ContentsTap to jump to a section+
- A polished email is not trustworthy just because it sounds like an executive or partner.
- Enable strong MFA for email and administrator accounts before other systems.
- Any request changing payment, passwords or data needs a second verification channel.
Phishing no longer looks careless
A fraudulent email can now reference a real project and sound like a familiar colleague. Spelling checks alone are no longer enough; the organisation needs controls that reduce the chance of a busy person making one mistake.
Layer one: protect domains and accounts
SPF, DKIM and DMARC help receiving servers validate mail sent from your domain. They are not a complete defence, but make spoofing harder. Enable strong MFA for email and administrator accounts.

Layers two and three: verify elsewhere, preserve evidence
Payment, access or data requests need confirmation through a known second channel. Give staff an easy way to report suspicious mail, then preserve the evidence and respond quickly.
FAQ
Frequently asked questions
Do SPF, DKIM and DMARC replace anti-phishing protection?
No. They authenticate a sending domain; filtering, MFA, training and verification workflows still matter.
Is SMS MFA enough?
Any MFA is better than none, but methods vary in strength. Prefer phishing-resistant options where available.
References
Sources used in this guide
We prioritise official guidance and primary technical sources. Visit each source for full context and the latest updates.