Skip to content

Home Topics Email Security Management Business email compromise

Email Security Management · Business email compromise

Business email compromise (BEC) not working? Troubleshooting guide

Short answer

When business email compromise (BEC) fails, check in this order: the DNS or platform configuration is published and resolves; the sending system is actually using it; the domain in headers aligns with what you published; and the receiver's verdict in Authentication-Results or bounce messages.

Symptoms#

  • Messages landing in spam despite previously good placement
  • Bounces mentioning policy, authentication, or reputation
  • Provider dashboards showing a drop in reputation or authentication pass rate

Diagnosis steps#

  1. Confirm the configuration is live: query DNS from an external resolver and check the sending platform's settings page.
  2. Send to a seed mailbox and read the full headers, especially Authentication-Results.
  3. Compare the domains in From, Return-Path, and DKIM d= for alignment.
  4. Check provider dashboards (Google Postmaster Tools, Microsoft SNDS) for reputation and error rates.
  5. Review recent changes: new vendors, DNS edits, list imports, volume spikes.

Likely causes#

  • Assuming DMARC protects against BEC from a compromised real account.
  • No out-of-band verification policy for finance.

Fix and re-verify#

  1. Require MFA on all mailboxes and disable legacy authentication protocols.
  2. Alert on new inbox rules that forward or delete mail, a common attacker persistence step.
  3. Verify payment changes by phone using a known number, never the one in the email.
  4. Flag external mail with display names matching internal staff.

Frequently asked questions#

How is BEC different from phishing?

Phishing casts wide for credentials; BEC is targeted social engineering for money, often using a real hijacked account.

Keep reading on Business email compromise