A changed bank account number can look like a routine invoice update. The email may use your vendor's logo, reference a real project, and arrive in the same thread as prior messages. To prevent invoice email fraud, your team needs more than a quick glance at the sender name. You need a payment process that verifies changes before money moves.
Invoice fraud is not one single trick. Sometimes a criminal creates a lookalike email address and impersonates a vendor. In other cases, they gain access to a legitimate vendor mailbox and send convincing instructions from the real account. Your controls must account for both.
Treat payment changes as a separate request
The straight answer is simple: never accept new payment instructions from email alone. A request to change bank details, payment recipients, mailing addresses, or invoice routing deserves a second verification step, even when the message appears legitimate.
Call a known contact at the vendor using a phone number already on file. Do not use the number included in the email signature or a new attachment. If your team uses a vendor portal, confirm the change there through an established account. The goal is to use a communication path that the sender of the suspicious email cannot control.
This rule should apply to urgent requests too. Fraudsters often create urgency by claiming an account will be suspended, a shipment will stop, or a late fee is due. A real deadline may exist, but it does not remove the need to verify new payment details.
Check the sender address, not just the display name
Email software often shows a friendly name first, such as Accounts Payable or Jane at Vendor Company. That field is easy to copy. Expand the sender details and inspect the full email address before responding or opening an attachment.
Look for small changes that are easy to miss: a swapped letter, an extra word, an unfamiliar country-code domain, or a free email address replacing the vendor's normal business domain. A message from billing@vendorco.com is different from billing@vendor-company.com, even if the display name is identical.
Still, a correct address is not automatic proof. A compromised vendor mailbox can send fraud from the real address. That is why address review is a useful first screen, not the final approval.
When an invoice seems unusual, check several details together:
- Is the sender address exactly consistent with prior verified correspondence?
- Does the invoice number, service period, and amount match a purchase order, contract, or expected recurring charge?
- Does the request introduce new bank details, a new payee, or an unfamiliar payment method?
- Is the sender asking you to bypass your usual approval process or keep the request confidential?
One warning sign may have an innocent explanation. Several warning signs are enough to pause payment and verify the request outside email.
Give invoice approvals clear limits
A good process makes it hard for one rushed person to approve a change alone. Separate the person who receives an invoice from the person who releases payment when your staffing allows it. For smaller organizations, that may mean an owner confirms vendor banking changes while an office manager prepares the payment.
Set a written threshold for additional review. For example, any new vendor, bank-detail change, first-time wire transfer, or payment above a defined amount requires a second approver and direct vendor confirmation. The exact threshold depends on your normal payment volume and cash flow. What matters is that people know the rule before a convincing email lands.
Keep a simple record of who verified each change, when they called, and which known contact confirmed it. This creates a reliable trail for your team and prevents someone from having to reconstruct a decision later.
Be careful with reply chains. A fraudulent message can arrive as a reply to a real conversation if a mailbox has been compromised. Replying may simply send your question back to the criminal. Start a new message using a trusted address from your vendor file, or call the established contact instead.
Make your own domain harder to impersonate
Payment fraud affects both sides of the invoice. If criminals impersonate your business, they can send your customers fake invoices or redirect payments. Email authentication helps receiving mail systems evaluate whether a message claiming to be from your domain is authorized.
SPF, or Sender Policy Framework, is a Domain Name System record that identifies the mail servers allowed to send email for your domain. It helps receivers identify unauthorized sending sources, but it does not protect every visible sender address by itself.
DKIM, or DomainKeys Identified Mail, adds a cryptographic signature to outgoing messages. That signature lets receiving systems check whether the signed message was altered after it was sent and whether it was authorized by your domain.
DMARC, or Domain-based Message Authentication, Reporting, and Conformance, brings SPF and DKIM together. It tells receiving systems how to handle messages that fail authentication and provides reports about messages using your domain. DMARC also checks alignment, meaning the domain visible in the From field should match the domain validated by SPF or DKIM.
These controls reduce opportunities for direct spoofing. They do not stop a criminal who has taken over a real mailbox, and they do not replace payment verification. They are separate layers, which is exactly why they work well together.
Getting authentication right can be more involved than adding a single record. Businesses often send email through their primary mailbox provider, accounting software, customer relationship platform, appointment tool, or marketing service. Every legitimate sender needs to be accounted for before you tighten your DMARC policy. Otherwise, valid business email can fail authentication.
Protect the mailboxes that handle money
Your accounts payable mailbox, executive mailbox, and vendor-management accounts deserve extra protection because criminals target them for access and authority. Require multi-factor authentication, which asks for a second verification step beyond a password. Use unique passwords stored in an approved password manager, and remove access promptly when an employee changes roles or leaves.
Also review mailbox forwarding rules. An attacker who gains access may create a hidden rule that forwards invoice conversations to an outside address, deletes replies, or marks messages as read. These rules can let a criminal watch a payment discussion and intervene at the right moment.
Train staff to report suspicious invoice messages without embarrassment. The person who pauses a payment has done their job well, even if the invoice turns out to be genuine. A short internal reporting path is better than vague advice to be careful.
Respond without making the situation worse
If a payment-change email looks suspicious, do not reply, click a link, open an unexpected attachment, or forward it broadly. Preserve the original message so your technical team can review the full sender details and headers. Then contact the vendor through a known, independent channel.
If money was already sent, contact your bank or payment provider immediately and follow its fraud-reporting process. Notify the real vendor through a verified contact as well. Internally, review recent invoices and payment requests from that vendor, because a single fraudulent email may be part of a longer attempt.
If the message claims to come from your company, check whether the sending domain is actually yours or a lookalike. A lookalike domain may require brand and vendor communication. Mail sent from your real domain may point to a compromised account or an email authentication gap. The investigation changes based on that distinction.
Make the next invoice change safer
Choose one person to own the bank-detail verification rule, document the trusted contact method for your active vendors, and tell the team that email alone never authorizes new payment instructions. Then use MailArrive's free email health check and Report Card to grade your domain's SPF, DKIM, and DMARC setup and identify the exact fixes needed to reduce impersonation risk.
