Last week, someone sent 4,000 emails using our domain.
We didn’t get hacked.
But someone was impersonating us.
Most people don’t realize this.
You don’t need access to a system to send emails that look like they’re from you.
If your domain isn’t set up properly, anyone can do it.
Why would someone do this?
Because it’s easy. And it works.
If an email looks like it comes from a trusted brand, people are more likely to open it.
Sometimes that’s all it takes.
At the time, we had DMARC set to p=none.
We were only monitoring what was happening.
We changed it to p=reject.
Now, if something doesn’t align, it doesn’t get delivered.
Nothing else changed.
But the system behaves very differently.
What does this tell you?
As a consumer
When you click through, check the website address.
Make sure it matches the email.
As a developer
Set up SPF and DKIM for your domain.
Monitor your DMARC and enforce it when you’re ready.
If people are trying to impersonate you, it means being you has value.
Learn more: receipt-ai.com