Business-e-mail compromise — a fraudster reading or imitating your mail to redirect a payment — costs Indian SMEs more than any other online fraud. The fixes are cheap.
Use your own domain
Mail from @yourbusiness.in can be authenticated; mail from @gmail.com cannot. Set SPF, DKIM and DMARC records for your domain (your provider's help page has the exact values) so a forged mail from your domain is rejected by the receiver.
Lock the accounts
2FA on every mailbox, especially accounts and the owner. Review forwarding rules and ‘app passwords’ monthly — attackers add a silent forward to a Gmail address and read everything.
The call-back rule
Any change to a vendor's bank account, any new payee, any ‘urgent’ payment request from the boss — confirmed by a voice call to a number you already had. Write it into the accounts SOP; a rule that lives only in someone's head fails on a busy Friday.
Reading a suspicious mail
Hover the sender to see the real address; look for a domain one letter off; check whether the tone or the request is unusual; open attachments only from expected senders; when in doubt, phone.
Checklist
- ☐Business mail on own domain
- ☐SPF, DKIM, DMARC published (p=quarantine or reject)
- ☐2FA on every mailbox
- ☐Forwarding rules reviewed monthly
- ☐Call-back rule written into the payment SOP
- ☐Staff phishing quiz done this quarter