Spoofhound

Business email compromise

Business email compromise is fraud carried out over email. Somebody impersonates a person the victim trusts — the finance director, a supplier, a solicitor in the middle of a transaction — and persuades them to send money to the wrong bank account, or to hand over information. There is usually no malware and no attachment. The message is simply an email that looks like it came from someone it didn't.

In 2025 the FBI recorded 24,768 reports of business email compromise and $3.05 billion in losses, second only to investment fraud (FBI Internet Crime Complaint Center, 2025 Internet Crime Report).

The five ways it is done

  • 1.Forging your exact domain, so the message appears to come from your own address
  • 2.Registering a domain that looks like yours, differing by a letter or a suffix
  • 3.Using your name as the display name on an unrelated address, which is all most people see on a phone
  • 4.Sending from a mailbox at your organisation the attacker has taken over
  • 5.Sending from a mailbox at your supplier they have taken over, so a genuine invoice arrives with the bank details changed

What Spoofhound does about it

Spoofhound eliminates the first one. Once your domain is at DMARC enforcement, mail forging your exact domain is rejected before it reaches anyone.

Getting to enforcement is the hard part, and it is where most organisations stop. They cannot see who sends mail as them, so turning on enforcement risks breaking payroll, the CRM, the ticketing system, or a marketing platform nobody remembers signing up for. Spoofhound shows you every sender using your domain, so you can reach enforcement without breaking anything, and prove it stays that way.

You also see attempts to spoof your domain as they happen, which is intelligence you do not otherwise have.

What Spoofhound does not do

Spoofhound does not stop an attacker who has taken over a real mailbox. Their messages are genuinely from that domain and pass every authentication check, because they are real. That is also where the largest losses occur, particularly the changed-invoice variant.

Spoofhound does not monitor domains you do not own, and it does not inspect mail arriving at your organisation. It reads the reports about mail sent as you.

Anyone telling you their DMARC product stops business email compromise is selling you something. It closes one route. It is the cheapest route for an attacker and the only one you can shut completely, which is why it is worth closing — but it is one route of five.

See where your own domain stands with the free domain spoofing & branding check — no signup, nothing installed.