When an Invoice Domain Scores Below 20

A trust score below 20 on a domain in your invoice email flow should force an investigation, especially when the message requests payment, bank-detail changes or urgent action. A low result does not prove fraud by itself, but it indicates that the domain, its authentication records or its sending history deserves immediate scrutiny.

Invoice scams increasingly target Australian businesses, from trades in Brisbane to professional firms in Sydney and Melbourne. A convincing message may copy a supplier’s branding, include an Australian Business Number and quote a legitimate GST invoice, while quietly directing funds to a different account.

Signal What it may mean Immediate response
Score below 20 Poor reputation, suspicious history or weak controls Pause payment and investigate
SPF or DKIM failure Unauthorised or incorrectly configured sending Verify with the supplier
DMARC policy set to none Spoofing may be harder to detect Review enforcement plans
Recently registered domain Possible impersonation or disposable infrastructure Compare with known records
Bank details changed High-risk payment diversion attempt Confirm using a trusted channel

Treat The Score As A Warning Signal

A reputation score is a triage tool rather than a final verdict. Low results can arise from spam complaints, malware associations, compromised mailboxes, poor DNS configuration, disposable domains or infrastructure shared with abusive senders. The correct response is to establish why the score is low and whether the domain is genuinely controlled by the expected supplier.

Start by recording the exact sender address, reply-to address, links, attachment names and message headers. Check whether the visible display name hides a different domain. An address ending in .com.au can still be fraudulent, while a legitimate overseas software provider may use another extension.

Verify The Sending Domain

Compare the invoice domain with previous correspondence, purchase orders and the supplier’s official website. Look for subtle substitutions such as rn replacing m, an added hyphen or a different top-level domain. Businesses operating across Perth, Adelaide or regional New South Wales should use an independently sourced phone number, not the number printed in the suspicious email.

A sender score checker can help review domain reputation, authentication signals and potential spoofing indicators in one place. Save the result with the email and header data so your finance or security team can compare findings over time.

Inspect SPF DKIM And DMARC

SPF identifies approved sending servers, DKIM adds a cryptographic signature and DMARC tells receiving systems what to do when authentication fails. A domain can have one record configured correctly while still exposing gaps elsewhere. For example, an invoice may pass SPF but fail DKIM because a third-party accounting platform was added without updating DNS.

Check the authentication results in the message headers, then inspect the domain’s public DNS records. DMARC set to p=none provides reporting but does not actively reject impostors. Stronger enforcement, introduced carefully after reviewing legitimate senders, can reduce spoofed invoice traffic.

Confirm Payment Changes Separately

A request to update bank details should be treated as a high-risk event, even when the message arrives inside an existing thread. Use a known telephone number, a supplier portal or a previously verified contact. Never rely solely on the email’s reply function, since an attacker may control the mailbox or redirect replies.

This matters under Australian payment habits, where electronic funds transfers and scheduled supplier payments are routine. Match the ABN, legal entity, purchase order and GST details against your records, but remember that copied business information does not establish that the sender is authentic.

Investigate Account Or Domain Compromise

A low domain score may reflect a compromised mailbox rather than a fake domain. Review recent sign-in locations, forwarding rules, OAuth applications, password resets and unusual sending volumes. Security teams should check whether other suppliers or customers received similar messages from the same account.

Examine URLs with a safe analysis process and avoid opening unexpected attachments on a production device. Invoice-themed malware often uses HTML files, password-protected archives or links to counterfeit Microsoft 365 login pages. The Australian Cyber Security Centre and Scamwatch guidance can support internal escalation and reporting decisions.

Contain The Financial Risk

Suspend payment for the affected invoice until the supplier confirms the request through a trusted route. If funds have already moved, contact the bank immediately and ask about recall or fraud intervention options. Preserve the original email, headers, attachment hash, payment details and timeline for investigators.

For larger organisations in Canberra, Sydney or Melbourne, route the case through finance, procurement and security rather than leaving it with a single accounts officer. Small businesses should still use a two-person approval process for new payee details and unexpected changes to recurring invoices.

Turn Findings Into Ongoing Controls

Create an approved-domain register for suppliers, SaaS platforms and outsourced billing providers. Monitor new domains, certificate changes, authentication failures and reputation shifts before they reach accounts payable. Bulk checks can help organisations review many vendor domains after a merger, software migration or procurement refresh.

For teams onboarding many customers or registrations, an API automation guide can help connect reputation checks to existing workflows. Combine automated alerts with human verification, because a high score cannot validate a changed bank account and a low score cannot alone prove criminal activity.