Payment diversion fraud usually begins with an email. Someone pretending to be a vendor, subcontractor, or executive asks accounting to change bank details, send a wire, or reroute a pending payment. The sooner suspicious messages are flagged, the less likely someone is to act on them under deadline pressure.
You cannot rely on staff vigilance alone. A handful of email rules and settings, most available in common platforms such as Microsoft 365, can add visible warnings and block obvious tricks. This article lists practical rules and how to use them without drowning your team in false alarms.
Why Email Rules Help
Fraudsters rely on messages that look ordinary. They use look-alike domains, hijacked real accounts, and subtle changes in reply addresses. Automated rules can notice patterns that humans miss, such as a message from a domain registered last week or a reply-to address that differs from the sender.
Rules do not replace verification procedures. They give your team a reason to slow down and apply them.
Rule 1: Tag External Senders
Add a visible banner or subject prefix to messages from outside your organization. This makes it harder for a spoofed internal address to pass unnoticed. Staff should learn that a message that claims to come from the owner but carries an external tag deserves suspicion.
Rule 2: Flag Look-Alike Domains
Anti-impersonation features can detect domains that closely resemble your own or those of frequent vendors, such as swapping a letter or adding a hyphen. Ask your IT provider to enable impersonation protection for your domain, your executives, and your top vendors.
Rule 3: Highlight Reply-To Mismatches
When the "from" address and the "reply-to" address differ, replies go to a different place. This is a common technique. Create a rule that adds a warning when they do not match.
Rule 4: Warn on Keywords in Financial Messages
For messages from external senders that mention terms such as new bank account, updated wire instructions, change of ACH, or remittance change, add a warning banner reminding staff to verify by phone using a known number. You can also route those messages to a finance review mailbox. Expect some false positives, and tune the keyword list over time.
Rule 5: Alert on New or Rare Senders
Flag messages from addresses that have never emailed your company before, especially if they relate to payment. Some email security products can do this automatically using sender history.
Rule 6: Block Auto-Forwarding to External Addresses
Attackers who gain access to a mailbox often create a rule that forwards copies of messages to themselves, or hides replies. Disable automatic external forwarding at the tenant level wherever possible, and alert on new inbox rules.
Rule 7: Monitor Mailbox Rule Changes
Create alerts for new rules that delete messages, move them to obscure folders, or mark them read. Attackers use these to hide their activity. Review such alerts quickly.
Rule 8: Add Authentication to Your Own Domain
Make sure your domain has properly configured SPF, DKIM, and DMARC records, ideally with a policy that blocks or quarantines spoofed mail. This protects your vendors and customers from fraudulent messages that claim to come from you, and it helps the wider ecosystem. Ask your IT provider to confirm and monitor your settings.
Pair Rules With a Human Procedure
Rules only help if staff respond correctly. Give accounts payable a simple, written process:
- Never change banking details based on an email, alone.
- Call the vendor at a phone number already on file, not one provided in the message.
- Require a second person to approve any change to payment instructions.
- Wait a defined period before sending the first payment to new instructions where feasible.
- Report suspected fraud immediately to IT and your bank.
The FBI's Internet Crime Complaint Center publishes guidance on business email compromise, which is a useful reference when training staff.
Avoid Alert Fatigue
If every message carries a warning, nobody notices them. Start with a few high-value rules, measure how often they trigger, and adjust. Consult with accounts payable about which warnings help and which annoy.
Test Your Setup
Ask your IT provider to send a harmless simulated message that mimics a bank change request and see whether your rules flag it. Review how long it takes staff to follow the verification procedure.
Closing Thoughts
Email rules are inexpensive, and they add a layer of defense where fraud actually begins. Ironfield Cyber can review your email security configuration, enable the protections that fit your environment, and help accounting teams build a verification routine that works under pressure.