A small business may not have three finance staff. It can still avoid one-person control. For example, the bookkeeper records the request, the owner performs the trusted callback and the authorised banking user approves the beneficiary and payment. If one person must perform more than one step, require a documented owner review before release instead of quietly dropping the control.
Do not create an “urgent” bypass for executives. Urgency is the moment the control matters most. A real director or supplier can wait for the verification step, answer through a trusted channel or follow the exception process.
Red flags that should stop the payment
One weak signal does not prove fraud. One high-risk change is enough to pause and verify.
- new bank details, a new beneficiary or a request to split the payment;
- pressure to act immediately, keep the request secret or bypass a usual approver;
- a senior person making an unusual payment request while travelling or unavailable;
- a supplier contact changing at the same time as the bank details;
- a reply chain that suddenly changes sender domain, tone, payment timing or invoice attachment;
- an invoice layout, account holder, bank or payment reference that differs from the supplier record;
- a message that discourages a phone call or provides a new number for “verification”;
- deleted or missing mail, unexplained password resets, unknown forwarding, unfamiliar inbox rules or sign-ins your user cannot explain.
Do not reject a message only because of grammar, and do not accept it because the grammar is good. The deciding control is verification through a channel and contact record the suspicious message did not supply.
Technology reduces risk; it does not approve a payment
Multifactor authentication
Require MFA for email, especially for administrators, executives and anyone who handles invoices, supplier records or payments. Use the strongest option your platform supports and keep recovery methods controlled.
MFA is not a fraud guarantee. A stolen session, compromised recovery method, unsafe legacy access, malicious consent or a compromised supplier account can leave you facing a convincing message. Continue to verify banking changes even when both organisations use MFA.
Passwords, sessions and account recovery
Use unique credentials, a password manager where appropriate and separate administrator accounts from daily mail. Do not share one mailbox password across a team. Restrict who can reset finance and executive accounts, and make sure the recovery contacts are current.
When compromise is suspected, a password change alone may leave active sessions, added authentication methods, app access or forwarding in place. The authorised administrator or IT provider should follow the mail platform's current containment procedure from a trusted device.
Inbox rules, forwarding, delegates and access logs
Review visible and hidden inbox rules, external forwarding, delegates, connected applications, recovery methods and recent sign-ins. Look for unexplained changes around the first suspicious message, not only the moment the payment request was sent. Preserve the relevant records before normal retention or cleanup removes them.
SPF, DKIM and DMARC
SPF identifies authorised sending sources for a mail domain. DKIM adds a cryptographic signature that lets a receiving system check the signed message. DMARC checks alignment with the visible From domain, tells receivers how to handle failures and provides reporting.
Correctly configured records make direct spoofing of your own domain harder and improve visibility. They do not stop someone from using a compromised real mailbox or a separately registered lookalike domain. If you need the DNS layer in more detail, use the Allanux guide to how DNS SPF records work, then have the full SPF, DKIM and DMARC configuration reviewed for every legitimate sender.
Least privilege around supplier and payment data
Limit who can create suppliers, edit beneficiaries, approve payments and export supplier or customer data. Remove access when roles change. Keep payment and email administration rights out of normal user accounts where the platform allows it. A mailbox control cannot compensate for unrestricted access to the supplier master or banking platform.
When you are setting up email hosting on your own domain, decide these owners before adding every mailbox: who manages DNS, who administers accounts, who can reset access, who reviews logs and who receives an internal fraud escalation.
Use a role map before pressure arrives
| Role |
Before an incident |
When a suspicious request appears |
| Request recipient |
Know the red flags and trusted reporting route |
Pause, preserve the message and alert the finance owner without replying |
| Supplier-record owner |
Maintain trusted contact details and a change log |
Freeze the proposed change until independent verification is complete |
| Independent verifier |
Know who is authorised at key suppliers |
Call a known number, confirm exact details and record the result |
| Payment approver |
Enforce approval limits and exception rules |
Refuse release until the verification evidence is attached and complete |
| Email/IT administrator |
Maintain MFA, logging, account recovery and least privilege |
Contain affected accounts and sessions, preserve logs and review rules, delegates and app access |
| Information Officer or deputy |
Maintain the organisation's POPIA incident path |
Assess whether personal information was affected and apply current Regulator guidance |
| Business incident owner |
Keep bank, insurer, legal and law-enforcement escalation details from official sources |
Coordinate facts, decisions, counterparties and updates without promising recovery |
If the request is suspicious but money has not moved
- Stop the beneficiary change and payment. Do not reply, forward the suspect message casually or call a number inside it.
- Contact the supposed sender through a trusted channel. Use the supplier master, contract or independently verified official number.
- Alert the finance and incident owners. They need to protect other pending payments and related supplier records.
- Preserve the original message. Keep the full message and headers where available, the attachment, timestamps and the actions already taken.
- Escalate possible mailbox compromise. The authorised email administrator or IT provider should contain and investigate the affected environment.
- Check for related requests. Review other unpaid invoices, beneficiary changes and messages involving the same parties without deleting evidence.
If the message proves genuine, complete the normal verification and approval record. A false alarm is cheaper than a payment released because someone was worried about inconveniencing a supplier or director.
If money has moved: run the first-hour actions in parallel
Do not spend the first hour debating who clicked what. Start the bank, account and evidence work immediately. Fast reporting may help, but no one should promise that a payment will be stopped, recalled or recovered.