Email Spoofing: Why Your Staff Can Still Be Impersonated

Email spoofing

Table of Contents

The email came from your managing director. Not from an odd-looking address, but with his name sitting in the sender field, his usual sign-off, and a request to release the payment before he landed in Perth. Your finance officer checked the name, saw it matched, and paid it. 

Nothing in that email was pretending to be your domain, so your domain-level protections did not fail that morning. They were never even the main issue. The message came from a Gmail account with your director’s name typed into the display field, and because Gmail was the real sending service, the message looked technically legitimate. 

That gap sits in most Australian businesses, and very few know it is there. Email compromise is now the most reported cybercrime affecting Australian organisations. ASD’s Annual Cyber Threat Report 2024-25 found 19% of business reports involved email compromise with no money lost, and another 15% involved business email compromise where funds did move. Over the same period, the average self-reported cost of cybercrime for a medium-sized Australian business climbed 55% to $97,166. 

Here is what email spoofing is and what you can do to reduce the risk. 

What is email spoofing?

Email spoofing (or email impersonation) is forging the sender details of a message so it appears to come from someone the recipient trusts. 

The forgery can happen in three different places:

  1. The domain the message claims to be sent from 
  2. The display name shown next to it, or
  3. A cosmetically similar domain specifically purchased with the intent to deceive you.  


Each type of impersonation produces the same result in the recipient’s inbox, which is a message that looks like it came from a person they know. Domain-level protections reduce one category of abuse, but they do not stop every email that looks like it came from someone your staff trust. 

Spoofing is often used to land a spear phishing attack in your mailbox. The sender looks familiar, so the request feels more believable.

The different types of email spoofing

There are three types of spoofing that malicious actors will often employ:

Exact-domain spoofing

The attacker sends mail claiming to be [email protected], using your real domain. This is the attack domain-level protections are built to reduce. When they are configured properly, the receiving server can identify that the message has not been sent by an authorised source and reject it. 

Display-name spoofing

The attacker registers an ordinary Gmail or Outlook account and sets the display name to “David Chen, Managing Director”. The message arrives from a real consumer mailbox. The issue is not that Gmail is being forged. The issue is that the name shown to the recipient belongs to someone inside your business. On a mobile screen, most email clients show only the display name, not the full email address. 

Lookalike domain spoofing

The attacker registers yourcompany-au.com or swaps a lowercase “L” for a capital “i”, then sends from infrastructure they legitimately control. From a technical point of view, the email may look clean. To a busy person approving an invoice, it looks like it belongs to you, but in fact belongs to somebody else. 

Sender checks do not solve impersonation on their own

Protecting your own domain helps stop attackers from sending as your exact organisation, but most staff do not examine the technical path a message took before it reached them. They look at the name, the request, the timing and whether the email feels plausible.

That is why the practical question is: Can the email platform recognise when a familiar name is being used from an unfamiliar source?

Microsoft 365 will not block display-name impersonation on most licenses

This is the part that surprises most people. Microsoft 365 includes strong email security features, but that does not mean every type of impersonation is automatically blocked.

Basic protection helps filter suspicious mail, but display-name impersonation usually needs extra protection and the right settings. Without that, an email from a real Gmail account using your managing director’s name may still reach a company inbox.

If your business is unsure what your Microsoft 365 plan includes, the safest step is to have it reviewed rather than trying to interpret the licences yourself.

Some Microsoft 365 plans include extra protection against impersonation, but licensing can be hard to untangle. If you are not sure what your business has access to, Windstil can review your Microsoft 365 setup and confirm what is switched on, what is missing, and what needs to be configured. 

The key point is simple: having Microsoft 365 is not the same as having impersonation protection switched on. It needs to be checked and configured properly. 

What to do if your domain is being spoofed right now

If you are getting bounce messages for emails you never sent, or clients are forwarding you messages with your name on them, work through this order.

  1. Don’t assume it is only spoofing. If emails are being sent in your name, we can help confirm whether your mailbox has been compromised or whether someone is impersonating you from outside your system. That distinction matters, because each situation needs a different response. If there is any sign of a breach, we will help you lock down the affected account before anything else. 
  2. Send us an example of the message. We can check whether it is coming from your real domain, a lookalike domain, or an outside account using a familiar name. That will help decide the right next step. 
  3. Warn clients and suppliers quickly. Tell them fake emails may be using your name or domain, and ask them to confirm any unusual request by phone using a number they already trust. They should not rely on phone numbers or contact details included in the suspicious email. 
  4. Check for lookalike domains. Attackers sometimes use web addresses that look almost identical to yours. If that is happening, we can help work out what can be reported, blocked or monitored.

How to minimise the impact of email spoofing

These steps make it harder for fake emails to get through and easier for staff to spot when something is not right. 

  1.  Check who is allowed to send email for your business. Your website, invoicing system, marketing platform and Microsoft 365 account may all send email on your behalf. We can make sure those systems are set up properly, so it is harder for someone else to copy your domain. 
  2. Protect the names attackers are most likely to copy. Directors, finance staff and anyone who approves payments are common targets. We can add extra checks around these people so suspicious emails using their names are more likely to be flagged. 
  3. Watch for fake versions of your domain. Attackers often register web addresses that look close to yours. We can help identify the obvious copies and monitor for new ones, so your team is not caught by a near-match. 
  4. Mark emails that come from outside your business. A simple warning on external emails gives staff an extra prompt before they trust the sender name. It is especially useful when someone is pretending to be a manager or supplier. 
  5. Make account sign-ins harder to fake. Stronger sign-in protection makes it harder for attackers to get into important accounts, even if they trick someone into sharing a password or approving a login. 
  6. Confirm bank detail changes by phone. Use a number you already have on file, not one from the email. This is the last check before money leaves the business, so it should be part of your normal approval process. 

 

Most of this is configuration rather than expenditure, and a fair share of it sits inside licences you are already paying for. 

If you are not sure which protections are switched on, or what your Microsoft 365 licence includes, request a callback with our team. We will review your setup and show you where the gaps are before someone else finds them.

Windstil provides cyber security consulting for Australian businesses. Our active clients enjoy a structured, ongoing approach to Essential Eight, with clear prioritisation, consistent progress and guidance to improve their maturity over time.

Subscribe to our newsletter

  Stay informed with practical IT and cyber security insights, along with company updates, announcements, and the work we’re doing with businesses like yours.