All articles
PhishingDMARC

What Happens When Anyone Can Send Email as Your Store

· 6 min read

Glowing blue envelope with a cracked seal and a shadowy figure behind it, representing a spoofed email

A fake “your order is delayed” email, a stolen card, and a customer who blames you. Here's how domain spoofing works — and how DMARC shuts it down.

The scam, in plain terms

Picture one of your customers. They ordered from you last week, and this morning an email arrives: “Your order is delayed — please confirm your payment details.” It has your logo. It comes from an address ending in your domain. They click, they type their card number, and it's gone.

Nothing was hacked. Nobody broke into your store. The criminal simply sent an email and wrote your domain in the “From” field. Email was designed in an era of trust, and by default it doesn't check whether the sender is who they say they are.

When the fraudulent charge shows up, your customer doesn't blame the scammer they never saw. They blame the store whose name was on the email — you.

Why “be careful with this message” warnings appear on real email

Inbox providers like Gmail and Outlook know spoofing happens. When they receive an email claiming to be from your domain but can't verify it, they get suspicious — and that suspicion also falls on your real email.

That's why legitimate stores sometimes see their own newsletters land with a yellow warning banner, or vanish into spam entirely. Without authentication, providers can't tell your real email apart from the fakes, so they treat everything cautiously.

The fix: what DMARC enforcement actually does

DMARC is a short public record in your DNS that tells inbox providers: “Here's how to check if email really comes from us — and if it fails, reject it.” It builds on SPF (which lists the servers allowed to send for you) and DKIM (which signs each message cryptographically).

With DMARC at enforcement, a spoofed “order delayed” email never reaches your customer. Gmail checks it, sees it fails, and drops it. Your real email, meanwhile, passes cleanly and earns more trust.

The catch is that enforcement must be rolled out carefully. Flip it on too early and you can block your own legitimate tools — your review app, your helpdesk, your ESP. That's why we always start in monitoring mode and verify every sender first.

What to do this week

Check whether your domain has a DMARC record at all. If it doesn't, or if it's set to “p=none” and has been for months, your domain can still be spoofed today.

List every tool that sends email for you: your store platform, your newsletter tool, your helpdesk, your invoicing app. Each one needs to be authenticated before enforcement is safe.

Or skip the homework: book a free audit and we'll tell you in 48 hours exactly where you stand.

Is your domain set up correctly?

Find out free — we'll tell you in 48 hours.

Book a Free Audit