For finance teams and anyone about to pay an invoice
Before you pay, check the domain.
An invoice or a ‘new bank details’ email that looks slightly off is worth one minute of checking. Paste the domain, name the supplier it claims to be from, and see whether it is what it appears to be.
Payment-diversion fraud works by changing one detail on a real-looking invoice — usually the bank account — and relying on the pressure to pay on time. The message often comes from a domain that resembles your supplier's closely enough to pass a glance. This page explains how to check before you pay, and what to do when something is wrong.
How the fraud is set up
It usually begins quietly, with either a compromised mailbox somewhere in a real conversation or a lookalike domain registered to imitate one. The message that eventually asks for a payment is often correct in every other respect — right reference, right amount, right tone — because it is either a genuine thread or a careful copy of one. The bank details are the only thing that changed.
- A thread that already exists is more convincing than a cold approach
- The sending domain may differ from the real one by a detail that survives a quick glance
- Urgency is the tell most often present and most often ignored
What to check before paying
Checking the domain a message came from establishes whether it is what it appears to be. It cannot tell you whether a particular payment request is genuine — for that there is one reliable step, and it has not changed.
- Check the sending domain, not just the display name — the name is trivially forged
- Phone the supplier on a number you already hold, never one from the message
- Treat any change of bank details as unverified until confirmed by voice
- Be wary when a change arrives alongside pressure to pay quickly
If a payment has already gone
Speed matters more than certainty. Contact your bank immediately and ask them to attempt recall — funds are sometimes recoverable in the first hours and rarely after that. Then report it, and preserve the original email rather than deleting it.
- Call your bank first; recall attempts are time-critical
- Report to Action Fraud in the UK
- Keep the original message intact — it carries the evidence of where it came from
- Tell the real supplier, whose mailbox or brand may be the one being abused
Common questions
›The email came from our supplier's real address. Can it still be fraud?
Yes. If their mailbox has been compromised, the message really does come from them and every technical check will pass. That is exactly why verifying bank-detail changes by phone, on a number you already hold, is the control that matters.
›Does a clean domain result mean the invoice is safe to pay?
No. It means the domain looks like what it claims to be. It cannot know whether a specific request is legitimate. Where money is moving, verify directly with the supplier.
›What if the domain is a lookalike?
Do not reply, do not pay, and do not use any contact details from the message. Contact the real supplier through details you already hold and tell them their brand is being impersonated, because their other customers are likely receiving the same thing.
Advisory only. Checking a domain assesses external signals about that domain. It cannot determine whether a particular invoice or payment request is genuine, and it is not a substitute for verifying changes directly with the supplier.
Also useful: what to do when a domain is fake.