Try free for 14 days

Protection against fraud

Preventing fake invoice emails: a guide for SMEs

An email from a familiar supplier: “Our bank details have changed, please pay the outstanding invoice to the new account.” Such fraud emails are among the costliest attacks on SMEs. They need no malware and look genuine.

3 min readHow well is your domain protected? Check my domain for free

Key points at a glance

  • Fake invoice emails need neither links nor attachments – which is why filters often fail to catch them.
  • DMARC with p=reject stops fraudsters from misusing your own domain as the sender.
  • The most effective rule: always confirm new bank details by calling back on a known number.

The three most common scams

  • Spoofed sender: the email carries the genuine domain of your company or a supplier. This works when that domain is not protected with DMARC p=reject.
  • Lookalike domain: fraudsters register a domain that looks almost identical, for example with swapped letters or a different ending.
  • Hijacked mailbox: a genuine account has been hacked; the fraudsters read along and insert themselves into an ongoing invoice exchange.

Why this is so dangerous

Such emails often contain neither links nor attachments. Virus scanners and spam filters therefore often fail to flag them – the email looks like a completely normal business email.

Technical protection

  • DMARC with p=reject on all your domains, including those that send no email.
  • Monitor similarly spelled domains so you can warn people early.
  • Multi-factor authentication (MFA) for all mailboxes, so accounts cannot be hijacked.
  • Visibly flag external emails in the mailbox.

Organisational protection: the key rule

No technology replaces a clear process: changes to bank details are never accepted by email alone. Call the supplier on a number you already know – not the number given in the email. Payments to new accounts need a second person to approve them.

The call-back rule for new bank details
  1. Email with new bank detailsDon’t reply, and don’t pay anything yet.
  2. Call backCall the supplier on a number you already know, never the number given in the email.
  3. Four-eyes principleA second person approves the payment to the new account.
  4. Only then payUpdate the confirmed bank details in your system and trigger the payment.

If it has already happened

Inform your bank immediately – a payment can often still be stopped within the first few hours. File a report with the police, keep the email with all its headers, and check whether a mailbox has been hijacked (change the password, check forwarding rules).

Keep an emergency number handy

Keep your bank’s emergency number somewhere your accounting team can find it immediately. In cases of fraud, every hour counts.

How DomainRadar helps

DomainRadar shows whether your domains are protected against forgery, guides you to p=reject, reports similarly spelled domains and alerts you when forgeries in your name appear in the DMARC reports.

The domain check stays free. Afterwards you test Business for 14 days – no credit card, the trial ends on its own.

More guides

How does your domain measure up?

DomainRadar continuously checks the SPF, DKIM and DMARC of your domains and tells you in plain words what to do.