Home 9 Business 9 Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be Your Company Today?

Imagine one of your customers receives an email from what appears to be your accounts department.

The branding looks correct.

The signature looks genuine.

The email address seems legitimate.

The message simply says:

“We’ve changed our bank details. Please send future payments to the account below.”

Your customer follows the instructions.

Thousands of pounds disappear.

The problem? The email never came from your business.

It was sent by a cyber criminal pretending to be you.

This type of attack is known as email spoofing, and it remains one of the most effective ways criminals trick clients, suppliers and staff into making payments, revealing information, or downloading malicious files.

Fortunately, there are three powerful technologies that can make this dramatically harder: SPF, DKIM and DMARC.


Why Scammers Can Send Emails Using Your Company Name

Email was designed decades ago when trust was assumed rather than verified.

Unlike logging into your bank account or Microsoft 365, traditional email doesn’t automatically prove that the sender is who they claim to be.

Think of the “From” address on an email like a return address written on an envelope. Anyone can write anything they want there.

Unless protections are in place, cyber criminals can create emails that appear to come directly from your organisation.

The UK’s National Cyber Security Centre (NCSC) specifically recommends anti-spoofing controls to prevent criminals abusing your company’s identity.

Expert Insight

“DMARC allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks.”

— National Cyber Security Centre


A Real-World Example

Let’s imagine your business is called ABC Engineering Ltd.

A criminal doesn’t need to hack your systems.

They don’t need your password.

They don’t even need access to Microsoft 365.

Instead, they simply create an email that appears to come from:

accounts@abcengineering.co.uk

A supplier receives the message requesting payment to a new bank account.

Everything looks genuine.

The payment is made.

The fraud isn’t discovered until days later.

This form of attack is known as Business Email Compromise (BEC), and it successfully targets organisations of every size because it exploits trust rather than technology.


The Three Records That Stop Email Spoofing

Three DNS records work together to prove your emails genuinely come from your organisation.

These are published once in your domain settings and then checked automatically every time you send an email.

SPF (Sender Policy Framework)

SPF acts as an authorised mailing list.

It tells receiving email servers which systems are allowed to send email on behalf of your domain.

If an unauthorised server attempts to send email pretending to be you, SPF helps identify it as suspicious.

DKIM (DomainKeys Identified Mail)

DKIM adds a unique digital signature to every email you send.

This confirms two important things:

  • The email genuinely came from your organisation.
  • The content hasn’t been tampered with during delivery.

DMARC (Domain-based Message Authentication, Reporting & Conformance)

DMARC ties SPF and DKIM together.

It tells receiving mail systems exactly what to do when an email fails authentication.

It also generates reports showing who is sending email using your domain.

Think of DMARC as the security guard that decides whether suspicious visitors are allowed through the door.



Visual illustration showing SPF, DKIM and DMARC protecting company emails from spoofing attacks

The DMARC Setting That Creates a False Sense of Security

This is one of the most common issues we encounter when reviewing business email security.

Many organisations have DMARC enabled but believe they are protected when they are not.

Policy 1: p=none

This policy only monitors activity.

Suspicious emails are still delivered.

You receive reports, but the spoofed emails are not blocked.

Policy 2: p=quarantine

Suspicious emails are diverted to spam or junk folders.

Policy 3: p=reject

Suspicious emails are blocked completely before they reach the recipient.

Think of it this way:

p=none is like installing CCTV but leaving all your doors unlocked.

You can see what criminals are doing, but you’re not actually stopping them.

Real protection begins when organisations move beyond monitoring and start actively enforcing DMARC policies.


What SPF, DKIM and DMARC Don’t Prevent

These protections are extremely effective, but they aren’t magic.

There are still two common attacks businesses should be aware of.

Lookalike Domains

A criminal could register a domain such as:

  • yourcompany-services.co.uk
  • yourcompany-invoices.com
  • yourcompanny.co.uk

Because they own that domain, your DMARC settings cannot stop them using it.

Display Name Spoofing

A criminal could send an email from a Gmail address whilst displaying:

“Your Company Accounts Team”

The displayed name looks genuine even though the actual address is unrelated.

This is why staff awareness and payment verification procedures remain essential.


Why This Matters Even If You Don’t Send Marketing Emails

Many business owners assume these protections only matter for high-volume email senders.

That’s not the case.

There are two significant benefits:

1. Protect Your Reputation

SPF, DKIM and DMARC make it much harder for criminals to impersonate your organisation.

That protects your customers, suppliers and staff.

2. Improve Email Deliverability

Email providers increasingly expect authentication controls to be present.

Without them, legitimate emails are more likely to be filtered, delayed or marked as spam.

If you’re sending quotes, invoices, contracts or customer updates, that’s a problem worth avoiding.


