The first time I saw a fake invoice land in a local hardware store’s inbox, it looked perfect. The logo was right. The font matched their previous statements. The amount was small enough that nobody would question it, but large enough to make the bookkeeper pause. It came from an address that looked like the supplier’s domain, except for a subtle difference in the spelling. By the time the store realized the email was spoofed, the money had already moved.
This is not a big-city problem. It is a small-business problem. In Quincy, where many shops operate on thin margins and rely on trusted vendors, a single bad invoice can eat a week’s profit. The fix is not a new accounting software or a bigger security team. It is a DNS record called DMARC.
Why spoofing works on small shops
Email spoofing is easy because the original email system was designed for trust, not verification. A sender can claim to be anyone. If you buy parts from “Acme Supply” at acmesupply.com, a hacker can send an email from “acmesupply.co” or “acmesupply.net” and it will still land in your inbox. Most email clients do not check if the sender is actually who they say they are. They just check if the email is valid.
For a Quincy shop, this is dangerous because you likely have a small list of vendors. You know their names. You know their products. When an email arrives that looks like it came from your usual supplier, your brain skips the verification step. You see the invoice, you see the familiar logo, and you pay. The hacker does not need to hack your computer. They just need to guess your vendor’s domain name correctly.
DMARC changes this. It tells your email provider to check if the sender is authorized to use that domain. If the domain says “only send from these specific servers,” and the email comes from somewhere else, your inbox can flag it, quarantine it, or reject it.
How DMARC actually works
You do not need to be a coder to set this up. You need to add a text record to your domain’s DNS settings. This record is called the DMARC policy. It has three parts:
- The policy: This tells the receiver what to do with failing emails. It can be “none” (just report), “quarantine” (move to spam), or “reject” (bounce back).
- The report address: This is where the receiver sends you a summary of who is sending email on your behalf. This is crucial for finding out if someone is spoofing you.
- The subdomain policy: This decides if the rules apply to subdomains like “billing.acmesupply.com.”
When you start, you set the policy to “none.” This means you are just watching. You will start receiving daily reports from Gmail, Outlook, and Yahoo. These reports show you every email sent from your domain. You will see your legitimate emails, and you will also see the spoofed ones. Once you know who is sending email for you, you can tighten the policy to “quarantine” and then “reject.”
A practical step-by-step for a local shop
If you run a shop in Quincy, here is how you handle this without hiring a consultant.
- Check your current setup. Log into your domain registrar (like GoDaddy, Namecheap, or Cloudflare). Look for the DNS management section.
- Add the DMARC record. Create a new TXT record. The name should be `_dmarc`. The value should start with `v=DMARC1; p=none; rua=mailto:you@yourshop.com`. Replace `you@yourshop.com` with an email address you check often.
- Wait for reports. Within 24 to 48 hours, you will start getting emails from major providers. These are not spam. They are data. Open them. Look for the “source IP” addresses.
- Identify the good senders. You will see IPs from your email provider (like Microsoft 365 or Google Workspace). You will also see IPs from your marketing tools (like Mailchimp). These are your friends.
- Identify the bad senders. You will see IPs you do not recognize. These are likely spoofers. If you see a lot of them, you know the problem is active.
- Tighten the policy. Once you are sure you know all your legitimate senders, change the `p=none` to `p=quarantine`. This will move failing emails to the spam folder. Watch for a week. If nothing breaks, change it to `p=reject`.
Common mistakes to avoid
Many shop owners make the same errors when setting this up.
- Skipping the “none” phase. If you jump straight to “reject,” you might block your own legitimate emails. This happens if you forgot to add a marketing tool to your allowlist. Always start with “none.”
- Using a shared inbox for reports. If you send reports to `info@yourshop.com`, and that inbox is full, you will miss the data. Use a dedicated email address like `dmarc@yourshop.com`.
- Forgetting subdomains. If you use `billing.yourshop.com` for invoices, you need to make sure your DMARC record covers subdomains. Add `sp=none` to your record to start.
- Assuming it is set and forget it. Email systems change. New vendors appear. Check your reports quarterly. If you see new IPs, investigate them.
What this means for your cash flow
When you stop spoofed invoices, you stop paying for parts you never ordered. You stop chasing refunds. You stop arguing with vendors who claim they never sent the email. DMARC is not a magic bullet, but it is the cheapest line of defense you have. It costs nothing to set up. It takes an afternoon to configure. And it saves you from the most common email scam targeting small businesses.
In Quincy, we look out for each other. Your vendors look out for you. But the internet does not. DMARC is how you tell the internet who you are. It is a small technical step that has a big financial impact. Do not wait for the next fake invoice to arrive. Set up the record today. Check your reports next week. And keep your cash where it belongs: in your register, not in a hacker’s pocket.