Email Authentication
The One Email Control That Stops Fraud Before It Starts
How companies prevent fake “from us” emails—and why most still don’t.
The Goal: Make Impersonation Impossible
If an email claims to be from your company, it must prove it. SPF, DKIM, and DMARC provide the proof; a reject policy keeps fake mail out of inboxes.
The Problem: Fake Emails That Look Real
Business Email Compromise relies on normal-looking emails that quietly change invoices, payroll details, or vendor banking information. Attackers don’t need to hack inboxes when your domain can be impersonated.
- Fake invoices sent to Accounts Payable
- Requests to redirect vendor payments
- Payroll change scams
- Emails pretending to be executives asking for urgent action
Why Finance Gets Extra Protection
Even with perfect authentication, process gaps move money. Layer controls for payment changes: second-channel verification, dual approvals, and heightened scrutiny for banking updates.
What Leadership Should Expect
Boards need clarity, not jargon. Can outsiders send as you? How often are impersonation attempts rejected? Are payment changes always verified outside email? A strict DMARC policy with reporting answers these confidently.
Think of Email Like Caller ID for Your Company
SPF
Publishes who is allowed to send as you. Unknown senders fail the check.
DKIM
Cryptographic signatures ensure the message wasn’t altered and came from approved systems.
DMARC
The rulebook that enforces alignment and rejects unproven mail—so fake “from us” email never arrives.
When enforced correctly, attackers move on to easier targets. That’s what prevention looks like.
BreachModal Field Tool
Email Auth 10-Minute Audit (SPF / DKIM / DMARC)
Paste domains, run checks, export results. DKIM requires known selectors—supply likely ones. This defensive audit queries public DNS only.
Tip: include the exact mail-from domains you use (root + key subdomains like billing/pay/invoices).
- SPF “10 DNS lookup” is estimated heuristically (fast red flag).
- DKIM key size can’t be reliably derived from the TXT alone; this checks presence + basic validity.
| Domain | SPF | DMARC | Subdomain Policy | DKIM (selectors) |
|---|---|---|---|---|
| Add domains and run the audit to see SPF, DKIM, and DMARC posture. | ||||
Why BreachModal Focuses Here
Email domain impersonation is one of the rare risks in cybersecurity that can be almost entirely eliminated. When authentication is configured with reject policies, the attack simply fails—quietly, reliably, every time.
If you want this control explained to your board, mapped to your email platform, or validated in under an hour, that’s exactly the kind of work we do.