It Wasn't Us. But It Looked Like Us.

Last month, I got a call about a business we work with in Addison County. They were upset and confused. One of their customers got an email that looked exactly like it came from them. It even had the right invoice number on it. The email asked the customer to pay a different way this time — through Zelle instead of the usual method. The customer paid. The money went straight to a stranger. It never reached the business it was meant for. 

They never sent that email. Someone else did, and made it look like it came from them. 

This kind of thing is happening more and more to small businesses, town offices, and everyday people right here in Vermont. And here's the hard truth: it's not really about hacking. Nobody broke into any computer. Someone just figured out how to send an email that looked real enough to fool a customer who trusted them — and it could just as easily have been you, me, or your neighbor on the other end of that message. 

Email Authentication: The Part Everyone Skips

There's a way to lock this down. It's called email authentication, and it's something we set up for every client whose domain we manage. Think of it as a guest list for your email. It tells the rest of the internet exactly which systems are allowed to send email on behalf of your business — and which ones aren't. 

Here's the part most people miss, though. Once that guest list is built, someone has to actually watch it. And you can only watch it well if you know everyone who's supposed to be on it. That's harder than it sounds. Think about how many different systems send email as your business right now: 

  • Your accounting software, sending invoices and receipts 

  • Your email marketing tool, sending newsletters or promotions 

  • The contact form on your website 

  • Your copier or printer, when it scans and emails a document 

  • Even your phone system, if it emails voicemails or faxes 

Every single one of those has to be accounted for. If one of them isn't on the list, or if you added a new tool six months ago and forgot to tell us, the whole system has a blind spot. 

This is the Partnership Part

This is exactly why we ask to be the ones managing your domain and your public records. It's not about control. It's because we can't watch the guest list if we don't know what's supposed to be on it — and we can't know that unless you tell us when something changes. 

That's the deal. We do the technical work. You keep us in the loop when you turn on something new. Together, that's what actually keeps your name safe. 

So consider this your invitation — or maybe your challenge. Sit down and think through every system in your business that sends email on your behalf. All of them. Then contact us, and we'll make sure they're all accounted for. 

A Few Things You Can Do Today

1. Before you turn on any new tool that sends email — accounting software, a marketing platform, even a new copier — tell us. It takes five minutes to add it to the list, and it closes a gap before it opens. 

2. If someone asks you to change how they pay you — call them. Use a number you already have, not one from the email. A thirty-second phone call can save someone real money. 

3. Walk through this with your team once. Make sure everyone knows what a real invoice or payment request from your business actually looks like.

I can't promise this stops every trick out there. But the real finish line isn't just having these protections turned on — it's getting them dialed all the way up, so a fake email gets blocked outright instead of just flagged and watched. That's what we call full alignment, and it's what we work toward for every domain in our care. At the end of the day, this isn't only a business problem. It's part of being a careful user of technology, whether you're running a company or just checking email at home. A little healthy suspicion, in either case, goes a long way. 

That's the whole point of having an IT Department down the Hall instead of just a login and a password. 

Already working with us?
Submit a ticket and we'll pull a report showing exactly where your domain stands — and if we're not monitoring it yet, let's have that conversation.  

Haven't worked with us yet?
Fill out the form on our site and we'll gladly take a look. 

Next
Next

Session Cookie Hijacking: The Security Gap After MFA