Skip to content
BreachModal logoBreachModal

Email Authentication

The One Email Control That Stops Fraud Before It Starts

How companies prevent fake “from us” emails—and why most still don’t.

The majority of email fraud doesn’t rely on hacking inboxes. Attackers simply pretend to be you. They send messages that look routine — invoice updates, banking changes, urgent approvals — and people comply because the messages appear to come from trusted domains.
Business Email Compromise thrives when outsiders can impersonate your domain. SPF, DKIM, and DMARC are the caller ID for your company: they prove who is allowed to send, verify that content wasn’t altered, and enforce what happens when authentication fails.
When these controls are enforced at reject, fake ‘from us’ email never reaches employees or customers. That is the difference between monitoring fraud and preventing it.

The Goal: Make Impersonation Impossible

If an email claims to be from your company, it must prove it. SPF, DKIM, and DMARC provide the proof; a reject policy keeps fake mail out of inboxes.

The Problem: Fake Emails That Look Real

Business Email Compromise relies on normal-looking emails that quietly change invoices, payroll details, or vendor banking information. Attackers don’t need to hack inboxes when your domain can be impersonated.

  • Fake invoices sent to Accounts Payable
  • Requests to redirect vendor payments
  • Payroll change scams
  • Emails pretending to be executives asking for urgent action

Why Finance Gets Extra Protection

Even with perfect authentication, process gaps move money. Layer controls for payment changes: second-channel verification, dual approvals, and heightened scrutiny for banking updates.

What Leadership Should Expect

Boards need clarity, not jargon. Can outsiders send as you? How often are impersonation attempts rejected? Are payment changes always verified outside email? A strict DMARC policy with reporting answers these confidently.

Think of Email Like Caller ID for Your Company

SPF

Publishes who is allowed to send as you. Unknown senders fail the check.

DKIM

Cryptographic signatures ensure the message wasn’t altered and came from approved systems.

DMARC

The rulebook that enforces alignment and rejects unproven mail—so fake “from us” email never arrives.

When enforced correctly, attackers move on to easier targets. That’s what prevention looks like.

BreachModal Field Tool

Email Auth 10-Minute Audit (SPF / DKIM / DMARC)

Paste domains, run checks, export results. DKIM requires known selectors—supply likely ones. This defensive audit queries public DNS only.

Built for quick board-level answers: Can outsiders send as us? Are subdomains covered? Do SPF/DKIM actually enforce?
Targetsone per line

Tip: include the exact mail-from domains you use (root + key subdomains like billing/pay/invoices).

Options
  • SPF “10 DNS lookup” is estimated heuristically (fast red flag).
  • DKIM key size can’t be reliably derived from the TXT alone; this checks presence + basic validity.
DomainSPFDMARCSubdomain PolicyDKIM (selectors)
Add domains and run the audit to see SPF, DKIM, and DMARC posture.

Why BreachModal Focuses Here

Email domain impersonation is one of the rare risks in cybersecurity that can be almost entirely eliminated. When authentication is configured with reject policies, the attack simply fails—quietly, reliably, every time.

If you want this control explained to your board, mapped to your email platform, or validated in under an hour, that’s exactly the kind of work we do.