Catching Fraud That Uses Your Email Domain With New Aliases You Never Created

Fraudsters don’t need your password to impersonate you. If they can create new email aliases on your domain—or exploit a misconfigured “catch‑all” or forwarding rule—they can look legitimate enough to reset passwords, open accounts, and trick your contacts. This guide explains how to spot unauthorized aliases tied to your domain, how they appear, what risks they create, and the step‑by‑step actions to investigate and shut them down.

What “new aliases on your email domain” actually means

An email alias is an address that delivers to an existing mailbox without needing a separate login. For example, billing@yourdomain.com might deliver into you@yourdomain.com. Fraud risk increases when:

  • Someone with access to your email system can create new aliases without your knowledge.
  • A “catch‑all” setting accepts mail to any address at your domain—even ones you never created—and forwards them somewhere.
  • Forwarders or routing rules send copies to an external mailbox the attacker controls.
  • Your domain is hosted at a registrar or email provider account that was weakly protected and modified by an intruder.

Red flags that suggest new, unauthorized aliases exist

Watch for these signals, especially if they appear suddenly or in clusters:

  • Unexpected “welcome” or “verify your email” messages to addresses like accounts@, info@, refunds@, or variations of your name that you never created.
  • Bounce-back notices from non-existent recipients at your domain (e.g., sales-3@yourdomain.com) you didn’t email.
  • Password reset prompts for accounts you don’t recognize, sent to an unfamiliar alias at your domain.
  • Support replies from companies you never contacted referencing messages sent from a new alias on your domain.
  • Mailflow anomalies: you stop receiving messages you expect, or rules auto-move messages to unusual folders.
  • Contacts report odd messages apparently “from” your domain that you didn’t send.

Common ways criminals abuse new aliases

  • Account takeovers and new account creation: They use a freshly created alias to receive verification codes and reset links.
  • Vendor and client fraud: They impersonate your billing or support team to reroute invoices or refunds.
  • Credential phishing: They craft convincing threads from a domain address to get targets to click or share data.
  • Reputation damage: Spam from your domain can get you blocklisted, causing real email to be delayed or rejected.

Immediate steps if you suspect unauthorized aliases

Time matters. Lock down access first, then investigate.

  1. Secure the top-level accounts
    • Change passwords on your registrar, DNS host, and email provider admin accounts.
    • Enable strong MFA (authenticator app or hardware key) on all admin and user accounts.
    • Revoke any suspicious sessions or app passwords.
  2. Audit mailboxes, aliases, and forwarding
    • List all mailboxes and aliases for your domain. Remove anything you don’t recognize.
    • Disable or tightly scope catch‑all delivery; ideally set it to bounce unknown addresses.
    • Review forwarding at the domain level and within each mailbox; remove unknown external forwards.
    • Check mailbox rules for auto-forward, delete, or move rules you didn’t set.
  3. Check DNS and domain ownership
    • Review name server changes, new subdomains, and MX records. Revert any unauthorized edits.
    • Turn on domain lock at the registrar. Confirm WHOIS contact details are yours.
  4. Harden sending authentication
    • Publish or review SPF, DKIM, and DMARC records to control who can send with your domain.
    • If you already have DMARC, consider moving from none to quarantine or reject after monitoring.
  5. Scan for account fallout
    • Search your mail for resets or verification emails you didn’t request.
    • Change passwords on any account that received unexpected reset prompts.

How to review aliases on popular providers

If you use a managed email provider, these are the core checks. The exact menu names can vary, but the concepts are consistent:

  • Google Workspace (Admin): Admin console → Directory → Users → open a user → Aliases. Also check Apps → Google Workspace → Gmail → Routing for forwarding and catch‑all; and Security → Access and data control → API controls for third‑party access.
  • Microsoft 365: Microsoft 365 admin center → Users → Active users → select user → Mail → Email aliases. Check Exchange admin center → Mail flow → Rules and Connectors; and Recipients → Mailboxes → select → Mailbox features → Forwarding.
  • cPanel/Shared hosting: Email Accounts → Forwarders; Default Address (catch‑all) → set to “Discard with error.” Remove unfamiliar forwarders or autoresponders.
  • Fastmail/Zoho/Other hosts: Look for Aliases, Routing, Rules, and External Forwarding. Disable global catch‑all unless you actively use it and can monitor it closely.

Understanding SPF, DKIM, and DMARC in plain language

These DNS records help mail servers decide whether messages “from” your domain are legitimate.

  • SPF lists the servers allowed to send mail for your domain. If a spammer sends from elsewhere, recipients can mark it as suspicious.
  • DKIM adds a cryptographic signature to messages your provider sends, proving they weren’t altered and came from an approved system.
  • DMARC tells recipients what to do when SPF/DKIM fail and where to send reports. Start with a monitoring policy (none), review reports, then move to quarantine or reject to block spoofed emails more aggressively.

These don’t stop a criminal who actually controls your inbox or alias list, but they reduce successful impersonation from outside systems and help you monitor abuse.

