A Bradenton accountant got a call from her biggest client last year. “Why are you asking me to wire $40,000 to a new account?” The accountant hadn’t sent that email. A scammer did — and it looked exactly like it came from her firm’s domain.
This isn’t rare. It’s called email spoofing, and it’s one of the easiest tricks in a scammer’s playbook. The FBI reported that business email fraud cost U.S. companies $2.77 billion in 2024 alone.
The scary part? Right now, without any special tools, someone could send an email that looks like it came from your company. Your domain name in the “From” line. Your logo pasted into the body. A polite request asking your client to pay an invoice or update their banking details.
Your client would have no reason to question it.
Why This Is Even Possible
Email was invented in 1982. Back then, everyone on the internet basically knew each other. Nobody built in a way to verify who actually sent a message.
The “From” address on an email is about as trustworthy as a return address handwritten on an envelope. Anyone can write anything they want.
Scammers exploit this every day. They send messages using your domain name to trick your clients, your vendors, even your own staff. And because the email appears to come from you, the person reading it has no obvious reason to be suspicious.
Three Settings That Lock the Door
There are three settings you can add to your domain that make spoofing much harder. Think of them as three locks on the same door. You need all three to keep scammers out.
Lock #1: SPF
SPF is a list you publish that says: “These are the only servers allowed to send email for my domain.” When a receiving server gets a message claiming to be from you, it checks the list. If the sending server isn’t on it, the message fails.
Lock #2: DKIM
DKIM adds a digital signature to every email you send — like a wax seal on a letter. The receiving server checks the seal against a key published on your domain. If it matches, the email is legit and hasn’t been tampered with.
Lock #3: DMARC
DMARC ties the first two together and tells the receiving server what to do when a message fails both checks. You set it to one of three levels:
- None — monitor only, don’t block anything.
- Quarantine — send suspicious messages to spam.
- Reject — block fake messages entirely.
Here’s where most businesses get burned.
The Mistake Almost Everyone Makes
According to industry research, roughly 69% of domains worldwide have no effective DMARC protection. Many businesses that do have DMARC leave it set to “none.” That means it watches — but it doesn’t block a single spoofed email.
It’s like installing a security camera but never checking the footage. You feel protected, but you’re not.
If you run an accounting firm, law practice, or financial advisory here in Tampa Bay, your clients trust emails from your domain with their money. A spoofed invoice from “your” email address could cost a client tens of thousands of dollars — and cost you that relationship forever.
A Quick Checklist to See Where You Stand
You can check your domain in about ten seconds using a free tool like MXToolbox. Just type in your domain name and look for three things:
- SPF record: Does it exist? Does it include every service that sends email on your behalf (your email provider, CRM, payroll system)?
- DKIM record: Is it published and active?
- DMARC record: Is the policy set to “quarantine” or “reject” — not just “none”?
If any of these are missing or stuck on “none,” your domain is exposed.
Don’t Flip the Switch Without a Plan
One important warning: you can’t just jump straight to “reject.” If you skip the monitoring phase, you might accidentally block real emails from services that send on your behalf — your marketing platform, your scheduling tool, your payroll provider.
The smart approach is to start at “none,” review the reports to see who’s sending email as your domain, make sure all legitimate senders are covered by SPF and DKIM, then step up to “quarantine,” and finally “reject.” This is part of solid cyber hygiene that any Manatee County business can put in place.
What This Means for Your Business
Your clients trust you with sensitive financial and legal information. One spoofed email from “your” domain could shatter that trust overnight. The tools to prevent it already exist — they just need to be set up correctly.
If you’re not sure where your domain stands, don’t guess. Book a free 15-minute risk assessment with Justin and Sara at Reef Cyber Security. We’ll check your SPF, DKIM, and DMARC in minutes and tell you exactly what needs to happen next.


