⚡ Found something damaging online? Get a FREE Confidential Exposure Scan → · Urgent? Response within 1 hour →

HomeGuidesWhat to Do About Email Spoofing of a Company Executive

Crisis Response

What to Do About Email Spoofing of a Company Executive: A Strategic Checklist

Frankie Lee By Frankie Lee, Founder · July 2, 2026

What to Do About Email Spoofing of a Company Executive: A Strategic Checklist

The first sign is usually a confused reply. A vendor asks your CFO about “the updated wire instructions.” An employee thanks the CEO for the gift-card request they’re about to fulfill. A board member forwards a message that looks exactly like it came from your president — same name, plausible address, right tone — asking for something slightly off. Email spoofing of a company executive rarely announces itself; it surfaces through the near-misses, and by the time you see one, there are usually others you haven’t seen.

This attack works because it exploits two things at once: technical gaps in how email verifies senders, and the human reality that people act quickly on messages from the boss. That means the response has to be layered too. Locking down your email authentication stops one class of spoofing cold, but it does nothing about the lookalike domain registered last Tuesday, and neither fixes the fact that the attacker scripted a convincing message using the org chart, travel schedule, and speaking style your executive has scattered across the public internet. We work the takedown and footprint layers of this problem professionally, and this guide is the full checklist: the technical controls in plain language, the reporting and takedown machinery for spoofed and lookalike domains, and the piece almost everyone skips — shrinking the public footprint that makes executive spearphishing possible in the first place.

One framing note before the checklist. We are a content removal firm — the domain-takedown and footprint work below is our lane; the email-infrastructure configuration belongs to your IT team or provider, and anything involving actual financial loss or legal exposure belongs with law enforcement and counsel. Good executive-impersonation response is a relay, and knowing which leg is whose is half the job.

First, know which kind of spoofing you’re facing

“Spoofing” covers three different attacks, and they’re stopped by different controls — misdiagnosis here wastes weeks.

Exact-domain spoofing. The attacker forges mail so it appears to come from your executive’s real address at your real domain. This is a pure technical exploit of email’s trusting design, and it’s the one the authentication trio below can genuinely shut down.

Lookalike domains. The attacker registers a domain nearly identical to yours — a swapped letter, an extra hyphen, a different ending — and sends from it, often with the executive’s real display name. Your email authentication can’t stop this, because the attacker’s mail is “legitimately” sent from a domain they actually own. This one is fought with takedowns.

Display-name impersonation. The message comes from a random free-mail address, but the sender name reads “Patricia Chen, CEO.” Technically trivial, surprisingly effective on phones, where most clients show only the display name. Fought with reporting, filtering, and user awareness.

Real email spoofing campaigns mix all three, and a serious response runs all three tracks at once. Check message headers — or have IT do it — on every sample you’ve collected, and sort them. And do collect them: forward nothing, delete nothing, and gather every spoofed sample with full headers intact, because headers are the evidence that reporting channels, registrars, and investigators will ask for first.

The technical layer: SPF, DKIM, and DMARC in plain language

These three acronyms are where every article on this topic gets impenetrable, so here is what they actually are, without the protocol details your IT team will handle anyway.

SPF is a guest list. Your domain publishes a public record saying “mail from us legitimately comes only from these servers.” A receiving mail system checks the sender against the list. Simple — but SPF alone breaks on forwarded mail and doesn’t stop an attacker from putting your executive’s name on a message that technically passes for some other domain.

DKIM is a wax seal. Your outgoing mail carries a cryptographic signature only your servers can produce. If the message is tampered with in transit or forged from elsewhere, the seal doesn’t verify. Also simple — and also insufficient alone, because a missing seal doesn’t tell the receiver what to do about it.

DMARC is the instruction card that makes the other two matter. It’s a published policy that says: “if a message claiming to be from our domain fails those checks, here’s what to do — deliver it anyway but tell me (p=none), quarantine it to spam (p=quarantine), or reject it outright (p=reject).” Crucially, DMARC also sends you reports on who is sending mail claiming to be you — which is how you discover both your forgotten legitimate senders (the newsletter tool, the CRM) and the spoofing campaigns you didn’t know about.

