it reaches the people who approve payments and hold the passwords. You do not need a sophisticated hacker to lose money by email; you just need a convincing message and a busy afternoon.
The good news is that email fraud follows a handful of predictable patterns, and the defences are well understood. This hub walks through what goes wrong and what to put in place, then links to step-by-step guides for each part. If you would rather have someone set it all up correctly, our cyber-security service covers exactly this.
Invoice fraud and business email compromise
The most expensive scams rarely involve viruses. Instead, a criminal watches or imitates your email and waits for a payment to be in play. They might spoof a supplier’s address and send a “we’ve changed bank details” message, or pose as a director asking finance to make an urgent transfer. This is known as Business Email Compromise, and our guide on what BEC is and how it works explains the common variations.
Two forms are worth singling out. Invoice and supplier spoofing targets the money you already owe, redirecting genuine payments to a fraudster’s account. Payroll diversion fraud targets your staff, quietly changing the bank details wages are paid into. Both rely on a simple habit: trusting an email that looks right. A quick phone call to a known number, using details you already hold rather than the ones in the email, stops most of them dead.
Stopping spoofing: SPF, DKIM and DMARC
Much email fraud depends on faking your address — or a supplier’s — so a message appears to come from someone it does not. Three records fix this at the technical level. SPF says which servers are allowed to send email for your domain. DKIM adds a tamper-proof signature. DMARC ties the two together and tells other mail providers what to do when a message fails the checks.
Set up properly, they make your domain far harder to impersonate and improve your legitimate email at the same time. Our overview of how spoofing works and why these records matter gives the plain-English version, and our step-by-step guide to setting up SPF, DKIM and DMARC walks through the actual records. This is one of the highest-value things a small business can do, and it usually costs nothing but time.
Phishing, smishing and vishing
Not every attack is aimed at your systems — many are aimed at your people. Phishing emails try to get someone to click a link, enter a password, or open an attachment. The tell-tale signs are learnable, and our guide on how to spot a phishing email covers the checks that matter: the real sender address, unexpected urgency, and links that do not go where they claim.
The same tricks now arrive by text and phone call, too. Smishing and vishing — scam SMS messages and phone calls — often work alongside email to make a fraud feel more real. Teaching your team to slow down and verify is as important as any software.
Deliverability and secure business email
Email security is not only about keeping bad messages out; it is about making sure your good ones arrive. If your invoices and quotes keep landing in customers’ spam folders, the cause is often the same missing SPF, DKIM and DMARC records — so fixing security and fixing deliverability go hand in hand.
The foundation is the platform itself. If you are still running the business on a free personal account, it is worth moving your business email off free Gmail to a proper business plan with admin controls, multi-factor authentication and the ability to enforce policy across your team.
Where this fits
Email sits alongside your wider defences. It connects closely to cyber-security fundamentals, to keeping the rest of your systems maintained through managed IT, and to your obligations around data protection when personal information is involved.
Not sure where your gaps are? Book a free IT and security review and we will look at your email set-up, check your SPF, DKIM and DMARC, and give you a plain-English list of what to fix first.
31 guides in this topic
IT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read → GuideIT Support for Estate Agents in the UK
Practical IT and cyber security for UK estate agents: protecting client money and AML data, working safely with Rightmove and portals, stopping deposit and completion fraud, and mobile working.
Read → ArticleHow to Stop Invoice Fraud and Email Spoofing (SPF, DKIM and DMARC)
How invoice and business email compromise fraud works, and how SPF, DKIM and DMARC stop criminals spoofing your domain. A plain-English guide for UK businesses.
Read → ArticlePasswordless and Passkeys Explained (For Non-Techies)
Passkeys let you sign in with your face, fingerprint or PIN instead of a password — and they're far harder to steal. Here's what they are and how to start.
Read → ArticlePayroll Diversion Fraud Explained: How Criminals Redirect Staff Salaries
Payroll diversion fraud tricks your finance team into paying a staff salary to a criminal's bank account. Here's how it works and how to stop it.
Read → GuideHow to Set Up SPF, DKIM and DMARC: A Step-by-Step Guide
A plain-English, step-by-step guide to setting up SPF, DKIM and DMARC for your UK business email, with a safe staged rollout and common mistakes to avoid.
Read → ArticleRansomware and UK Small Businesses: How Firms Get Hit and How to Stop It
How a small UK business really gets hit by ransomware, and the handful of controls, backups, MFA, patching and staff awareness, that actually prevent it.
Read → ArticleAccount Takeover: How It Happens and How to Stop It
Account takeover is when a criminal logs into your account as you. Learn how it happens, the warning signs to watch for, and how to lock attackers out.
Read → PlaybookWhat to Do After a Cyber Attack: A First-Hours Playbook for Small Businesses
A calm, step-by-step playbook for the first hours after a cyber attack on your UK small business: contain, assess, report, recover and learn.
Read → ArticleWhy Do My Business Emails Go to Spam?
Your important emails keep landing in spam? Here is why it happens — authentication, sender reputation, content and list hygiene — and the practical checks to fix it.
