Distinguishing brand impersonators from real competitors using SPF

A finance staffer in Sydney opens an invoice that looks correct. The logo matches, the bank details have changed, and the domain reads "acme-payments.com" rather than the usual "acme.com.au". Within hours, the company has wired thousands of dollars to a fraudster running a brand impersonation domain. The ACCC's Scamwatch reports that business email compromise losses have climbed well past $100 million in recent years, and similar cases now land on Australian security teams almost weekly.

SPF, or Sender Policy Framework, was never built to stop these attacks alone. It was designed to let a domain owner publish which mail servers are allowed to send email on their behalf. Yet because every sending host leaves a trace in DNS, an SPF record can quietly reveal whether a domain is a quiet corporate sender, an aggressive marketing machine, or a freshly registered lookalike with no real infrastructure behind it.

That makes SPF one of the most useful free signals for separating a legitimate competitor from a brand impersonation domain. Reading it carefully, and pairing it with a few other checks, can turn a confusing inbox into a much clearer risk picture.

How brand impersonation domains hide in plain sight

Impersonators rely on subtle visual tricks. They register domains such as "company-payments.net", "c0mpany.com", or a country-coded variant like "company.com.au-id.au" to slip past busy employees. The emails often mimic the tone of an Australian supplier, reference local suburbs in Melbourne or Brisbane, and may even copy a real ABN from public registers to look more credible.

Lookalike domains are cheap to launch. A scammer can register a fresh .com for under twenty dollars, point it to a free mailbox provider, and start sending within the hour. With no history, traffic, or customer base, the impersonator can move quickly before blacklists catch up. These unrated trust scores often point to a brand new registration rather than a long-standing business.

What a legitimate competitor's DNS footprint looks like

A genuine competitor, even one your customer has never heard of, usually has years of DNS history. They will have an SPF record listing several include mechanisms, often referencing transactional senders, marketing platforms, and a primary mail server. MX records will point to a hosted exchange provider such as Microsoft 365 or Google Workspace, and the domain will resolve to a populated website with real content.

A real Australian competitor will frequently operate under a .com.au or .net.au address, which requires a valid ABN to register. This single administrative hurdle filters out most casual impersonators, who prefer cheaper generic TLDs. You will also see DMARC and DKIM records in place, along with a published policy that shows the company takes email authentication seriously.

Reading SPF records as a trust signal

SPF is published as a TXT record beginning with "v=spf1". The mechanisms that follow tell you which IPs, hostnames, or include domains are permitted to send mail. A real corporate domain typically lists several entries, with an "-all" or "~all" qualifier at the end. A blank record, a "v=spf1 -all" string on a domain actively sending marketing email, or a record full of unrelated third-party includes should raise immediate suspicion.

When an SPF lookup exceeds the ten-mechanism limit, records often break silently. Mail gets rejected or marked as softfail, and the sending domain's reputation erodes. The deeper effects of this kind of failure are explored in the broken SPF record guide, and the lesson applies whether you are auditing your own domain or judging someone else's.

Running SPF checks from Brisbane to Perth

You do not need a corporate account to start checking domains. A simple nslookup or dig command against any domain will return its SPF record, and free web tools translate the raw string into readable English. Run the same check on the suspect domain and on a known competitor in the same industry to compare infrastructure depth.

For teams handling higher volumes, the platform's dashboard makes it easier to compare many domains at once and flag those with thin, missing, or freshly changed SPF records. A small Perth-based agency reviewing a new client's email setup can do this in minutes without a paid subscription.

When SPF alone falls short

SPF only checks the envelope sender, not the visible From address. This means a brand impersonation domain can pass SPF with a valid include while still presenting a fake brand in the inbox. A lookalike domain can also copy a competitor's SPF string wholesale, since SPF records are public. Looking at the record tells you who is allowed to send, not who is actually pretending to be the brand.

DKIM and DMARC fill that gap. DKIM signs individual messages with a cryptographic key, and DMARC aligns that signature with the From domain. When all three are published correctly, a spoofed email usually fails at least one check. In Australia, the Notifiable Data Breaches scheme and guidance from the Office of the Australian Information Commissioner push organisations towards strict policies rather than permissive ones.

Building a complete picture before you click

Before acting on an email, take ten seconds to check the visible domain against its SPF record. Confirm it is not a fresh registration, that the SPF list makes sense for a company of that size, and that DKIM and DMARC are also present. If unsure, report the message to Scamwatch or the ACSC's ReportCyber portal so others can be warned.

Brand impersonation domains are getting more polished, but their DNS infrastructure usually betrays them. A few minutes of SPF analysis, combined with broader authentication signals, can tell you whether you are looking at a quiet competitor in Adelaide or a fast-moving imposter in a data centre overseas.