How Easy Is It to Impersonate Your Business?

If someone wanted to impersonate your business, they probably could. Here’s what stops it.

If someone wanted to impersonate your business, they probably could.

They wouldn’t need to hack your systems.
They wouldn’t need access to your email account.

They could simply send an email pretending to be you.

And to the person receiving it, it could look completely legitimate.

That’s the real problem SPF, DKIM and DMARC are designed to solve.

Illustration explaining how SPF, DKIM and DMARC help prevent email impersonation.

Start With the Real Risk

Most email fraud doesn’t look suspicious.

It looks:

  • Familiar
  • Normal
  • Often urgent

In many cases, it appears to come from a genuine address.

That’s because this isn’t always about hacking.

It’s about impersonation, timing, and pressure.

A Simple Example

Someone registers:

aff1rmit.co.uk instead of affirmit.co.uk

They send an email to your accounts team asking for a payment.

The name looks right.
The signature looks right.
The wording feels normal.

Most people won’t spot the difference straight away.

That’s how this works.

SPF, DKIM and DMARC authentication process protecting business email.

SPF – Where Your Email Is Allowed to Come From

SPF is the simplest piece.

Think of it as a list of approved senders.

It tells receiving systems:
“These are the systems allowed to send email for this domain.”

If an email comes from somewhere else, it can be flagged or blocked.

DKIM – Proving the Email Hasn’t Been Changed

DKIM adds a signature to every email.

When the message is received, that signature is checked.

If anything has been altered, the check fails.

That tells the receiving system something is wrong.

DMARC – Deciding What Happens Next

DMARC brings everything together.

It tells the receiving system what to do if something doesn’t pass:

  • Reject it
  • Quarantine it
  • Or just monitor

In simple terms:

DMARC decides what happens next

SPF checks where it came from

DKIM checks it hasn’t been altered

Comparison between a legitimate invoice email and an impersonated phishing email.

Why This Gets Missed

One of the most common beliefs is:

“We’ve got email, so we’re secure.”

That’s not the case.

Most email systems will happily send and receive messages without checking whether they’re genuine.

That’s where the gap is.

This Isn’t About Staff

Fraud works because people are:

  • Busy
  • Helpful
  • Trying to do the right thing

The solution isn’t asking people to be more suspicious.

It’s putting systems in place so those emails don’t get through in the first place.

Where These Controls Sit

These aren’t advanced tools.

They’re basic protection for your domain.

They sit in the background and filter emails before your team ever sees them.

Quick Comparison

ControlWhat It Does
SPFChecks where the email was sent from
DKIMChecks it hasn’t been changed
DMARCControls what happens if it fails
Legitimate email delivered successfully compared with a spoofed email being blocked.

How Do You Know If Yours Are Set Up?

Most businesses don’t.

It’s common to find:

  • No SPF record at all
  • DKIM not turned on
  • DMARC set to monitoring only

Microsoft 365 supports all of this, but it still has to be set up properly.

Until it is, you’re relying on people spotting issues manually.

Final Thoughts

Email is where a lot of fraud starts.

If your domain can be impersonated, everything else becomes harder to protect.

SPF, DKIM and DMARC don’t stop every attack.

But they remove a large part of the risk before it reaches your team.

Business email impersonation attack detected before reaching the recipient.

FAQ

Can someone send emails pretending to be my business?

Yes. Without these controls, it’s relatively easy to do.

Do small businesses need this?

Yes. Impersonation affects businesses of all sizes.

Does Microsoft 365 include this automatically?

It supports it, but it still needs to be configured.

Will it stop all phishing?

No. But it reduces a significant amount of impersonation.

What’s the difference between SPF, DKIM and DMARC?

SPF checks the sender, DKIM checks the message, DMARC decides what happens.

Need Help?

At Affirm IT, we start with simple questions:

  • Can your domain be used to send emails by anyone else?
  • What happens if an email fails checks?
  • Are you relying on your team to spot problems?

From there, we put the basics in place properly.

If you’re not sure where you stand, get in touch., get in touch with us. At Affirm IT, we specialise in providing comprehensive IT support for small businesses in Heanor, Ripley, Ilkeston, Eastwood and all over the UK

Explore our IT Services

We provide IT Support, Consultancy and Cyber Security services for businesses across the UK. Explore our full list of IT Services below.

Other blogs you may like

Encryption might save your business £1000s

It’s 8:30 on Monday and a laptop is missing. What happens next? Learn how encryption, BitLocker and device management protect your data
Picture of Phil Davenport

Phil Davenport

Backup and redundancy systems shown protecting business servers during an IT outage.

Why Backups Don’t Keep Your Business Running

Backups protect your data. Redundancy keeps your business running. They are not the same thing.
Picture of Phil Davenport

Phil Davenport

Outsourced vs In-House IT for Manufacturers: Which Model Works Best?

For manufacturing businesses, IT is no longer simply about fixing computers when something goes wrong. Technology now underpins almost every part of

Picture of Phil Davenport

Phil Davenport