Email Rules and Account Controls That Block Invoice Fraud

Many diversion scams start inside a compromised mailbox. These configuration steps help catch hidden forwarding rules, lookalike domains and risky sign-ins.

3 min readBy Ironfield Cyber Team

Most invoice fraud begins with an email problem: a compromised mailbox at your company or at a vendor, or a lookalike domain that fools a busy reader. Process controls such as callback verification remain the most important defense, but technical settings can catch many attacks earlier, or make them harder to execute.

This post covers practical configuration steps for contractors and energy companies. Details vary by email platform, so treat it as a checklist for your IT provider to implement in Microsoft 365 or whichever system you use.

How attackers use mailboxes

Once criminals have a mailbox password, they usually do not announce themselves. They read messages to learn who you pay, when invoices are due, and how people write. They may create rules that hide replies or forward copies of messages elsewhere. Then they insert themselves at the right moment, sometimes replying within a genuine thread with new banking instructions.

Understanding that pattern points to the settings that matter.

1. Enforce multi-factor authentication

Password-only email access is the single biggest weakness. Require MFA for every user, especially accounting staff, project managers, and executives. Prefer stronger methods such as authenticator apps or hardware keys over text messages where possible, and block older sign-in methods that bypass MFA.

2. Alert on suspicious inbox rules

Attackers frequently create rules that auto-forward messages to outside addresses, move messages to obscure folders, or delete messages containing words like invoice, payment, or wire. Configure alerts for new forwarding and rules, and consider blocking automatic external forwarding unless there is a business reason. Review existing rules in finance mailboxes.

3. Watch sign-in activity

Enable alerts for risky sign-ins, such as logins from unfamiliar countries, impossible travel between locations, or unusual devices. Review reports of failed and successful logins. When an alert fires on a finance mailbox, treat it as urgent, since a successful sign-in from an unexpected place may mean the account is compromised.

4. Mark external email clearly

Add a visible banner to messages from outside your organization. A clear warning helps staff notice when an email that claims to be from the owner or a coworker did not originate internally.

5. Defend against lookalike domains

Attackers register domains that resemble yours or your vendors, differing by a single character. Steps to reduce this risk:

  • Use email filtering that flags newly registered or lookalike domains.
  • Add your frequent vendors' domains to a watch list for comparison.
  • Consider registering common variations of your own domain.
  • Teach staff to read the full address, not just the display name.

6. Configure email authentication for your own domain

Settings known as SPF, DKIM, and DMARC help receivers verify that mail claiming to come from your domain actually does. A properly enforced DMARC policy makes it harder for criminals to spoof your company's address when emailing your customers and vendors. Your IT provider can implement these gradually, monitoring reports before enforcing strict policies.

7. Limit who can send as whom

Restrict permissions that allow one user to send on behalf of another, and review delegated access to executive mailboxes. Review shared mailboxes such as accounts payable, which often have many members and weaker controls.

8. Protect attachments and links

Use filtering that scans attachments and rewrites or checks links at click time. Block risky file types. Sandboxing suspicious files can catch what signature-based tools miss.

9. Keep logs

Make sure mailbox auditing is enabled and logs are retained long enough to investigate. When fraud occurs, investigators will want to know when an account was accessed, from where, and what was read or changed.

10. Add a payment-change alert

Where possible, configure rules that flag incoming messages containing phrases about changing bank details, new account numbers, or updated remittance instructions. These alerts can prompt staff to apply callback verification before anything else happens.

Combine with process controls

Technical measures reduce exposure but do not replace verification. Pair them with the following:

  1. Callback verification for every banking change.
  2. Separation of duties between vendor setup and payment approval.
  3. A short hold period before paying to new instructions.
  4. Quick, blame-free reporting of suspicious messages.

Test periodically

Ask your IT provider to confirm settings quarterly. Send a harmless test message from an external address to see whether banners appear and filters behave as expected. Review lists of users without MFA, and any delegated access to finance mailboxes.

Support from Ironfield Cyber

Ironfield Cyber configures and monitors email security for contractors and energy firms, including MFA, rule alerts, domain protections, and training. If you would like a review of your finance team's mailbox settings, we can do it quickly.