Spoofed and Exposed: Email Security Overhaul for a Singapore FMCG Brand
A mid-sized FMCG brand headquartered in Jurong faced a surge in customer complaints from regional retail partners who had received suspicious emails appearing to originate from the company’s official domain. These messages, often containing urgent payment requests or updated delivery schedules, were not sent by the company. The brand’s name was being weaponised in targeted phishing campaigns, eroding trust with key distribution partners and triggering internal investigations into possible data breaches. With revenue tied to just-in-time supply agreements and tight compliance timelines across Southeast Asia, any delay or miscommunication risked contractual penalties and reputational damage. The urgency was amplified by the fact that the company had no visibility into how widespread the spoofing had become or how long it had been occurring.
When we began our assessment, the company had no email authentication protocols properly configured. Their DNS records lacked SPF entries, DKIM was not implemented, and DMARC was entirely absent. This meant that any external actor could send emails using the company’s domain without technical barriers. We conducted a passive email traffic analysis using tools from Agari and validated findings through Google Postmaster and Microsoft SNDS, which revealed that over 78% of emails appearing to come from their domain were illegitimate. The domain had already been flagged by multiple threat intelligence platforms as a source of phishing activity. Worse, internal staff were unaware of the risk because outbound email logs showed no anomalies — the attacks were entirely external, exploiting the lack of domain ownership verification on the internet’s email infrastructure.
We implemented a phased email authentication rollout beginning with a DMARC monitoring policy set to p=none, allowing us to collect forensic data on all email flows without disrupting legitimate communication. This was supported by a comprehensive SPF record that listed all authorised mail servers, including those used by their ERP system, marketing automation platform, and third-party logistics providers. We then enabled DKIM signing using keys hosted in AWS Key Management Service and integrated with their Microsoft 365 tenant, ensuring every outbound message could be cryptographically verified. After four weeks of traffic analysis, we transitioned the DMARC policy to quarantine, instructing recipient mail systems like Gmail and Outlook to redirect unauthenticated messages to spam. We used Proofpoint’s DMARC analytics dashboard to monitor aggregate and forensic reports, identifying and onboarding previously unknown third-party vendors still sending on behalf of the domain. The final enforcement phase moved to reject, blocking all unauthorised use of the domain at the SMTP level.
Within three months of full DMARC enforcement, unauthorised use of the domain dropped to 0.6%. Google Postmaster scores improved from “bad” to “high,” and the domain was removed from the Spamhaus Blocklist. Retail partners reported an immediate decline in fraudulent communications, and the company’s security team regained control over domain reputation. Monthly phishing complaints fell from an average of 14 to fewer than two, and internal audit teams confirmed full compliance with MAS TRM guidelines on third-party risk and PDPC advisory guidelines on domain protection. The company now runs quarterly DMARC health checks and has integrated domain monitoring into its broader cybersecurity awareness program, ensuring long-term resilience.
For Singapore SMEs in FMCG and distribution-heavy sectors, domain spoofing is not a hypothetical threat — it is an operational risk tied directly to supply chain integrity. The absence of email authentication is not merely a technical gap; it is a liability that can be exploited to manipulate partners, reroute payments, and damage hard-earned trust. Implementing DMARC is not a complex project requiring major infrastructure, but it does require disciplined DNS governance and visibility across all email-sending services, including those operated by external vendors. Many companies assume that securing their email servers is enough, but without domain-level authentication, the brand remains exposed to impersonation that bypasses traditional perimeter defences.
If your brand’s name is being used in transactions beyond your control, it may already be vulnerable to silent exploitation — explore how we help Singapore businesses reclaim their digital identity.