The plain-language checklist for this layer:

  1. Verify all three exist for every domain you own — including the ones that send no mail at all, which need records saying so, because parked domains are attackers’ favorites.
  2. Ask one question of IT: “What is our DMARC policy?” If the answer is p=none — monitoring only — your domain is documenting its own spoofing without preventing any of it. A large share of organizations that believe they’re protected sit at p=none indefinitely.
  3. Move to enforcement deliberately. The standard path is monitor, fix the legitimate senders that fail, then step to quarantine and finally reject. Done carefully this takes weeks, not days, and it’s the single highest-value technical project on this list: at p=reject, exact-domain spoofing of your executives essentially stops working against any receiver that honors the policy.
  4. Don’t stop here. The morning after you reach p=reject, the lookalike domain still works fine. Which is why the next layer exists.

The takedown layer: reporting spoofed senders and killing lookalike domains

This is where infrastructure ends and removal work begins — the layer where you go after the attacker’s assets rather than hardening your own.

Report the spoofed mail itself. Free-mail accounts used for display-name impersonation should be reported to the providers, with headers; providers close accounts used for fraud, and while attackers open new ones, each closure destroys the reply-thread continuity that ongoing invoice-fraud conversations depend on. Report campaigns to the relevant national fraud and cybercrime reporting channels as well — in the US that includes the FBI’s IC3, particularly for attempted or actual wire fraud — both because it can matter and because the report number becomes part of the evidence file that strengthens every subsequent takedown request.

Kill lookalike domains through their infrastructure. A fraudulent lookalike domain has the same dependencies every website has — a registrar, often a host, sometimes a mailbox provider — and each dependency is a takedown channel. Registrars’ abuse teams act on domains used for phishing and fraud, especially with evidence: your headers, the near-identical domain string, screenshots of any credential-harvesting page behind it. Hosts take down phishing content. Anti-phishing blocklist operators — the shared databases that browsers and mail filters consult — can flag a domain within hours, which functionally neutralizes it even before the registrar acts. Trademark-based processes offer a slower, more formal route to actually seize a lookalike domain when it uses your protected name. This escalation-through-infrastructure discipline is exactly the machinery of professional cyber abuse removal, and it parallels the ladder we use in legal content removal matters: when one party won’t act, another one will.

Hunt proactively, not reactively. The lookalike domain you’ve seen is rarely the only one registered. Monitoring services watch new domain registrations for strings resembling your domains and executive names, turning next month’s spoofing campaign into this week’s takedown request — before the first fraudulent email goes out. We fold this into reputation monitoring for executive clients because the registration itself is the earliest observable signal an impersonation campaign exists.

Warn the humans in parallel. While takedowns run, finance and executive-assistant teams get a short, specific alert — the spoofed addresses seen so far, the request patterns used, and the standing rule that no payment or credential request from an executive is actioned on email alone. Verification-by-second-channel is boring and defeats the majority of these attacks by itself.

The footprint layer: starving the spearphish

Here is the layer almost every technical checklist omits, and the reason spoofed executive email is so convincing in the first place: the attacker did research, and your executive’s public footprint was the research library.

A spearphisher scripting a convincing message wants the org chart (who reports to whom, who moves money), the context (the exec is traveling, the acquisition just closed, the conference is this week), the voice (how the exec actually writes), and the trust map (which vendors, banks, and partners the company uses). All of it is routinely available: leadership pages listing full teams, conference bios, podcast interviews, social posts announcing travel in real time, data-broker profiles exposing personal email addresses and phone numbers, old breached credentials, and PDFs on your own site whose metadata names the exec’s account format. The message that fooled your vendor wasn’t lucky — it was assembled.

You cannot zero this footprint for a public-facing executive, and you shouldn’t try. You can shrink the operationally dangerous parts of it dramatically:

  • Audit what an attacker sees. Run the same open-source reconnaissance an attacker would on each protected executive — search results, social profiles, data-broker listings, breach exposure, document metadata. This is precisely what our free exposure scan produces, and for executives the findings are consistently worse than expected.
  • Remove the removable. Data-broker profiles exposing personal contact details, home addresses, and family information come down through opt-out and removal processes — tedious at scale, recurring by nature, and the highest-value removal work in this scenario because personal contact channels are where attackers go when corporate email hardens. Exposed personal information in search results can qualify for search-engine removal under personal-information policies.
  • Thin the voluntary leaks. Travel posted after the trip, not during. Team-structure detail trimmed from public bios. Real-time schedule information kept out of public calendars and conference apps where possible.
  • Keep it maintained. Footprints regrow — brokers repopulate, new profiles appear, each speaking gig adds a bio. Executive-protection protection plans exist because this is a subscription problem, not a project. Our executive services treat impersonation-driven footprint reduction as standing work for exactly this reason.