Five Warning Signs Your Domain May Not Be Fully Protected

  • You don’t know whether SPF, DKIM or DMARC are configured.
  • Your DMARC policy remains set to p=none.
  • You use multiple platforms to send email.
  • Customers have reported suspicious emails claiming to come from you.
  • Your emails occasionally land in spam folders.

If any of these sound familiar, it’s worth carrying out a review.


How to Check Your Domain

Several free online tools can quickly identify whether SPF, DKIM and DMARC records exist for your domain.

However, having records present does not necessarily mean they’re configured correctly.

Many businesses discover that systems such as website contact forms, marketing platforms, CRM systems or third-party services have been overlooked.

A proper review ensures all legitimate senders are authenticated before DMARC enforcement is introduced.


How Bespoke IT Solutions Can Help

Email spoofing is one of the easiest ways cyber criminals damage trust, steal money and impersonate businesses.

The good news is that it is also one of the most preventable.

At Bespoke IT Solutions, we help organisations across Hampshire, Surrey and Berkshire assess, configure and monitor:

  • SPF Records
  • DKIM Authentication
  • DMARC Monitoring & Enforcement
  • Microsoft 365 Email Security
  • Anti-Phishing Protection
  • Email Deliverability Improvements

We’ll identify gaps, ensure all legitimate mail systems are authenticated and help move your domain safely towards full DMARC protection.

Don’t wait until a customer receives a fake invoice appearing to come from your business.

Book Your Email

No. DMARC prevents criminals spoofing your domain but does not stop lookalike domains or display-name impersonation.

Can DMARC break email delivery?

If implemented incorrectly, yes. That’s why businesses should start with monitoring before moving to enforcement.

Are SPF, DKIM and DMARC required for Microsoft 365?

They are strongly recommended and increasingly expected by major email providers to improve both security and deliverability.

Recent Posts

How Outsourcing Is Driving Innovation in UK Businesses

How Outsourcing Is Driving Innovation in UK Businesses

Beyond Cost Savings: Outsourcing for Innovation Why UK businesses are turning IT partners into growth drivers The problem For a long time, outsourcing was just about saving money. You handed over IT tasks, reduced costs, and kept things running. But today, that...

How secure is your backup solution?

How secure is your backup solution?

Immutable Backups: The Cyber Insurance Question That Catches Businesses Out Immutable backups are now one of the most important parts of cyber insurance and ransomware protection. However, many businesses are not sure what they are or whether they already have them in...

What to do in case of a cyber attack

What to do in case of a cyber attack

Cyberattack? Here's Exactly What Your Business Should Do in the First Hour It's 2pm on a normal Monday. Your team are busy working, emails are flowing, and everything seems normal. Then suddenly something isn't right. Files won't open. Systems are running strangely. A...

Small businesses are still targets of cyber attacks.

Small businesses are still targets of cyber attacks.

A ransomware attack on a small business does not happen overnight. Instead, it builds step by step, often starting with simple mistakes that go unnoticed. In fact, many attacks succeed because of small gaps rather than complex hacking. So in this guide, we will walk...

Microsoft 365 Copilot: Why Permissions Matter More Than You Think

Microsoft 365 Copilot: Why Permissions Matter More Than You Think

Microsoft 365 Copilot: Why Permissions Matter More Than You Think If you’re thinking about using Microsoft 365 Copilot, you’re probably excited about what it can do. But here’s the reality most businesses miss. Copilot doesn’t create new risk. It exposes what’s...

Plan for offboarding from day one.

Plan for offboarding from day one.

Offboarding problems don’t start when someone leaves. They start on day one   When someone leaves your business, things can feel rushed and messy. You’re chasing logins, tracking down devices, and trying to work out what they had access to. However, most of these...

Managing the cloud sprawl.

Managing the cloud sprawl.

Cloud Sprawl Management Take control of your cloud, reduce stress, and let your business grow without the chaos. Cloud sprawl management is now one of the biggest challenges facing growing businesses. While cloud systems help you move faster, they can also create...

FortiBleed – Cyber Attack News

FortiBleed – Cyber Attack News

FortiBleed: Why This Cyber Attack Is Different And What You Need To Do Now The problem There’s a new cyber threat making headlines and it’s not what most people expect. FortiBleed is a global campaign targeting Fortinet firewalls and VPN systems. These are the tools...

UK’s Tech Talent Crunch.

UK’s Tech Talent Crunch.

UK Tech Talent Shortage Solutions Why hiring is harder than ever and what you can do about it If you’re struggling to hire IT staff, you’re not alone. Many businesses across the UK are facing the same challenge. UK tech talent shortage solutions are now essential for...

Outsourcing Is Changing – And It’s Becoming a Growth Strategy

Outsourcing Is Changing – And It’s Becoming a Growth Strategy

Strategic IT Outsourcing UK: A Smarter Way to Grow The problem: many UK businesses are under pressure. Costs are rising, skilled IT staff are hard to find, and keeping systems secure is getting harder. The answer: strategic IT outsourcing UK gives you access to expert...