How to Stop Email Spoofing in Your Shop's Name
The phone rings on a Thursday afternoon. It's the purchasing manager at your best customer — the account that keeps two of your machines busy. She's calling to confirm the new bank account before accounts payable releases payment on last month's order.
You didn't change your bank account. You never sent that email.
But she's looking right at it: your domain in the From line, your logo, something close enough to your signature. That's email spoofing, and the uncomfortable part is that it required no hacking at all. Nobody broke into your server or guessed a password. A scammer typed your domain into the From field and hit send — and unless your domain is set up to stop it, the message sails through.
What makes it dangerous for a shop is that the scam rarely targets you directly. It targets the people who pay you and the people you pay. A fake "updated remittance details" email to your customer's accounts payable. A fake invoice to your bookkeeper that looks like it came from your steel supplier. One convincing message, and a payment for parts you already shipped lands in a criminal's account — while your customer believes, in good faith, that they paid you.
The fix is three settings on your domain, called SPF, DKIM, and DMARC. Here's the plain-English version we walk through with shops around Parkesburg and across Chester and Lancaster County: what each record does, the setting most businesses get wrong, and how to find out where your own domain stands.
Why Scammers Can Send Email in Your Shop's Name
Email was built in a more trusting era. On its own, the system that delivers mail never checks that a sender is who they claim to be. The From line on an email is about as trustworthy as the return address handwritten on an envelope — anyone can write anything there, and the message still gets delivered.
Spoofing simply takes advantage of that. A scammer puts your domain in the From field and sends the message. Unless your domain tells receiving mail servers how to spot the fake, they have no reason to question it, and the email lands in your customer's inbox looking exactly like it came from your front office. It's common enough that the UK's National Cyber Security Centre publishes anti-spoofing guidance aimed at precisely this problem.
And think for a second about what "email from your shop" actually is:
- Quotes going out to purchasing managers
- Order confirmations and ship notices from JobBOSS, E2, or QuickBooks
- Invoices and payment terms from the office manager
- POs to your material and tooling suppliers
Every one of those is a message a scammer can imitate — and a customer relationship they can burn while doing it.
The Three DNS Records That Stop Email Spoofing
Three records work together to prove a message really came from your domain. They live in your DNS — the same place your website address lives. You set them up once, and receiving mail servers check them automatically on every message you send.
SPF: the guest list
SPF (Sender Policy Framework) is a published list of the mail servers allowed to send email for your domain. When a message arrives claiming to be from you, the receiving server checks whether it came from a server on your list. Not on the list? It gets flagged.
DKIM: the signature
DKIM (DomainKeys Identified Mail) adds a tamper-proof signature to every message you send. The receiving server verifies it and confirms two things: the message genuinely came from your domain, and nobody altered it in transit — nobody swapped the bank account number on the invoice, for instance.
DMARC: the bouncer
DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the first two together and tells receiving servers what to do with a message that fails the check — let it through, junk it, or turn it away at the door. It also confirms that the address your customer sees matches the domain that actually passed the checks, which is the part that stops someone forging your exact address. And it sends you reports showing everyone sending email as your domain — including the senders who shouldn't be.
The DMARC Setting Most Shops Get Wrong
Here's where most businesses stumble — not by missing DMARC entirely, but by running it in a mode that doesn't protect anything.
DMARC has three policy settings:
- p=none — monitor only. Fakes still get delivered; you just get a report about it.
- p=quarantine — failing messages go to the junk folder.
- p=reject — failing messages are turned away before they ever arrive.
A lot of businesses set DMARC to p=none, watch the reports roll in, and never move past it. At p=none, your domain can still be spoofed all day long. Real protection only starts at quarantine or reject — Microsoft's own guidance is to work toward p=reject once you've confirmed your legitimate mail passes. If somebody set this up for you years ago and hasn't touched it since, this one setting is worth checking today.
What SPF, DKIM, and DMARC Don't Stop
These records stop someone from forging your exact domain. Two tricks slip past them, and both are worth two minutes with whoever pays your bills.
Lookalike domains. A scammer registers a domain that resembles yours — yourshopname-invoices.com, or .co instead of .com — and sends from that. Your records protect your real domain, not the copycat the scammer owns.
Display-name spoofing. The name shown in the inbox can read "Your Shop Accounts" while the address behind it is a random free webmail account. DMARC checks the domain, not the display name.
The defense for both is a habit, not a setting — the same habit that catches any phishing email. Check the full email address, not just the name. And verify any request to change payment details by calling a number you already have on file, never one from the email itself. Make that an office rule the way lockout/tagout is a floor rule: no exceptions, no matter how busy the week gets.
Why This Matters Even If You Only Email Quotes and Invoices
"We're a twenty-person shop — we barely send email" is the usual objection. Two reasons it doesn't hold up.
Protection. These records keep scammers from using your name against your customers, your suppliers, and your own office. Your size doesn't matter to the person impersonating you — if anything, small shops make appealing targets, because their customers rarely expect fraud from them.