The honest framing for this layer: footprint reduction is probabilistic, not absolute. It doesn’t make spearphishing impossible; it makes your executives more expensive to research than the next target, and it removes the personal channels attackers pivot to. In a discipline with no guarantees anywhere — every takedown is ultimately a registrar’s, provider’s, or platform’s decision, not ours — raising the attacker’s costs across every layer is what winning actually looks like.

The one-page sequence

Pulling the checklist together in operating order:

  1. Contain and collect — preserve every sample with headers; alert finance and assistants; verification-by-second-channel becomes policy today.
  2. Classify — exact-domain, lookalike, display-name, or (usually) a mix.
  3. Harden — SPF and DKIM verified on all domains including parked ones; DMARC driven to enforcement on a deliberate timeline.
  4. Report and take down — provider reports, fraud-channel reports, registrar and host abuse filings, blocklist submissions, trademark process where warranted.
  5. Hunt — stand up lookalike-domain and impersonation monitoring for company and executive names.
  6. Starve — audit each executive’s public footprint, remove the removable, thin the voluntary leaks, maintain on a schedule.
  7. Escalate where it’s earned — actual losses, extortion, or persistent targeted campaigns bring law enforcement and counsel into the relay.

Frequently asked questions

We have SPF, DKIM, and DMARC set up. Why is our CEO still being spoofed?

Almost always one of three reasons. Your DMARC policy is p=none, which observes spoofing without blocking it — check this first, it’s the most common gap. The attack uses a lookalike domain or display-name impersonation, which your authentication cannot touch because the mail doesn’t claim to be from your domain at all. Or a subdomain or parked domain you forgot about lacks records. The fix is matching the control to the attack type — and accepting that the takedown and footprint layers aren’t optional extras.

How fast can a lookalike domain be taken down?

Honestly variable, because every channel is a third party’s decision. Blocklist flagging — which neutralizes most of a domain’s usefulness — can happen within hours to days with good evidence. Registrar suspensions for clear phishing commonly run days to a couple of weeks, faster with responsive registrars and complete documentation. Formal trademark-based seizure runs months. This spread is why the playbook files blocklist, host, and registrar channels simultaneously rather than waiting on any one of them, and why proactive registration monitoring beats every reactive timeline.

Should we tell customers and partners the executive is being spoofed?

Usually yes, and sooner than feels comfortable — quietly and specifically. A short notice to the vendors, partners, and finance contacts most likely to be targeted (“fraudulent emails impersonating our executives are circulating; we will never change payment instructions by email; verify by phone against known numbers”) costs little and defeats the attack at its destination. Save the broad public statement for campaigns that reach customers at scale; targeted notification to money-movers is the high-value version.

Is executive email spoofing a crime, and should we involve law enforcement?

Impersonation-based fraud generally is, and yes — report it, especially when money moved or was attempted. In the US, the FBI’s IC3 is the standard channel for business email compromise, and speed matters enormously when funds are in flight, because rapid reporting is what makes wire recalls occasionally possible. We’re not a law firm and this isn’t legal advice, but the operational point stands regardless: the law-enforcement report, the technical hardening, the takedowns, and the footprint work are parallel tracks, and none of them should wait on the others.


If your executives are being spoofed — or you’d rather find out before an attacker does the research — start with a free exposure scan. We’ll map each executive’s public footprint the way a spearphisher would, flag the data-broker listings and exposed details feeding impersonation, and lay out an honest, prioritized takedown and reduction plan.

Dealing with this right now?

Get an honest, confidential read on your situation — free.

How we can help →

Start with a free, confidential Exposure Scan

We'll scan your digital footprint, show you exactly what's exposed, and recommend the fastest path to remove it — or tell you honestly if you don't need us.

Book Your Assessment
Free · Confidential · 30 minutes
🔍 Get My Free Exposure Scan