You got a call from a client saying they received a strange email from your company asking them to change bank details. Or a supplier telling you they sent payment to an account you don't recognise. Or your own customers warning you that emails pretending to be from you are hitting their inboxes.
This is called Business Email Compromise — or just email spoofing — and it's one of the most damaging scams targeting small businesses right now. Here's exactly what's happening and what you can do about it.
What's Actually Happening
There are two ways fraudsters send fake emails pretending to be your business:
1. Domain Spoofing
They register a domain that looks almost identical to yours — acme-corp.com instead of acmecorp.com, or acmecorp.net instead of acmecorp.com — and set up email on that fake domain. To a busy client glancing at their inbox, it looks legitimate.
2. Email Header Spoofing
More technically sophisticated — they forge the "From" header in an email so it appears to come from your actual domain even though it was sent from somewhere else entirely. This exploits missing or misconfigured email authentication on your domain.
Both are serious. Domain spoofing requires taking down the fake domain. Header spoofing requires fixing your own domain's email security settings.
Step 1 — Get the Email Headers
Ask whoever received the fake email to forward it to you with full email headers. In Gmail this is done by opening the email, clicking the three dots, and selecting "Show original." In Outlook it's File → Properties.
The headers reveal the actual sending IP address and domain — not just what the fraudster wants you to see. Look for the Return-Path and Received fields. This tells you whether they're spoofing your domain directly or sending from a fake lookalike domain.
Step 2 — Identify the Fake Domain
If the headers show a domain that isn't yours but looks like it — that's the fake domain you need to take down. Look it up on WHOIS to find out who registered it and who is hosting it.
If the headers show your own domain as the sender, skip to Step 4 — the problem is your email authentication, not a fake domain.
Step 3 — Take Down the Fake Domain
Once you've identified the fake domain, you need to contact the registrar and hosting provider and request immediate suspension. File abuse reports with:
- The domain registrar — found via WHOIS lookup
- The hosting provider — found via IP address lookup
- Spamhaus — to block emails from the fake domain globally
- Google Safe Browsing — to flag any associated fake website
Be specific in your abuse reports. Include the email headers, screenshots, dates, and a clear explanation of the fraud. Generic reports get ignored. Specific, evidence-backed reports get acted on.
Speed matters here. Every hour the fake domain is active, more of your clients or suppliers could receive fraudulent emails. File reports the same day you discover it.
Step 4 — Fix Your Own Email Authentication
Whether or not there's a fake domain involved, if fraudsters can send emails appearing to come from your domain, your email authentication records need fixing. Three records protect your domain:
SPF (Sender Policy Framework)
Tells the world which mail servers are authorised to send email on behalf of your domain. If you don't have an SPF record, anyone can send email pretending to be you. Add one through your domain's DNS settings.
DKIM (DomainKeys Identified Mail)
Adds a cryptographic signature to every email you send so recipients can verify it genuinely came from you. Your email provider (Google Workspace, Microsoft 365) can generate this for you.
DMARC (Domain-based Message Authentication)
The most important one. DMARC tells receiving mail servers what to do if SPF or DKIM fails — quarantine the email, reject it, or do nothing. If you have no DMARC record or it's set to p=none, you have no protection. Set it to p=quarantine or p=reject.
Check your DMARC right now. Go to MXToolbox.com and search your domain. If it says "No DMARC record found" or shows p=none, your domain can be spoofed by anyone. This is the single most important thing you can fix today.
Step 5 — Warn Your Clients and Suppliers
Send a clear communication to your clients and suppliers as soon as possible:
- Tell them you are aware fraudulent emails are being sent using your name
- Tell them never to action payment changes or unusual requests received by email without calling you directly to verify
- Give them a verified phone number to call
- Tell them you will never ask them to change payment details by email alone
This is the fastest way to limit the damage while the technical takedown is in progress.
How Long Will This Take?
Getting a fake domain suspended typically takes 24-72 hours with a cooperative registrar. Spamhaus listings can happen within hours and immediately start blocking the fraudulent emails from reaching inboxes globally.
Fixing your SPF, DKIM, and DMARC records can be done in an afternoon if you have access to your domain's DNS settings. The effects propagate across the internet within 24-48 hours.
Don't Want to Handle This Yourself?
BOO! specialises in exactly this — taking down fake domains being used for email fraud and business email compromise. We handle the abuse reports, the registrar contacts, and the escalations. You focus on managing your clients.
$200 flat fee, only charged if we successfully take down the fake domain. If we can't get it done, you owe us nothing.