Check before you pay
Invoice fraud and business email compromise usually depend on a domain the victim has never looked at closely. A short check of the sender domain before a payment or bank-detail change can stop the loss. If the domain in an email or invoice was created days or weeks ago and resembles a known supplier, stop and verify through a contact channel you already trust.
Building the check into the payment process works better than relying on individuals to notice spelling differences. Ask staff to look up any domain that requests a new bank account, an urgent transfer, or credentials.
A simple risk routine
Compare the sender domain character by character with the domain on file. Look up its creation date, registrar and mail servers. Check whether it publishes SPF and DMARC. Confirm whether the website is new, empty or copied. Each finding is context; together they help decide whether to escalate.
- Domain created recently and resembles a known partner: escalate.
- Bank-detail change requested by email: verify by phone using a known number.
- MX records point to a different provider than the genuine partner: investigate.
- No SPF or DMARC on a domain that sends invoices: treat with caution.
- Keep a sealed report of the checks for audit and insurance purposes.
Onboarding and due diligence
The same checks support supplier onboarding, marketplace seller review and investment due diligence. A company claiming many years of trading with a domain registered last month warrants a closer look. Record the result so later changes in registration or hosting can be compared.
