Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
By problem · Forged invoices

Stop fake payment requests sent in your name

A forged invoice, or a request to change bank details, arrives from an address that reads as yours. We read from outside what makes that possible at your firm, and give your IT provider the steps that close it.

Attackers use AI to find openings. We use it to find yours first, and a person checks every finding before you see it.

Read-only, from outsideNothing tested or logged intoReviewed by a person
What we check for thisRead-only
Your mail
Whether a message forged in your name is delivered (SPF, DMARC)
Look-alikes
Registered names one character from yours
Staff addresses
Which appear in monitored breach databases, from which breach
Public pages
Payment or banking details a forger can copy
Reviewed by a person before release. Every finding carries a check anyone can run.
In 24 seconds · no sound

How a forged invoice gets sent in your name.

Captions on, no sound. Illustrative; no real firm is shown.

Read the transcript
  1. This invoice looks like yours. You didn’t send it.
  2. An invoice arrives that reads as yours, asking a client to change bank details.
  3. Four openings make that possible. First: email anyone can forge. Your mail records say whether it is refused.
  4. Second: look-alike domains, one character from yours.
  5. Third: staff addresses in breach records. A reused password can open a real mailbox.
  6. Fourth: payment details posted on your own public pages.
  7. All four can be read from outside. We log into nothing and test nothing.
  8. See what a forger would see, before one uses it. Check my firm.
01 · What we check

Four ways a forged payment request gets through.

01
Email anyone can forge

Your SPF and DMARC records, in plain words: whether a message that fakes your address is refused or delivered.

02
Look-alike domains

Names one character from yours, or with another ending, that resolve today and could send an invoice that reads as yours.

03
Staff in breach records

Addresses at your domain in monitored breach databases. A reused password can open a real mailbox, and a real conversation with a client.

04
Payment details in public

During the assessment your public pages are read the way someone impersonating you would read them, for posted banking details, payment instructions and who approves payments, and a person approves what is reported.

02 · What it costs, as reported

The published figures, with their sources.

$3.05B
Business email compromise losses reported to the FBI in 2025
24,768
Business email compromise complaints to the FBI in 2025
58%
Of the FBI Recovery Asset Team’s 2025 freeze attempts on reported fraud that held the money. Reporting fast matters.

Reported losses, as the publisher states them. They describe what was reported, not what will happen to your firm.

03 · What we read

The outside view, in plain words.

Your mail records
The SPF, DKIM and DMARC records your domain publishes. Check it yourself: look up your domain's DMARC record with any free DNS lookup.
Registered names
Names one character from yours, and other endings, that resolve today. Check it yourself: type your domain with one letter changed.
Monitored breach databases
Published breach lists, searched for addresses at your domain, with the date of each breach and what it listed.
Your public pages
Read during the assessment, with a person approving what is reported: posted banking details, payment instructions, and the names of the people who approve payments.
What it cannot see
Your inbox, your bank, or whether a payment has already gone astray. We log into nothing and test nothing.
How we are different

Next to the people you already work with.

Your IT provider

Keeps your systems running and does the fixes. We give them an independent list to act on, with the check that proves each fix. We are paid by no one who sells the fixes, so every finding is independent.

A penetration test

Tries to break in and needs access. We read only what is already public, from outside, and log into nothing.

Your insurer's scan

Feeds your premium and eligibility. We show you the same outside view first, in plain words, so you walk into renewal knowing the answers.

For your firm

See what a forger would see, before one uses it.

The External Exposure Check: your outside reading, with what we found and a check you can run yourself. No access, nothing tested.

Check my firm