top of page

The 40-Year-Old Loophole Hiding in Your Inbox


1980s Computer Frustration
1980s Computer Frustration

The tech your email runs on was built in the 1980s. It has never once checked who's really sending. Here's why that should worry you.


Here's something most business owners don't know: the technology your email runs on was designed in the 1980s — and it never checks who's really sending.


Anyone. That's right, anyone can put your email address in the "from" line of a message. That's domain spoofing — a criminal sending email that appears to come from your company, to your clients, your vendors, even your own staff.


Why does it matter? Because this is how a huge share of real attacks begin. The fake invoice. The urgent "wire the funds today" request from the boss. These don't require sophisticated hacking — they just require your customers to trust a name they recognize. Yours.


So why is this even possible? Because email was built in an era when everyone on the network was a trusted university or research lab. Nobody imagined they'd need to verify the sender — so the system never did. Forty years later, we run our entire business lives on it, and that original blind spot is still wide open unless you close it.


The good news: there's a way to lock this down. With the right setup, your domain publishes proof that any email claiming to be from you is genuinely authorized by you. Impersonators fail that check and get quarantined before they ever reach an inbox.


It's one of the cheapest, highest-leverage protections a small business can put in place. And in my experience, almost none of them have it done correctly — many don't have it at all.


If you're not sure where your business stands, that uncertainty is the finding. Worth a look.


 
 
 

Comments


bottom of page