Read → ArticleTech Support Scams and Fake IT Calls: How to Spot Them
Fake 'Microsoft' calls and scary pop-ups pressure you into handing over access or money. Learn the tells, what to do, and how a real IT provider behaves.
Read → ArticleHow to Check if Your Business Email Has Been Breached
Worried your work email has turned up in a data breach? Here's how to check for free, what to do if it has, and how to keep an eye on it going forward.
Read → ArticleBusiness Email Compromise (BEC) Explained
Business email compromise costs UK firms dearly and slips past spam filters. Learn how CEO fraud and supplier impersonation work — and the layered defence that stops it.
Read → ArticleSmishing and Vishing: The SMS and Phone Scams Targeting Your Business
Smishing (text) and vishing (phone) scams are hitting UK businesses hard. Learn the warning signs, the common tricks and exactly how your team should respond.
Read → GuideHow to Migrate to Microsoft 365 Without the Downtime Headache
A plain-English guide for UK small businesses moving email and files to Microsoft 365: how to prepare, handle DNS and MX, avoid downtime, and lock it down after.
Read → ArticleMulti-Factor Authentication (MFA) Explained for Small Businesses
Multi-factor authentication stops most account takeovers even when passwords leak. Learn app codes vs SMS vs passkeys, and how to roll MFA out.
Read → ArticleSIM Swapping Attacks Explained: Why Your Phone Number Isn't a Safe Login
Learn how SIM swapping hijacks your mobile number to beat SMS security codes, why app-based MFA is safer, and how to lock down your phone account.
Read → ArticleQR Code Scams (Quishing) Explained: The Hidden Risk in a Square of Dots
Quishing means QR code phishing. Fake QR codes now appear on car parks, invoices and posters. Learn where they hide, why they slip past filters and how to stay safe.
Read → ArticleHow to Spot a Phishing Email (and What to Do About It)
Learn to spot phishing emails fast: the classic tells, real-world patterns, and exactly what to do next — plus how to train your staff to catch them.
Read → ArticleDeepfake and AI Voice Scams: When the Fake CEO Sounds Completely Real
AI can now clone a voice from seconds of audio. Learn how deepfake calls supercharge CEO fraud and BEC — and the simple call-back and code-word defences that stop them.
Read → ArticleWhat Is Encryption? A Plain-English Guide for Business Owners
Encryption explained without the jargon: at rest vs in transit, HTTPS, device and disk encryption, encrypted email and storage, and why it matters for your business.
Read → ArticleWhy You Should Move Your Business Off Free Gmail
Free consumer email quietly costs you trust, control and security. Here is why UK small businesses should move to a proper custom-domain email, and how.
Read → GuideMicrosoft 365 Security Settings Every Small Business Should Turn On
A plain-English guide to the Microsoft 365 security settings UK small businesses should enable: MFA, anti-phishing, Safe Links, audit logging and sharing controls.
Read → ArticleMDR and EDR Explained: Do Small Businesses Really Need Them?
What managed detection and response (MDR) and EDR mean in plain English, why small firms are targeted too, whether you need 24/7 monitoring, and what to look for.
Read → ArticleSecurity Awareness Training for Staff: Turning Your Team Into Your Best Defence
Why your staff are the front line against cyber attacks, and how short, regular, practical security awareness training builds a strong reporting culture.
Read → ArticleSecure File Sharing for Small Business: A Plain-English Guide
Emailing attachments and using consumer cloud apps quietly leaks business data. Here's what secure file sharing looks like, and how to get it right.
Read → ArticleMicrosoft 365 vs Google Workspace for Small Business
An honest UK comparison of Microsoft 365 and Google Workspace for small businesses: cost, apps, email, security and how easy each is to switch to.
Read → ArticleEmail Marketing for Small Business: Getting Started the Right Way
How to build a mailing list properly under UK PECR rules, pick the right tool, and get your emails delivered. A plain-English guide for small businesses.
Read → ArticleDomain Names and DNS Basics for Business: A Plain-English Guide
A jargon-free guide to domain names and DNS for business owners — what A, MX and TXT records do, why they matter for your website and email security.
Read → ArticleCyber Insurance for UK Small Businesses: What It Covers and How to Avoid a Denied Claim
What cyber insurance actually covers, why UK insurers now check for MFA and DMARC, what to put in place first, and the common reasons small-business claims get denied.
Read → GuideThe UK Small Business Cyber Security Starter Guide
A complete beginner's guide to cyber security for UK small businesses: the real threats, the controls that matter, Cyber Essentials, and where to get help.
Read →Other guide hubs
Cyber Security for UK Small Businesses
A plain-English guide to cyber security for UK small businesses: the real threats, the essential controls that stop most attacks, and where to get help.
Explore →Managed IT & Cloud Support for Small Businesses
A plain-English guide to managed IT, Microsoft 365, cloud, VoIP and scaling technology for UK small businesses. Start here, then explore the detail.
Explore →Data Protection & UK GDPR for Small Businesses
A plain-English guide to UK GDPR for small businesses: ICO registration, lawful basis, SARs, DPIAs, privacy notices, cookies and international data transfers.
Explore →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review — no jargon, no pressure.