The Email Infrastructure Red Flag That Most Risky Suppliers Share
Our verification data shows that missing DMARC and SPF records are among the strongest early indicators of supplier risk. Here is why email infrastructure matters for invoice fraud prevention.
In our verification dataset, one signal consistently distinguishes legitimate, established businesses from newly registered or high-risk entities: the presence of proper email authentication infrastructure.
Specifically: whether a supplier's domain has DMARC and SPF records configured.
This sounds like an IT concern. It is actually an accounts payable concern.
What DMARC and SPF are, and why they matter
SPF (Sender Policy Framework) and DMARC (Domain-based Message Authentication, Reporting and Conformance) are DNS records that tell receiving mail servers which servers are authorised to send email on behalf of a domain — and what to do when they receive messages that fail this check.
A legitimate business that has been operating for more than a year, receives and sends business email, and cares about its communications infrastructure will almost always have these records configured. It is a standard part of business email setup.
A fraudulent supplier domain — registered in the last few weeks to facilitate a specific scam — typically has none of these. The domain exists to receive one or two invoice payments, not to support an ongoing email operation.
The invoice fraud pattern
| Risk Indicator | Risk Level | Description |
|---|---|---|
| Missing DMARC | High | Phishing vulnerability |
| No SPF Record | Medium | Spam filtering issues |
| Weak Email Auth | Low | Information disclosure |
| Outdated DNS | Medium | Security patch delays |
| Unsecured Email | High | Data breach risk |
Business email compromise (BEC) fraud typically follows one of two patterns:
- Domain spoofing: The attacker registers a domain that closely resembles a legitimate supplier (e.g., suppliercompany-pty.com instead of suppliercompany.com.au), creates a similar email address, and sends payment redirection requests from it. Without SPF/DMARC, this domain has no email reputation at all — but that does not trigger any warning in a standard AP workflow.
- New supplier registration: A fraudulent supplier entity is registered with a new ABN, a domain is acquired, and invoices are submitted. The ABN is genuine — newly registered — but the entire operation exists only to collect payment before disappearing.
In both cases, the absence of email authentication records is a signal. It does not confirm fraud, but it correlates strongly with risk.
What Gumshoe checks
The Gumshoe email infrastructure check queries the supplier's domain DNS records for SPF and DMARC configuration, checks whether the domain is on known email threat intelligence lists, and flags the domain if it was registered within the past 90 days.
A domain registered last week with no SPF, no DMARC, and no MX record history is a significant signal. Combined with a new ABN (registered within the past year) and no verifiable phone contact, this pattern should trigger manual review before any payment is processed.
The compounding effect of multiple signals
No single signal is determinative. A legitimate startup might have a new ABN and an imperfectly configured domain. The risk calculus changes when signals compound:
- New ABN (registered within 12 months) and
- Domain registered within 90 days and
- No SPF/DMARC records and
- No verifiable phone contact
This combination — which Gumshoe surfaces in the free tier checks — is one of the highest-risk supplier profiles in our dataset. It describes the operational profile of a significant proportion of invoice fraud attempts.
The email infrastructure check costs nothing and takes seconds. Including it in new supplier onboarding is the most straightforward fraud prevention improvement most organisations can make today.
Uncommon Insights
One of the lesser-known implications of the ATO's "genuine steps" requirement for verifying supplier identities (as per the A New Tax System (Goods and Services Tax) Act 1999, Section 165-40) is that it effectively mandates a review of a supplier's email infrastructure. This is because the ATO's guidance on supplier verification emphasizes the need to verify the authenticity of a supplier's communications, which includes email. In practice, this means that accounts payable teams should be checking for the presence of DMARC and SPF records as part of their supplier verification processes.
ASIC's Regulatory Guide 183 (RG 183) on "Verification of identity" notes that businesses must take reasonable steps to verify the identity of their customers and suppliers. However, what is often overlooked is that RG 183 also requires businesses to monitor and report suspicious transactions. In the context of invoice fraud prevention, this means that accounts payable teams should be monitoring their suppliers' email infrastructure for signs of suspicious activity, such as changes to SPF or DMARC records, which could indicate a phishing or spoofing attempt.
The ATO's data-matching protocols, as outlined in the Australian Government's Data-Matching Program Protocol (2014), emphasize the importance of verifying the authenticity of business records, including email communications. In practice, this means that the ATO may request evidence of a supplier's email infrastructure, including DMARC and SPF records, as part of its data-matching activities. Businesses that fail to maintain adequate email infrastructure records may be at risk of non-compliance with the ATO's data-matching protocols.
Corporations Act 2001 (Cth), Section 588G requires directors to take reasonable care to prevent their company from incurring debts that it may not be able to pay. In the context of invoice fraud prevention, this means that directors have a duty to ensure that their company's accounts payable processes are robust and include adequate checks on supplier identities, including email infrastructure. The absence of DMARC and SPF records from a supplier's domain can be a significant red flag, and directors who fail to address this risk may be in breach of their duties under Section 588G.
Run a free supplier check in seconds
Search by business name, ABN, or ACN. Instant PASS/WARN/FAIL across 8 verification signals.
Start verifying →