You got a call from a client saying they received a strange email from your company asking them to change bank details. Or a supplier telling you they sent payment to an account you don't recognise. Or your own customers warning you that emails pretending to be from you are hitting their inboxes.

This is called Business Email Compromise — or just email spoofing — and it's one of the most damaging scams targeting small businesses right now. Here's exactly what's happening and what you can do about it.

What's Actually Happening

There are two ways fraudsters send fake emails pretending to be your business:

1. Domain Spoofing

They register a domain that looks almost identical to yours — acme-corp.com instead of acmecorp.com, or acmecorp.net instead of acmecorp.com — and set up email on that fake domain. To a busy client glancing at their inbox, it looks legitimate.

2. Email Header Spoofing

More technically sophisticated — they forge the "From" header in an email so it appears to come from your actual domain even though it was sent from somewhere else entirely. This exploits missing or misconfigured email authentication on your domain.

Both are serious. Domain spoofing requires taking down the fake domain. Header spoofing requires fixing your own domain's email security settings.

Step 1 — Get the Email Headers

Ask whoever received the fake email to forward it to you with full email headers. In Gmail this is done by opening the email, clicking the three dots, and selecting "Show original." In Outlook it's File → Properties.

The headers reveal the actual sending IP address and domain — not just what the fraudster wants you to see. Look for the Return-Path and Received fields. This tells you whether they're spoofing your domain directly or sending from a fake lookalike domain.

Step 2 — Identify the Fake Domain

If the headers show a domain that isn't yours but looks like it — that's the fake domain you need to take down. Look it up on WHOIS to find out who registered it and who is hosting it.

If the headers show your own domain as the sender, skip to Step 4 — the problem is your email authentication, not a fake domain.

Step 3 — Take Down the Fake Domain

Once you've identified the fake domain, you need to contact the registrar and hosting provider and request immediate suspension. File abuse reports with:

Be specific in your abuse reports. Include the email headers, screenshots, dates, and a clear explanation of the fraud. Generic reports get ignored. Specific, evidence-backed reports get acted on.

Speed matters here. Every hour the fake domain is active, more of your clients or suppliers could receive fraudulent emails. File reports the same day you discover it.

Step 4 — Fix Your Own Email Authentication

Whether or not there's a fake domain involved, if fraudsters can send emails appearing to come from your domain, your email authentication records need fixing. Three records protect your domain:

SPF (Sender Policy Framework)

Tells the world which mail servers are authorised to send email on behalf of your domain. If you don't have an SPF record, anyone can send email pretending to be you. Add one through your domain's DNS settings.

DKIM (DomainKeys Identified Mail)

Adds a cryptographic signature to every email you send so recipients can verify it genuinely came from you. Your email provider (Google Workspace, Microsoft 365) can generate this for you.

DMARC (Domain-based Message Authentication)

The most important one. DMARC tells receiving mail servers what to do if SPF or DKIM fails — quarantine the email, reject it, or do nothing. If you have no DMARC record or it's set to p=none, you have no protection. Set it to p=quarantine or p=reject.

Check your DMARC right now. Go to MXToolbox.com and search your domain. If it says "No DMARC record found" or shows p=none, your domain can be spoofed by anyone. This is the single most important thing you can fix today.

Step 5 — Warn Your Clients and Suppliers

Send a clear communication to your clients and suppliers as soon as possible:

This is the fastest way to limit the damage while the technical takedown is in progress.

How Long Will This Take?

Getting a fake domain suspended typically takes 24-72 hours with a cooperative registrar. Spamhaus listings can happen within hours and immediately start blocking the fraudulent emails from reaching inboxes globally.

Fixing your SPF, DKIM, and DMARC records can be done in an afternoon if you have access to your domain's DNS settings. The effects propagate across the internet within 24-48 hours.

Don't Want to Handle This Yourself?

BOO! specialises in exactly this — taking down fake domains being used for email fraud and business email compromise. We handle the abuse reports, the registrar contacts, and the escalations. You focus on managing your clients.

$200 flat fee, only charged if we successfully take down the fake domain. If we can't get it done, you owe us nothing.