ZeroSpams

Phishing and email spoofing protection

The fake invoice that looks like it came from your accounts team. The "urgent payment" email that seems to be from your manager. Spoofing and phishing target businesses of every size, and your domain can be used against your own customers.

Updated · 2 min read · By the ZeroSpams team

The short answer

Email spoofing is sending email that pretends to be from your domain; phishing uses it to trick people into paying, clicking or sharing passwords. Your domain is protected from spoofing by enforcing DMARC (quarantine or reject), so receivers throw away forged messages [1]. Your staff are protected by filtering, warnings on outside emails, and a few simple habits. We set up both.

What’s included

  • DMARC enforcement (p=quarantine or p=reject), reached safely after SPF and DKIM are fixed.
  • Protection for domains that don’t send email, which are often used for spoofing because nobody watches them.
  • A check for lookalike domains registered to imitate yours.
  • Warnings on external email in Google Workspace or Microsoft 365, so staff can see when a "colleague" writes from outside.
  • Anti-phishing and attachment and link protection settings in your email service, switched on and tuned.
  • A short guide for staff: how to spot a fake payment request, and what to do.

How we do it

  1. Check your domains, DMARC status and email service settings.
  2. Fix authentication for every legitimate sender.
  3. Enforce DMARC and lock down unused domains.
  4. Switch on the protection features in your email service.
  5. Brief your team, with a one-page guide.

Two different problems

  • Someone forges your domain to fool your customers or suppliers. The fix is on your domain: DMARC at quarantine or reject.
  • Someone sends your staff a convincing fake from another domain. The fix is in your mailboxes: filtering, external-sender warnings, and staff who know to check before paying.

Common questions

Can DMARC stop all phishing?

No. DMARC stops email that forges your exact domain. It doesn’t stop lookalike domains (like "yourcompany-invoices.com") or phishing sent to your staff from elsewhere; that’s why the service also covers your mailboxes and your team.

We don’t send email from some of our domains. Are they at risk?

Yes, often more. Unused domains without SPF and DMARC are easy to forge. We publish records saying they send no email, so receivers reject anything claiming to be from them.

Will this affect our normal email?

No, when done in stages: we fix every legitimate sender before enforcing DMARC.

Sources

Numbers in this guide come from these studies and publications. Links open the original.

  1. RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)IETF, 2015