A customer calls to ask why your bank details have changed. They received an invoice from your company. Your name in the sender line, your logo, your usual wording, a Hong Kong bank account at the bottom. They paid it. Nobody broke into your mailbox. Nobody guessed a password. Somebody simply wrote your company's email address in the "From" field of a message, and no computer along the way stopped them.
That is email spoofing, and for most Hong Kong businesses it takes a scammer about ten minutes and costs them nothing.
Your email address is a return address, and by default nobody checks it
Posting an email is like posting a letter. You can write any return address you like on the envelope. The postal system does not ring the sender to confirm it, and neither does email. The system was built in the 1970s on the assumption that everyone sending mail was trustworthy, and that assumption was never removed.
What was added, decades later, was a way for you to tell the world's mail servers which senders are genuinely yours. You do that with three small settings attached to your domain name. These live in your DNS records, which are the public settings that sit behind your website address, a bit like the entry for your company in a public registry. Anyone can look yours up in a few seconds. Scammers do exactly that, which is how they choose who to impersonate. A business with no protection is simply easier work than one with it.
If you have never been asked to add these records, you almost certainly do not have them. They are not switched on by default by your registrar, your web designer or your email provider.
What the scam actually looks like here
Take a small logistics firm in Kwun Tong. Its website lists the accounts manager by name, shows the email format is firstname@company.com.hk, and mentions the main shipping clients. That is enough.
The scammer registers nothing and hacks nothing. They send a message that appears to come from accounts@company.com.hk to those clients, attaching a PDF invoice built from a real one lifted off the website or an earlier email. The wording is polite and ordinary. Only the bank account is new, usually with a short line explaining that the company has changed banks. Payment goes to a mule account and is moved within hours.
You find out days later, from an angry customer. Your mail server logs show nothing, because the message never touched your system. This is the frustrating part for owners: there is nothing to "clean up" afterwards, and changing everyone's passwords does not help.
Hong Kong is seeing a lot of this. HKCERT handled 12,536 security incidents in 2024, the highest figure in five years, and phishing accounted for roughly 62% of them, more than double the year before. 釣魚電郵 has become the default way in, partly because it got cheap. IBM's research found that AI tools can draft a convincing phishing email in about five minutes, work that previously took a skilled person around sixteen hours. Volume that once had to be targeted can now be sprayed at every supplier and customer in your industry.
And 電郵詐騙 is rarely where it ends. Verizon's 2024 Data Breach Investigations Report found that 88% of breaches at small businesses involved ransomware or extortion, and a convincing email is usually the first step.
SPF, DKIM and DMARC, explained as a mailroom
These three sound technical. They are just three checks a receiving mail server performs, and the postal analogy holds well.
SPF is your list of approved post offices. It is a public note saying "only mail sent from these servers is really from us". If a message claims to be from your company but was posted somewhere not on the list, that is a red flag.
DKIM is a wax seal on the envelope. Your mail server stamps each message with a seal that only you can produce. If the seal is missing or the letter has been tampered with in transit, the receiving side can tell.
DMARC is the standing instruction to the receiving mailroom. It answers the question the first two checks leave open: what should we do when a letter fails? Deliver it anyway, put it in the junk pile, or refuse it at the door. DMARC also sends you a regular report listing everyone who is sending mail using your name, which is often the first time an owner sees the scale of it.
Without DMARC, the first two checks are advisory. A message can fail them and still land in your customer's inbox looking perfectly normal.
What we found across 214 Hong Kong business websites
Our own scan of 214 Hong Kong business websites found the gap is the norm, not the exception:
- 62% have no DMARC record at all, meaning anyone can send email pretending to be them and receiving servers have no instruction to stop it
- 35% have no SPF record
- 68% have no DKIM
- 72% have at least one finding we rate high or critical
- The average exposure score was 41 out of 100, where 0 means nothing is exposed
The pattern worth noticing is the gap between SPF and DMARC. Plenty of these businesses have an SPF record, usually added automatically when they set up Google Workspace or Microsoft 365 years ago. Far fewer ever added the instruction that makes it count. It is the equivalent of having a guest list at the door and no one checking it.
Fixing it, honestly
This is not a purchase. The records are free. It is an hour of a competent person's time, then a few weeks of light monitoring. Here is what you can do today:
- Find out who controls your DNS. It is usually your domain registrar or whoever built your website. If you do not know, that is question one.
- Write down every service that sends email as your company: your mail provider, your accounting or invoicing system, your booking platform, your newsletter tool, your online shop. Each one needs to be included, or its mail will start failing.
- Ask your web or IT person for one thing: "please add SPF, DKIM and DMARC for our domain, starting DMARC at p=none."
- Insist on that starting point. p=none means monitor only, nothing gets blocked. Run it for two to four weeks, read the reports, confirm every legitimate sender passes, then move to quarantine and finally to reject. Jumping straight to reject is how companies accidentally stop their own invoices arriving.
- Tell your finance staff and your regular customers, in writing, that your bank details will never change by email alone. This costs nothing and blocks the scam even when the email gets through.
Two honest limits. DMARC stops people using your exact domain. It does not stop someone registering a lookalike domain, so the discipline of confirming payment changes by phone still matters. And none of this protects a mailbox whose password has been stolen. It solves one specific problem completely, which is more than most controls manage.
Where does your domain stand today
You can check part of this yourself in a minute by asking your IT person to look up your DMARC record, or you can have the whole picture handed to you. We run a passive scan of Hong Kong business websites, which means we only read what is already public, exactly as a scammer would, and we will send you the report for your own domain at no cost.