Site AI Auditde la Internet Solutions

Invoice Fraud by Email: How Small Businesses Stay Protected

17 septembrie 20267 min de cititLivrabilitatea e-mailurilor
Invoice Fraud by Email: How Small Businesses Stay Protected

Short answer: Invoice fraud, a form of business e-mail compromise, tricks a company or its customers into paying a criminal, usually by sending a fake invoice or a message announcing “new bank details”. Protect your business on three fronts: stop criminals from sending mail as your exact domain with SPF, DKIM and an enforcing DMARC policy; secure mailboxes with two-factor authentication and checks for hidden forwarding rules; and adopt a simple rule that any change of payment details is confirmed by phone using a number already on file.

How invoice fraud works

The schemes vary, but most follow one of a few patterns:

Small businesses are attractive targets for a simple reason: they often have fewer approval steps, fewer security tools and staff who handle several roles at once. A single person may receive the invoice, approve it and make the transfer on the same afternoon, with nobody else in the loop to notice something odd.

What makes these attacks effective is that they rarely contain malware or obvious spam signals. They are ordinary-looking business messages, often well written, sent at a plausible moment.

Layer 1: stop exact-domain spoofing with DMARC

If criminals can send mail with your exact domain in the From address and receivers accept it, your customers have little chance of spotting the fake. DMARC with an enforcing policy tells receivers to reject or quarantine such messages.

  1. Publish SPF listing your legitimate senders.
  2. Set up DKIM with your own domain in your mail provider and every tool that sends invoices, reminders or quotes, including accounting and invoicing software.
  3. Publish DMARC with p=none and a report address, then use the reports to fix any unaligned legitimate sender.
  4. Move to p=quarantine and then p=reject, and make sure subdomains are covered.
  5. Protect unused domains you own with v=spf1 -all and DMARC p=reject.

Invoicing software deserves special attention: it is exactly the mail criminals imitate, and it is often the last system to be authenticated. If your invoices fail DMARC, enforcement will hurt you; if they are not aligned before enforcement, you cannot enforce at all.

Layer 2: secure the mailboxes

DMARC cannot help when a criminal sends from inside a real, compromised mailbox, because that mail is genuinely authenticated. Mailbox security is therefore just as important:

Layer 3: payment verification rules

Technology reduces the risk; a simple process stops the remaining attacks. The most effective rules are short enough that everyone remembers them:

The same rules apply in the other direction. If your company announces a genuine change of bank details, do it in a way customers can verify: tell them in advance by phone or letter, not only by e-mail, and invite them to call you to confirm.

Write the rules down, include them in onboarding for finance staff, and make it explicit that nobody will be criticised for delaying a payment to verify it.

Layer 4: tell your customers

Your customers are targets too, because criminals impersonate you to them. Help them protect themselves and you:

Layer 5: watch for lookalike domains

Lookalike domains are the attacker’s answer to DMARC. Once your exact domain is protected, a criminal can register yourdomain-invoices.com, a version with a swapped or doubled letter, or the same name under a different top-level domain, and send fully authenticated mail from it. Technical records on your domain cannot stop that, but several measures reduce the risk:

When you find a lookalike domain used for fraud, report it to the registrar’s abuse contact and to the hosting provider, and warn customers who may be targeted. Takedowns are not always fast, which is why the payment verification rule remains the most reliable defence.

Recognising the warning signs

SignWhy it matters
New or changed bank accountThe core of almost every invoice fraud
Slightly different sender domainLookalike domains pass authentication
Reply-To differs from FromReplies go to the criminal, not the real sender
Unusual urgency or secrecyPressure prevents verification
Change of tone or language in a known threadMay indicate a compromised mailbox
Request to switch to another channel or personal addressMoves the conversation away from records and colleagues

If it happens

  1. Contact your bank immediately. Speed matters for any chance of stopping or recalling a transfer.
  2. Report the crime to the police or the relevant national fraud reporting service.
  3. Secure the affected mailboxes: reset passwords, enforce two-factor authentication, remove unknown forwarding rules and sessions.
  4. Warn affected customers or suppliers.
  5. Review DMARC reports and mail logs to understand whether the attack used spoofing, a lookalike domain or a compromised account.
  6. Fix the gap that allowed it, whether technical or procedural.

Checking your domain’s defences

The technical part of layer 1 is visible from outside. Site AI Audit checks whether your domain has SPF (within the lookup limit), DKIM and a DMARC policy, and whether that policy actually enforces, alongside MX records and the website’s SSL and security headers. Findings are explained in plain words with the fix. A free check shows your current protection; paid plans on the pricing page monitor it and alert you if a record is removed or weakened.

Related reading

The bottom line

Invoice fraud combines technical tricks with human pressure, so the defence must do both. Enforce DMARC so your exact domain cannot be forged, secure mailboxes against takeover, verify every change of bank details by phone, and tell customers how you communicate payment information. Each layer covers gaps the others leave open.

FAQ

Can DMARC stop invoice fraud?

It stops fraud that forges your exact domain. It does not stop lookalike domains or attacks from compromised mailboxes, which is why mailbox security and payment verification are also needed.

What is business e-mail compromise?

It is a type of fraud in which criminals impersonate or take over business e-mail accounts to trick people into paying money or sending sensitive information.

How do criminals know when to send a fake invoice?

Often they have access to a real mailbox and read ongoing conversations, or they time messages to typical billing periods. Hidden forwarding rules are a common sign of such access.

What should I do if a supplier asks to change bank details?

Call the supplier using a phone number from your own records, not from the message, and confirm the change before paying.

Should I check mailbox forwarding rules?

Yes. Attackers often create rules that forward or hide messages. Review them regularly and consider blocking automatic forwarding to external addresses.

How can I stop criminals from using lookalike domains?

You cannot prevent registration, but you can monitor for lookalikes, tell customers how you communicate, and rely on payment verification rules that work regardless of the sender’s domain.

#Checklists#DMARC#Email Authentication#Email Security
Verifică-ți propriul site — gratuit.Ce să repari pe site — și de unde să începi.
Începe gratuit

Mai multe de pe blog

Toate articolele →
Internet Solutions

Mai multe de la echipa noastră

Create de Internet Solutions. Încearcă și celelalte produse ale noastre — fiecare îți economisește timp în alt fel.

internet-solutions.net ↗
Site AI Audit
Prezentare generală a confidențialității

Acest site folosește cookie-uri pentru a-ți oferi cea mai bună experiență posibilă. Informațiile din cookie-uri sunt stocate în browserul tău și îndeplinesc funcții precum recunoașterea ta când revii pe site și ajutarea echipei noastre să înțeleagă ce secțiuni ale site-ului găsești cele mai interesante și utile.