How Spoofed Emails Slip Past the Bookkeeper
A vendor invoice lands in the bookkeeper inbox. The sender name looks right. The amount and due date match an open order. The bookkeeper clicks and the company loses money before anyone notices the domain was wrong. This happens when the email records that stop spoofing are not set or checked.
Good IT already owns those records for every mailbox in Microsoft 365. They review them after any staff change or domain update. The tell that your IT company is not doing the work is repeated spoof attempts that still reach users.
What These Three Records Actually Control
SPF lists which servers are allowed to send mail for your domain. DKIM adds a signature that proves the message was not changed in transit. DMARC tells receiving servers what to do when either check fails. Together they keep fake messages from looking like they came from inside the company.
When these records are missing or wrong, a laptop that left with a former employee can still be used to send mail that passes basic checks. Good IT updates the records the same day any device or user is removed. If your current provider never mentions these records after a staff change, that is the sign they are not managing them.
Signs Your IT Company Is Skipping the Work
- Spoofed messages continue to arrive weeks after a vendor or employee change.
- No one from IT has asked for a list of systems that send mail on behalf of the company.
- DMARC reports are never reviewed, so repeated failures go unnoticed.
These gaps let fake invoices reach the office manager and the bookkeeper without raising an alarm. The company pays for IT support yet still handles the fallout from spoofed mail.
What we do Bellwether keeps SPF, DKIM, and DMARC records current for every Microsoft 365 tenant we manage and reviews the reports each month so spoof attempts are blocked before they reach users.
Why the Records Must Be Checked After Every Change
A new accounting program or a remote worker on a personal laptop can add an authorized sender that was never recorded. Good IT adds that sender to the SPF list and tests the full chain. They also watch DMARC reports for new failure patterns that point to an old device still trying to send mail.
If your IT company treats these records as a one-time setup and never revisits them, spoofed mail will keep arriving. The office pays for protection that is not being maintained.
If your current IT company is not doing this work, reach out to see how Bellwether can take it over.