Privacy & Social · September 20, 2026
What to Do When Scammers Spoof Your Business Email
A practical response plan for documenting email impersonation, protecting accounts, warning customers, improving authentication, and reporting fraud.

Save the suspicious message and full headers without opening links or attachments. Determine whether it is display-name impersonation, a lookalike domain, or a real mailbox compromise. Secure affected accounts, warn people through trusted channels when needed, review SPF, DKIM, and DMARC with your email administrator, and report the scam with accurate evidence. No control can stop every impersonation attempt.
A message can look as though it came from your company even when the real mailbox was never accessed. A scammer may copy a display name, register a similar domain, alter the reply address, or take over an account. Those situations have different risks and should not be called a confirmed hack without supporting evidence.
Impersonation can damage trust when people believe a fake invoice, password request, hiring message, or payment instruction came from you. Respond with security, clear communication, accurate reporting, and monitoring. Do not identify a suspect publicly without verified evidence and qualified advice.
Email authentication helps receiving systems evaluate mail sent for your domain. Google recommends SPF, DKIM, and DMARC for custom-domain email and a gradual rollout. Include every legitimate sender, such as billing, marketing, support, and website systems. A mistake can affect real mail, so involve a qualified administrator.
A practical step-by-step approach
01Preserve the message safely
Save the original email, full headers, sender display name, From and Reply-To addresses, date, recipient, subject, links, attachments, and request. Keep the original because headers contain routing and authentication details. Do not click, reply, call a number in the message, or publish private information. Verify the sender through a known website, phone number, or contact record.
02Identify the type of impersonation
Compare the visible address, reply address, and domain with your real accounts. Ask the administrator to review the full header and account logs. A copied display name, lookalike domain, and authenticated message from a compromised mailbox are not the same. State only what is confirmed instead of making an inaccurate breach announcement.
03Contain any real account compromise
If a real mailbox may be compromised, use a trusted administrator path to reset credentials, revoke sessions, review forwarding and recovery settings, remove unknown access, and turn on multifactor authentication. Review sent mail and sign-in activity and preserve logs. Coordinate with the provider, cybersecurity team, insurer, and counsel when sensitive or regulated data may be involved.
04Warn employees, customers, and vendors carefully
When people face a real risk, post a short notice on a known official channel. Describe the suspicious sender pattern, what your company will never request by email, how to verify a payment or account change, and where to forward messages. Do not repeat the malicious link. The FTC advises businesses to alert customers promptly when scammers impersonate the company.
05Review SPF, DKIM, and DMARC
Inventory every system allowed to send mail before changing DNS. SPF identifies approved senders, DKIM adds a domain-linked signature, and DMARC publishes handling and reporting instructions when authentication and alignment fail. Follow current provider documentation, test legitimate senders, review reports, and increase enforcement gradually. These controls cannot block every similar domain or copied display name.
06Send focused abuse reports
Report the message through the mail provider's phishing or abuse process. For a lookalike domain, document the exact domain, registrar, host, pages, and conduct before contacting the appropriate abuse team. Use only categories supported by the facts. A provider needs enough evidence to distinguish fraud from lawful criticism or an unrelated business.
07Act quickly if money or information was lost
Contact the bank, card issuer, payment service, or payroll provider immediately through a trusted number. U.S. victims can report fraud to the FTC and internet-enabled crime to the FBI's IC3. IdentityTheft.gov offers recovery steps for exposed personal information. Laws and notice duties vary, so seek qualified security, privacy, insurance, and legal guidance.
08Monitor the brand and improve verification
Track new sender variations, customer reports, lookalike domains, fake support messages, and search results without engaging the scammer. Add a second-channel check for payment, payroll, password, and vendor changes. Train staff to verify urgent requests. Keep one incident log with evidence, reports, notices, decisions, and follow-up dates.
Information to gather
A clear record makes it easier to choose the right channel, communicate accurately, and avoid unnecessary repetition. Start with:
- Original message, full headers, screenshots, date, and affected recipients
- Verified difference between display-name spoofing, lookalike domain, and mailbox compromise
- Account sessions, forwarding rules, recovery methods, managers, and multifactor authentication
- List of every legitimate service that sends email for the domain
- Current SPF, DKIM, DMARC, provider guidance, and test results
- Approved customer or vendor notice on a trusted company channel
- Provider, registrar, host, FTC, IC3, bank, or insurer report records as relevant
- Monitoring owner, payment-verification procedure, and follow-up date
What not to do
Pressure can lead to decisions that create a second reputation problem. Avoid:
- Clicking a link, opening an attachment, or calling a number in the suspicious message
- Announcing a mailbox breach before account evidence confirms one
- Publishing full headers, customer data, payment details, or private evidence
- Changing DMARC enforcement before every legitimate sender is identified and tested
- Submitting false, duplicate, retaliatory, or exaggerated abuse and legal reports
- Promising that authentication, reporting, removal, investigation, or monitoring will stop every scam
Frequently asked questions
Does a spoofed email mean our mailbox was hacked?
No. A scammer can copy a display name, change a reply address, or use a lookalike domain without entering your mailbox. A compromise may show unknown sign-ins, sent messages, forwarding rules, or recovery changes. Preserve the message and ask the administrator to review headers and logs before describing the incident.
Can SPF, DKIM, and DMARC stop all business impersonation?
No. They help receiving systems authenticate mail associated with your real domain, but they do not prevent every copied display name, similar-looking domain, forwarded message, or compromised account. Correct setup, gradual enforcement, multifactor authentication, staff training, payment verification, reporting, and monitoring work together.
Should we warn customers about fake emails?
Warn affected people when the evidence shows a meaningful risk. Use a concise notice on a known official channel. Explain which addresses or requests are suspicious, what the company will never ask for by email, and how to verify contact. Do not repeat a malicious link or expose recipient information.
Where should an impersonation email be reported?
Report it through the receiving email service and, when supported by evidence, to the lookalike domain's registrar or host. U.S. victims can report fraud to ReportFraud.ftc.gov and internet-enabled crime to IC3.gov. Contact a bank or payment provider immediately after a suspicious transfer, and use IdentityTheft.gov when personal information was exposed.
Can a reputation company guarantee that spoofed emails will stop?
No. A responsible provider can organize evidence, coordinate accurate notices and reports, and monitor new variations. Outcomes depend on security facts, email providers, registrars, hosts, recipients, law enforcement, platform rules, technical controls, and other third parties. No provider can guarantee removal, investigation, delivery, or timing.
Primary resources
Policies and features can change. Review the current source before submitting a request:
- FTC: business email imposters
- FTC: recognize and report phishing
- CISA: Secure Our World
- FBI IC3: Business Email Compromise
- Google Workspace: set up SPF
- Google Workspace: recommended DMARC rollout