17 Sep 20265 minutes read
Waseem OsmanDMARC PractitionerBreach Prevention: Domain Impersonation vs. Internal Account Compromise

Breach prevention overview:
- External domain impersonation exploits three gaps: unenforced DMARC, unmonitored lookalikes, and compromised third-party senders.
- p=reject is the single most effective control, but requires a clean sender inventory first.
- Internal account compromise bypasses SPF, DKIM, and DMARC by using a legitimate account.
- Detection needs behavioral monitoring, not authentication checks.
Most email breaches don't require a zero-day exploit. The openings are simpler than that. Two patterns show up often enough in enterprise environments to be worth a closer look: external domain impersonation and internal account compromise. For each, the mechanics are distinct, the organizational impact is serious, and the control stack is specific.
Before addressing either pattern, confirm what your current authentication setup actually allows. Run your domain through Sendmarc's free DMARC record checker to see what's currently published.
Pattern One: External Domain Impersonation
How It Works
An attacker sends email that appears to originate from your domain, or a convincing lookalike, without ever touching your infrastructure.
At enterprise scale, impersonation takes three common forms.
The first is direct domain spoofing. The attacker uses your exact domain in the "From" header. Without full DMARC enforcement (p=reject), receiving servers accept and deliver the message. Recipients see your domain name, the email looks legitimate, and there's no visual indicator to trigger suspicion.
The second is lookalike domain abuse. The attacker registers a domain that resembles yours, substituting characters, adding words, or using a different top-level domain, and sends from that. DMARC doesn't protect against this. Detection requires active monitoring of newly registered domains that match your brand.
The third is third-party sending infrastructure compromise. If a marketing platform, HR system, or transactional email provider that sends on your behalf is breached, attackers inherit that sender's authorization. SPF records that include that provider's IP ranges will pass, and DKIM signatures from that provider will validate, so the email looks fully authenticated.
Impact
Business email compromise (BEC) targeting your customers or partners uses your trusted domain to authorize fraudulent payments or harvest credentials. Your brand absorbs the reputational damage even if your systems were never touched.
In regulated industries, healthcare, insurance, and financial services, that damage extends to regulatory exposure, because customer data or client relationships were affected by email that impersonated your identity.
External Impersonation Controls
The control stack for external domain impersonation is layered.
- DMARC at enforcement: Move from p=none to p=quarantine, then p=reject. This is the single most effective action available. It instructs receiving servers to act on authentication failures rather than observe them.
- SPF hygiene: Audit your SPF record for sender sprawl. Every marketing tool, HR platform, CRM, and transactional email provider added over time represents a potential attack surface if that sender is compromised.
- DKIM coverage: Verify that every authorized sender is signing with DKIM and that the key rotation schedule is current. Stale keys held by former vendors remain valid until explicitly revoked.
- Lookalike domain monitoring: DMARC enforcement on your primary domain doesn't protect against lookalike domains. Active scanning for newly registered domains that resemble your brand is a separate, necessary control.
The sequencing matters. DMARC enforcement without a clean, current sender inventory creates delivery risk. Audit first, enforce second.
Pattern Two: Internal Account Compromise
How It Works
Internal account compromise is structurally different from impersonation. The attacker doesn't need to mimic your domain because they have access to a legitimate account. Email sent from a compromised internal mailbox passes every authentication check (SPF, DKIM, and DMARC) because it originates from authorized infrastructure.
The entry points for internal account compromise are well documented: credential stuffing against accounts without multi-factor authentication (MFA), phishing that harvests session tokens, legacy protocol exploitation, and OAuth application abuse where a malicious app is granted persistent email access.
Once inside a mailbox, attackers operate laterally. They read historical threads to understand context, identify payment workflows, and map relationships before initiating fraud.
Detection requires behavioral signals (unusual send volume, access from atypical locations, email rules that forward to external addresses) rather than authentication failures, because authentication is passing.
Impact
Internal account compromise carries a different risk than external impersonation. Because the email originates from a legitimate account, it bypasses security controls that look for external spoofing signals. Recipients trust the sender, finance teams approve wire transfers, and customers share sensitive information. The social engineering is effective precisely because it's technically indistinguishable from legitimate email.
For regulated industries, this pattern also creates audit and notification obligations.
A compromised employee mailbox that contains patient health information, client financial data, or personally identifiable information (PII) can trigger breach notification obligations. The incident response cost (forensic investigation, legal review, customer notification, and regulatory response) is substantial and separate from any direct fraud losses.
Internal Compromise Controls
- Legacy protocol blocking: Disable legacy protocols for accounts that don't require them. Where these protocols must remain active, restrict access by IP range.
- Conditional access and MFA enforcement: Enforce MFA on all accounts, including service accounts. Apply conditional access policies that block access from unrecognized devices or locations.
- Behavioral monitoring: Authentication passing doesn't indicate legitimate use. Monitor for anomalous send patterns, unexpected email forwarding rules, and access from unusual locations or at unusual times.
How Sendmarc Can Help
Domain impersonation and internal account compromise both stem from the same root problem: stretched security teams that lack full visibility into who's sending on their behalf and whether internal accounts are behaving as expected. Sendmarc provides the visibility and enforcement infrastructure both patterns need for effective breach prevention, without adding to your team's workload.
For external impersonation, the Sendmarc Platform gives companies a current, accurate picture of every sender authorized to send on behalf of their domains, including third-party tools and vendors, and supports a structured path to DMARC enforcement.
Lookalike Domain Defense surfaces newly registered domains that match your brand before attackers weaponize them, addressing the risk that DMARC enforcement doesn't cover.
For internal account compromise, Breach Detection monitors for exposed employee credentials so security teams can respond before those credentials are used to access real accounts.
Together, these capabilities address both entry points: attackers impersonating your domain from outside, and attackers operating from inside a compromised account.
Explore Lookalike Domain Defense to see how continuous monitoring for lookalike domains works alongside DMARC enforcement and Breach Detection.



Leave a reply Cancel reply
Your email address will not be published. Required fields are marked *