Deliverability. The big mailbox providers have stopped being patient with unauthenticated email. Since February 2024, Google and Yahoo have required high-volume senders to use SPF, DKIM, and DMARC, and Microsoft began applying similar requirements to Outlook and Hotmail accounts in 2025 — first routing non-compliant mail to junk, then rejecting it. Even well below those volumes, an authenticated domain is far more likely to reach the inbox than the spam folder.
For a shop, "the spam folder" has a specific price tag: the quote a purchasing manager never saw, the order confirmation that "never arrived," the invoice that ages thirty days because it sat in junk. If customers keep telling you "we didn't get your email," this is one of the first things worth checking.
How to Check and Fix Your Shop's Domain
You can get a rough read in five minutes. Making it right takes a careful sequence, because these records live in your DNS and a mistake can send your own legitimate quotes and invoices to spam. The rollout is done in stages, and nobody should skip to the end.
1. See where you stand
Free SPF and DMARC checkers let you type in your domain and see which records exist. That tells you whether the records are present — not whether they're configured correctly, or whether DMARC is sitting uselessly at p=none.
2. Cover everything that sends email as you
SPF and DKIM need to account for every legitimate source of your email: your mail service, your ERP or accounting system if it sends invoices and order confirmations directly, your quoting tools, a marketing platform if you use one. Miss one, and its mail starts failing the very checks meant to protect you.
3. Turn on DMARC in monitor mode and read the reports
Start at p=none and watch the reports for a few weeks. This is where you find the mail source nobody remembered — and where you confirm your real mail passes before anything gets blocked.
4. Move to quarantine, then reject
Once the reports come back clean, step up to p=quarantine, then p=reject. That's the point where your domain is actually protected, not just monitored.
This is a job for whoever manages your IT — it touches DNS, your mail service, and every system that sends on your behalf. Done right, it's invisible: your mail keeps flowing, and the fakes stop.
The Quiet Bonus: Easier Insurance Renewals and Customer Questionnaires
Email authentication has a way of showing up in two documents shop owners have learned to dread: the cyber insurance renewal application and the vendor security questionnaire from a big customer. Both increasingly ask how you prevent email impersonation and payment fraud, and "SPF, DKIM, and DMARC at enforcement" is exactly the answer they're looking for.
Getting these records right before the renewal or the questionnaire lands means one less blank you can't fill in. It's part of the cyber-insurance compliance package we build for manufacturers — set up the controls, document them, and hand the paperwork straight to your broker or your customer's security team.
Email Spoofing FAQs for Small Manufacturers
What is email spoofing?
Email spoofing is when a scammer sends a message with your domain in the From address so it appears to come from your company. It's typically used to trick your customers, suppliers, or office staff into paying fake invoices or changing banking details. No hacking is required — without the right DNS records, anyone can send email as your domain.
What are SPF, DKIM, and DMARC in plain English?
SPF is a guest list of the servers allowed to send email for your domain. DKIM is a tamper-proof signature proving a message came from you and wasn't altered. DMARC ties them together, tells receiving servers to junk or reject messages that fail, and sends you reports on who is sending email as your domain.
Will setting up DMARC block my own quotes and invoices?
Not if you roll it out in stages. Starting DMARC at p=none (monitor mode) lets you confirm your real mail — including invoices and confirmations from your ERP or accounting software — passes the checks before anything gets blocked. Problems come from skipping straight to reject without checking first.
Does DMARC stop every fake email?
No. DMARC stops scammers from forging your exact domain. It doesn't stop lookalike domains (yourshop-invoices.com) or display-name spoofing, where the sender name shows your company but the address behind it is different. Those still require alert staff and a firm rule to verify payment changes by phone.
Do we need these records if we only send a few emails a day?
Yes. The records protect your domain from being impersonated no matter how much you send, and they keep the email you do send out of spam folders. Google, Yahoo, and Microsoft now expect authentication, and unauthenticated mail — including your quotes and invoices — is more likely to be filtered.
How do I find out if our domain can be spoofed?
Type your domain into any free SPF/DMARC checker to see which records exist. If DMARC is missing — or set to p=none — your domain can currently be spoofed. A proper review goes further, confirming the records cover every system that sends email for you, from your mail service to your ERP.
Not Sure Whether Your Domain Is Protected?
Starlux IT provides IT support for manufacturers in Parkesburg, Coatesville, Downingtown, Gap, and across Chester and Lancaster County. We know how shop email actually works — quotes, confirmations, and invoices coming out of systems like JobBOSS, E2, and QuickBooks — and we set up email authentication so the fakes get blocked while your real mail keeps landing in inboxes. It's the same work that satisfies cyber insurance applications and customer security questionnaires, documented and ready to hand over.
Give us 30 minutes, free, no pressure. We'll check your domain, show you exactly where the gaps are, and you'll know where you stand — whether you hire us or not.
Check My Domain — Free 30-Minute Review →