How to monitor for new aliases and misuse going forward

  • Log and review changes: Turn on admin audit logs for mailbox, alias, and routing changes. Review monthly or after any alert.
  • Create known-good documentation: Maintain a list of approved aliases, forwards, and routing rules. Compare during audits.
  • Set admin alerts: Where supported, enable alerts for new alias creation, forwarding additions, MFA disablement, or login from new locations.
  • Use DMARC reports: Point rua/rua tags to a monitored inbox. Review who is sending with your domain and investigate unknown sources.
  • Mailbox rule sweeps: Quarterly, check every mailbox for rules that forward externally or hide messages.
  • Disable catch‑all: If you must use it, direct it to a monitored, separate mailbox with strict filters and frequent reviews.

What to do if the attacker created accounts using your domain

Once you remove the aliases and secure your domain, check for wider identity or financial misuse.

  • Search your email for “welcome,” “verify,” “thank you for creating an account,” and “password reset” messages to unknown services.
  • Reset or close suspicious accounts: Use the provider’s account recovery to lock or delete any account created with your domain.
  • Place security alerts: Add MFA and unique passwords on critical services: banking, payroll, cloud storage, and social platforms.
  • Watch financial identity signals: If criminals used your domain to open financial accounts, you may see new inquiries or accounts on your credit reports. Consider ongoing monitoring to catch these early.

For ongoing visibility into credit report changes, identity‑related alerts, and new account inquiries tied to potential misuse, see our overview of privacy, credit monitoring, and identity‑protection tools.

Locking down admin access and shared credentials

Most unauthorized alias creation happens because an admin account or shared login is compromised. Reduce that risk:

  • Use least privilege: Only give admin rights to people who truly need them. Grant temporary elevation for one‑off tasks.
  • Strong MFA for all admins: Prefer hardware keys or authenticator apps; disable SMS‑only where possible.
  • Rotate passwords and app passwords after personnel changes. Remove stale accounts quickly.
  • Review third‑party app access: Revoke unnecessary OAuth grants that can create or route mail.
  • Secure the registrar: Admin email changes at the registrar can cascade into full domain control loss.

Technical checklist for DNS and mail authentication

Use this as a quick reference when hardening your domain:

  • Registrar: Domain lock on; MFA enabled; WHOIS contacts verified; recovery email/phone accurate.
  • DNS: Review recent changes; limit who can edit; enable change alerts.
  • MX: Confirm they point to your intended mail host only.
  • SPF: Include only services you actively use (e.g., your mail host, transactional sender). Remove unused vendors.
  • DKIM: Enabled for each sending service; rotate keys when staff or vendors change.
  • DMARC: Start p=none with reporting; after 2–4 weeks of review, move to p=quarantine or p=reject in stages.
  • Catches and forwards: Catch‑all disabled; external forwards allowed only if necessary and logged.

How this connects to your broader privacy and security

Unauthorized aliases blur the line between technical email abuse and personal privacy risk. Once attackers receive messages meant for you, they can pivot into your wider digital life—resetting logins, scraping personal data, and probing financial accounts. Combining strong domain controls with personal security habits gives you the best protection:

  • Password discipline: Unique passwords in a reputable password manager reduce cross‑account fallout.
  • Multi‑factor authentication: Turn it on wherever available, especially for email, banking, and cloud services.
  • Breach awareness: If your email is in a known data breach, change the password and review forwarding/rules.
  • Credit and identity monitoring: New credit inquiries or accounts can indicate that someone leveraged your domain to impersonate you.

When to get help

Consider professional or legal help if you see any of the following:

  • Admin access loss at your registrar or email provider.
  • Persistent re‑creation of aliases after removal (indicates a still‑compromised admin or automation).
  • Vendor or client wire fraud attempts using your domain.
  • Evidence of financial account openings or tax‑related identity theft.

Quick response playbook

  1. Freeze control: Change admin passwords, enable MFA, lock the domain.
  2. Remove footholds: Delete unknown aliases, disable catch‑all, remove forwards and mailbox rules.
  3. Verify configuration: Inspect DNS/MX; lock down SPF/DKIM/DMARC.
  4. Hunt indicators: Search for verification and reset emails; secure affected accounts.
  5. Monitor: Set alerts, review DMARC reports, and watch credit/identity signals for fallout.

Conclusion

New, unauthorized aliases on your domain are more than a nuisance—they’re a doorway to impersonation, account resets, and financial fraud. You can cut off most attacks by disabling catch‑all delivery, removing unknown forwards and rules, enforcing MFA on admin accounts, and tightening SPF, DKIM, and DMARC. Keep a written inventory of approved aliases, enable change alerts, and review DMARC reports regularly. If you suspect the abuse has spilled into financial identity risks, use ongoing credit and identity monitoring to surface new inquiries or accounts early so you can respond quickly and limit the damage.

Good to Know

Many “mystery” sign‑ups tied to addresses like invoices@ or support@ on your domain are early warning signs of a catch‑all mailbox or forwarding rule you didn’t intend; locking down catch‑all and reviewing forwarding is one of the fastest wins.