EMAIL DOMAIN IMPERSONATION

Wanjohi Edwin 0 Reputation points
2026-08-04T13:18:35.1133333+00:00

Hello,

A domain impersonation issue has recently hit us.

The impersonating party solicited funds to be wired into their account.

How can we improve security on our end?

Outlook | Web | Outlook on the web for business | Security
0 comments No comments

1 answer

Sort by: Most helpful
  1. Michelle Nguyen 1,095 Reputation points Independent Advisor
    2026-08-04T13:39:28.22+00:00

    Hi @Wanjohi Edwin

    Thank you for bringing this to the community's attention.

    Domain impersonation and business email compromise attacks are unfortunately becoming increasingly common, particularly when financial transactions are involved.

    To help reduce the risk of similar issue, organizations should consider implementing a layered approach to security, including:

    • Configuring and enforcing SPF, DKIM, and DMARC to help prevent email spoofing.
    • Enabling anti-phishing and impersonation protection within their email platform.
    • Monitoring for lookalike domains that could be used to mimic their organization.
    • Establishing a formal process to verify any banking or payment-related changes through a secondary trusted channel before funds are transferred.
    • Enforcing Multi-Factor Authentication (MFA) for all accounts, especially those with financial or administrative privileges.

    If you're using Microsoft 365, reviewing your Defender for Office 365 anti-phishing policies and DMARC implementation would be a good starting point.

    Thank you for your understanding.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.