DMARC Deployment Stopped $2.3M Wire Fraud Attempt
The Incident
A Florida title company with zero email authentication was actively targeted by a business email compromise (BEC) scheme. The attackers were spoofing the firm's domain to send fraudulent wire transfer instructions to closing agents. No SPF, DKIM, or DMARC records existed. Every email from the firm was unauthenticated and trivially spoofable.
What We Did
- Deployed SPF, DKIM, and DMARC with p=reject — authenticated all legitimate mail and instructed receivers to reject spoofs at the gateway
- Configured monitoring for DMARC aggregate and forensic reports — alerts on any authentication failure
- Validated deliverability — ensured legitimate client communications were unaffected by the policy
Before vs After
| Security Score | 45 | 95 |
| Email Authentication | ✗ | ✓ |
| Spoofing Attempts Blocked | 0 | 3 in first week |
| Wire Fraud Exposure | $2.3M | $0 |
Key Takeaways
Unauthenticated email is an open door for wire fraud. Without DMARC p=reject, anyone can send as your domain. Authentication is not optional for firms handling wires.
FAQ
How does DMARC stop wire fraud?
DMARC prevents attackers from spoofing your domain. When a fraudulent email claiming to be from your firm arrives, DMARC instructs the receiving server to reject it before it reaches the inbox.
Will DMARC affect legitimate email?
No. When correctly deployed with SPF and DKIM alignment, legitimate mail passes and only spoofed mail is rejected.
Don't wait for the breach
The best time to harden was before the incident. The second best time is now.
Deploy Protection