Privacy & Social · September 20, 2026

What to Do When Scammers Spoof Your Business Email

A practical response plan for documenting email impersonation, protecting accounts, warning customers, improving authentication, and reporting fraud.

Business owner and adviser documenting fraudulent emails that impersonate the company
Short answer

Save the suspicious message and full headers without opening links or attachments. Determine whether it is display-name impersonation, a lookalike domain, or a real mailbox compromise. Secure affected accounts, warn people through trusted channels when needed, review SPF, DKIM, and DMARC with your email administrator, and report the scam with accurate evidence. No control can stop every impersonation attempt.

A message can look as though it came from your company even when the real mailbox was never accessed. A scammer may copy a display name, register a similar domain, alter the reply address, or take over an account. Those situations have different risks and should not be called a confirmed hack without supporting evidence.

Impersonation can damage trust when people believe a fake invoice, password request, hiring message, or payment instruction came from you. Respond with security, clear communication, accurate reporting, and monitoring. Do not identify a suspect publicly without verified evidence and qualified advice.

Email authentication helps receiving systems evaluate mail sent for your domain. Google recommends SPF, DKIM, and DMARC for custom-domain email and a gradual rollout. Include every legitimate sender, such as billing, marketing, support, and website systems. A mistake can affect real mail, so involve a qualified administrator.

A practical step-by-step approach

01Preserve the message safely

Save the original email, full headers, sender display name, From and Reply-To addresses, date, recipient, subject, links, attachments, and request. Keep the original because headers contain routing and authentication details. Do not click, reply, call a number in the message, or publish private information. Verify the sender through a known website, phone number, or contact record.

02Identify the type of impersonation

Compare the visible address, reply address, and domain with your real accounts. Ask the administrator to review the full header and account logs. A copied display name, lookalike domain, and authenticated message from a compromised mailbox are not the same. State only what is confirmed instead of making an inaccurate breach announcement.

03Contain any real account compromise

If a real mailbox may be compromised, use a trusted administrator path to reset credentials, revoke sessions, review forwarding and recovery settings, remove unknown access, and turn on multifactor authentication. Review sent mail and sign-in activity and preserve logs. Coordinate with the provider, cybersecurity team, insurer, and counsel when sensitive or regulated data may be involved.

04Warn employees, customers, and vendors carefully

When people face a real risk, post a short notice on a known official channel. Describe the suspicious sender pattern, what your company will never request by email, how to verify a payment or account change, and where to forward messages. Do not repeat the malicious link. The FTC advises businesses to alert customers promptly when scammers impersonate the company.

05Review SPF, DKIM, and DMARC

Inventory every system allowed to send mail before changing DNS. SPF identifies approved senders, DKIM adds a domain-linked signature, and DMARC publishes handling and reporting instructions when authentication and alignment fail. Follow current provider documentation, test legitimate senders, review reports, and increase enforcement gradually. These controls cannot block every similar domain or copied display name.

06Send focused abuse reports

Report the message through the mail provider's phishing or abuse process. For a lookalike domain, document the exact domain, registrar, host, pages, and conduct before contacting the appropriate abuse team. Use only categories supported by the facts. A provider needs enough evidence to distinguish fraud from lawful criticism or an unrelated business.

07Act quickly if money or information was lost

Contact the bank, card issuer, payment service, or payroll provider immediately through a trusted number. U.S. victims can report fraud to the FTC and internet-enabled crime to the FBI's IC3. IdentityTheft.gov offers recovery steps for exposed personal information. Laws and notice duties vary, so seek qualified security, privacy, insurance, and legal guidance.

08Monitor the brand and improve verification

Track new sender variations, customer reports, lookalike domains, fake support messages, and search results without engaging the scammer. Add a second-channel check for payment, payroll, password, and vendor changes. Train staff to verify urgent requests. Keep one incident log with evidence, reports, notices, decisions, and follow-up dates.

Information to gather

A clear record makes it easier to choose the right channel, communicate accurately, and avoid unnecessary repetition. Start with:

  • Original message, full headers, screenshots, date, and affected recipients
  • Verified difference between display-name spoofing, lookalike domain, and mailbox compromise
  • Account sessions, forwarding rules, recovery methods, managers, and multifactor authentication
  • List of every legitimate service that sends email for the domain
  • Current SPF, DKIM, DMARC, provider guidance, and test results
  • Approved customer or vendor notice on a trusted company channel
  • Provider, registrar, host, FTC, IC3, bank, or insurer report records as relevant
  • Monitoring owner, payment-verification procedure, and follow-up date

What not to do

Pressure can lead to decisions that create a second reputation problem. Avoid:

  • Clicking a link, opening an attachment, or calling a number in the suspicious message
  • Announcing a mailbox breach before account evidence confirms one
  • Publishing full headers, customer data, payment details, or private evidence
  • Changing DMARC enforcement before every legitimate sender is identified and tested
  • Submitting false, duplicate, retaliatory, or exaggerated abuse and legal reports
  • Promising that authentication, reporting, removal, investigation, or monitoring will stop every scam
Important: Outcomes depend on the facts, evidence, publisher or platform rules, search engines, applicable law, and other third parties. This article is educational information and is not legal advice.

Frequently asked questions

Does a spoofed email mean our mailbox was hacked?

No. A scammer can copy a display name, change a reply address, or use a lookalike domain without entering your mailbox. A compromise may show unknown sign-ins, sent messages, forwarding rules, or recovery changes. Preserve the message and ask the administrator to review headers and logs before describing the incident.

Can SPF, DKIM, and DMARC stop all business impersonation?

No. They help receiving systems authenticate mail associated with your real domain, but they do not prevent every copied display name, similar-looking domain, forwarded message, or compromised account. Correct setup, gradual enforcement, multifactor authentication, staff training, payment verification, reporting, and monitoring work together.

Should we warn customers about fake emails?

Warn affected people when the evidence shows a meaningful risk. Use a concise notice on a known official channel. Explain which addresses or requests are suspicious, what the company will never ask for by email, and how to verify contact. Do not repeat a malicious link or expose recipient information.

Where should an impersonation email be reported?

Report it through the receiving email service and, when supported by evidence, to the lookalike domain's registrar or host. U.S. victims can report fraud to ReportFraud.ftc.gov and internet-enabled crime to IC3.gov. Contact a bank or payment provider immediately after a suspicious transfer, and use IdentityTheft.gov when personal information was exposed.

Can a reputation company guarantee that spoofed emails will stop?

No. A responsible provider can organize evidence, coordinate accurate notices and reports, and monitor new variations. Outcomes depend on security facts, email providers, registrars, hosts, recipients, law enforcement, platform rules, technical controls, and other third parties. No provider can guarantee removal, investigation, delivery, or timing.

Primary resources

Policies and features can change. Review the current source before submitting a request:

Related guides