Is Someone Sending Fake Emails From Your Company's Domain? Here's How Houston Businesses Can Stop It

Right now, without any special tools, a scammer could send an email that looks exactly like it came from your company. The From line would show your domain. Your logo could be pasted right into the message. And it could ask one of your clients to pay an overdue invoice or "update" your banking details.

This is called email spoofing, and it's one of the most common ways fraud against your clients, vendors, and staff gets started — whether you're a small business in the Heights or a growing company in the Energy Corridor.

The good news: there are three DNS settings that make spoofing your domain far harder to pull off. They're called SPF, DKIM, and DMARC. In our experience working with Houston-area businesses, most companies have one or two of these configured — and the third is either missing or set up incorrectly. That gap is usually all it takes for a spoofed email to slip through.

Here's what each one does, the mistake we see most often, and how to check where your own domain stands.

Why Scammers Can Send Email "From" Your Company

Email was built in a more trusting era. The system that delivers mail doesn't automatically verify that a sender is who they claim to be. The From address on an email is about as trustworthy as a handwritten return address on an envelope — anyone can write anything there, and the message still gets delivered.

Spoofing exploits exactly that gap. A scammer puts your domain in the From field, sends the message, and unless your domain is locked down, the receiving mail server has no reason to question it. It lands in your client's inbox looking completely legitimate. Even the UK's National Cyber Security Centre publishes anti-spoofing guidance because the problem is so widespread.

The Three DNS Records That Stop Email Spoofing

Three records work together to prove an email genuinely came from your domain. You set them up once, at your domain registrar or DNS host, and every receiving mail server checks them automatically from then on.

SPF (Sender Policy Framework)

SPF is a published list of the mail servers allowed to send email for your domain. When a receiving server gets a message claiming to be from you, it checks the sending server against that list. If a server isn't authorized, SPF flags the message.

DKIM (DomainKeys Identified Mail)

DKIM attaches a tamper-proof digital signature to every email you send. Your mail server signs outgoing messages with a private key, while the matching public key lives in your DNS. The receiving server uses it to confirm two things: the message actually came from your domain, and nobody altered it in transit.

DMARC (Domain-based Message Authentication, Reporting and Conformance)

DMARC ties SPF and DKIM together and tells receiving servers what to actually do when a message fails those checks. It also confirms the domain in the visible From address matches what SPF and DKIM verified — which is the piece that stops someone from forging your exact address. On top of that, DMARC sends you regular reports showing every server sending email on your domain's behalf, including the ones that shouldn't be.

The DMARC Mistake We See Most Often

DMARC has three policy settings, and getting this one setting wrong is extremely common:

  1. p=none — Monitor only. Receiving servers do nothing when a message fails. Your domain can still be spoofed.

  2. p=quarantine — Failing messages get routed to the junk folder.

  3. p=reject — Failing messages are blocked before they ever reach an inbox.

Many businesses set up DMARC at p=none, start collecting reports, and never move past it. At that setting, you get visibility — but zero actual protection. Real protection only begins at quarantine or reject. Microsoft's own guidance recommends working toward p=reject once you've confirmed your legitimate mail is passing authentication.

What SPF, DKIM, and DMARC Won't Catch

These records lock down your exact domain — but two related scams still get through, and both are worth knowing about:

  • Lookalike domains. A scammer can register something close to yours — griffintech-invoices.com, or swapping .com for .co — and send from there instead. Your DNS records only protect your real domain, not a copycat one the attacker controls.

  • Display-name spoofing. The name shown in the From line might read "Griffin Technology Solutions Accounting," while the actual email address behind it is a random Gmail account. DMARC checks the domain — not the display name.

For both of these, your team still needs the same habits that catch any phishing attempt: check the full email address, not just the display name, and verify any request to change payment or banking details by calling a known phone number — never one listed in the email itself.

Why This Matters Even If You Don't Send Bulk Email

Protection. These three records stop scammers from impersonating your domain to your clients, your vendors, and your own staff.

Deliverability. Major mailbox providers increasingly require this setup. Since February 2024, Google and Yahoo have required anyone sending more than 5,000 messages a day to have SPF, DKIM, and DMARC in place. Microsoft began rolling out similar requirements for Outlook.com and Hotmail in 2025, first routing non-compliant bulk mail to junk, then rejecting it outright. Even below those volume thresholds, a properly authenticated domain is simply more likely to land in the inbox instead of spam.

How to Check and Fix Your Domain

You can get a rough read on where you stand without any technical work — several free SPF and DMARC lookup tools let you type in your domain and see which records exist. That tells you what's present, though not necessarily whether it's configured correctly.

Getting it fully right is a job for whoever manages your IT and DNS, and it should be rolled out in stages, since a misconfigured record can accidentally send your own legitimate mail to spam:

  1. Publish SPF and DKIM covering every legitimate mail source your business uses.

  2. Add DMARC at p=none and review the reports to confirm your real mail is passing.

  3. Move DMARC to p=quarantine, then to p=reject, once the reports come back clean.

Microsoft recommends this same gradual rollout — start at none, work toward reject — so you protect the domain without accidentally blocking your own mail along the way.

Protect Your Domain With Griffin Technology Solutions

If you're not sure whether your business's domain is protected — or you've never even heard of SPF, DKIM, or DMARC until now — Griffin Technology Solutions can review your setup, run the rollout safely in stages, and make sure your Houston business isn't an easy target for invoice fraud or impersonation scams. Contact us today to get a free domain security check.

Frequently Asked Questions

What is email spoofing?

Email spoofing is when someone sends a message with your domain in the From address to make it look like it came from your company. It's commonly used to trick clients, vendors, or staff into paying fake invoices, changing banking details, or sharing sensitive information.

What are SPF, DKIM, and DMARC in simple terms?

SPF is a list of servers authorized to send email for your domain. DKIM is a digital signature confirming a message came from you and wasn't altered. DMARC ties both together, tells receiving servers what to do with messages that fail, and reports back on who is sending email using your domain.

Does DMARC stop all email impersonation?

No. DMARC stops someone from forging your exact domain, but it doesn't stop lookalike domains (like griffintech-invoices.com) or display-name spoofing, where the sender's name shows your company but the underlying address is different. Those require staff training and payment-verification habits.

Will setting up DMARC block my own emails?

Not if it's rolled out gradually. Starting at p=none lets you monitor reports and confirm your legitimate mail passes before moving to quarantine and then reject. Jumping straight to reject without checking first is what causes delivery problems.

Do I need these records if my business doesn't send much email?

Yes. They protect your domain from being spoofed regardless of your sending volume, and they improve your chances of landing in the inbox rather than spam. Google, Yahoo, and Microsoft all now expect proper email authentication.

Next
Next

Cyberattack Response Plan: What Houston Businesses Should Do in the First Hour