A display name does not prove identity
A message can show a colleague’s name without coming from them. Check the full email address and sender domain. A changed letter or an extra domain component can indicate impersonation.
SPF, DKIM and DMARC work together
SPF identifies servers authorised to send for a domain. DKIM adds a verifiable signature to messages. DMARC checks alignment with the visible sender domain and communicates a policy for messages that fail verification. Configuration must account for all legitimate sending services.
Introduce policy gradually
Inventory email sources, check results and review reports before adopting a strict policy. An untested rule can affect legitimate messages. Domain authentication does not stop every attack using lookalike domains.
Verify sensitive requests separately
For a bank account change or an urgent payment, contact the person using a previously known number. Do not automatically rely on a number supplied in the suspicious message.