Technical explainer
DMARC, explained for managing partners: can someone send an invoice as your firm?
You have almost certainly never been asked this question, which is why it has never occurred to you. So here it is:
If a stranger sent an email to your biggest client, from your firm's own email address, with new bank details on an invoice — would it get through?
For a large proportion of UK firms, the answer is yes. Not because of anything clever. Because three settings on the domain were never finished.
The three records
SPF is a published list of the mail servers allowed to send email on your behalf. Without it, a receiving mail server has no way to tell your genuine email from a forgery. Most firms have this one, because their mail provider set it up during a migration.
DKIM puts a tamper-proof signature on every message you send, proving it came from you and wasn't altered in transit. Many firms have this switched off without knowing, because it has to be enabled in the mail provider and published on the domain.
DMARC is the one that matters most, and the one most often missing. It is the instruction that tells the world's mail servers what to do with a message that claims to be from you but fails the checks. Reject it. Quarantine it. Or — the default — do nothing and let it through.
The most common failure: "p=none"
Plenty of firms have a DMARC record and believe they are covered. Then we read it, and it says p=none.
That means: monitor only. Report the forgeries to me afterwards. Stop none of them. A forged invoice from your domain still lands in the client's inbox looking entirely genuine, and the client has no way to tell.
It is usually the result of a record published during a migration with the intention of tightening it later. Later never came, because nobody owned it.
Why this is the headline finding for professional services
Phishing is the most common attack in the UK. Invoice redirection fraud is the version that hurts a law or accountancy firm most, because you send invoices, your clients pay them, and a forged one from your real domain passes every human and technical check. This is not a hypothetical — it is the largest single source of actual harm in the market.
What to do
Publish DMARC. Review the reports for a few weeks. Move the policy to quarantine, then reject. Enable DKIM. Make sure SPF ends in -all.
It is a day's work for someone who knows what they are doing. The hard part is not the configuration — it is having someone whose job it is to notice it was never done.
See it for your own firm
Run the free 60-second exposure scan.
The same outside-in view an attacker starts from. Public data only — nothing is probed.