Wire Fraud Protection

DMARC Deployment Stopped $2.3M Wire Fraud Attempt

August 24, 2026 · Title & Escrow · Florida

Engagement Snapshot

Client: Florida Title Company (name anonymized)
Industry: Title & Escrow
Attack: Business Email Compromise — Domain Spoofing
Exposure: $2.3M wire fraud
Outcome: 3 spoofing attempts blocked in first week · $0 loss · p=reject enforced

The Incident

A Florida title company with zero email authentication was actively targeted by a business email compromise (BEC) scheme. The attackers were spoofing the firm's domain to send fraudulent wire transfer instructions to closing agents. No SPF, DKIM, or DMARC records existed. Every email from the firm was unauthenticated and trivially spoofable.

What We Did

Before vs After

Security Score4595
Email Authentication
Spoofing Attempts Blocked03 in first week
Wire Fraud Exposure$2.3M$0

Key Takeaways

Unauthenticated email is an open door for wire fraud. Without DMARC p=reject, anyone can send as your domain. Authentication is not optional for firms handling wires.

FAQ

How does DMARC stop wire fraud?

DMARC prevents attackers from spoofing your domain. When a fraudulent email claiming to be from your firm arrives, DMARC instructs the receiving server to reject it before it reaches the inbox.

Will DMARC affect legitimate email?

No. When correctly deployed with SPF and DKIM alignment, legitimate mail passes and only spoofed mail is rejected.

Don't wait for the breach

The best time to harden was before the incident. The second best time is now.

Deploy Protection

Other Case Studies