Anyone Can Send Email as Your Company. Here Is What Stops Them
Ikram Massabini
August 21, 2026
A scammer does not need to break into your systems to defraud your clients using your name. They need your domain, which is public, and a mail server, which is free. They put your company in the From line, attach a plausible invoice, and ask a customer to update the banking details on file.
Nothing was hacked. Nothing triggered an alert. Your client received a message that appeared to come from you and acted on it, which is how a large share of business payment fraud begins.
This works because email was designed in an era that assumed good faith. The protocol that delivers mail does not verify that senders are who they claim to be. The From address carries about as much authority as a return address handwritten on an envelope.
Three DNS records close that gap. Most businesses have some of them in place, which is a different thing from being protected.
What each record actually does
These live in your DNS, at your registrar or DNS host. You publish them once, and receiving mail servers check them on every message claiming to come from your domain.
- SPF publishes the list of mail servers permitted to send on your behalf. When a message arrives claiming to be from you, the receiving server checks whether it came from a server on that list. Anything else fails.
- DKIM attaches a cryptographic signature to the messages you send. Your mail server signs with a private key, the matching public key sits in your DNS, and the receiving server verifies two things at once: the message genuinely originated from your domain, and nobody modified it in transit.
- DMARC gives the other two teeth. It tells receiving servers what to do with messages that fail, confirms the domain in the visible From address matches what SPF and DKIM verified, and reports on everyone sending mail under your name.
The setting that leaves most domains exposed
DMARC has three policy values, and this is where good intentions quietly stall out.
A policy of p=none instructs receiving servers to take no action on failures. It monitors and reports, nothing more. Your domain remains fully spoofable.
p=quarantine routes failing messages to junk. p=reject blocks them before delivery.
The common pattern is a business that publishes DMARC at p=none, watches reports for a few weeks, and never advances. The record exists, an audit checkbox gets ticked, and the domain is no better defended than before. Protection begins at quarantine and is complete at reject. Microsoft’s published guidance points in the same direction: treat reject as the destination, and get there once the reports show your real mail passing cleanly.
If you have ever been told your domain is “set up with DMARC,” the useful follow-up question is which policy value it is running.
What these records will not catch
Authentication protects your exact domain. Two related attacks fall outside it.
Lookalike domains are the first. A scammer registers something adjacent to yours, a hyphenated variant or a different top-level domain, and sends from a domain they legitimately control. Your records govern your domain, not theirs.
Display-name spoofing is the second. The name in the From line reads like your accounting department while the actual address behind it is a free webmail account. DMARC evaluates the domain, not the friendly name.
Both still require the human habits that catch any phishing attempt: reading the full address, and confirming any request to change payment details by calling a number you already had.
Why this matters even for low-volume senders
The obvious reason is protection, keeping criminals from impersonating your domain to clients, suppliers, and staff.
The less obvious one is deliverability. Since February 2024, Google and Yahoo have required SPF, DKIM, and DMARC from bulk senders, and Microsoft extended comparable requirements to Outlook.com and Hotmail through 2025, first routing non-compliant mail to junk and then rejecting it. Even well below those thresholds, an authenticated domain lands in the inbox more reliably.
How to find out where you stand
Free DMARC and SPF lookup tools will tell you which records exist on your domain in about thirty seconds, though they say nothing about whether those records are correct or which policy DMARC is enforcing.
Fixing them properly belongs with whoever manages your DNS, because a careless change sends your own legitimate mail to spam. The rollout is deliberately staged: publish SPF and DKIM covering every real source of your mail, add DMARC at p=none and read the reports until nothing legitimate is failing, then move to quarantine and finally reject.
A twenty-minute answer for your domain
MVP Network Consulting handles this for businesses across Buffalo and Western New York. We will check what your domain publishes today, tell you whether it can be spoofed right now, and run the staged rollout to reject without stranding your own email. Ask us for a look at your records.