Over 90% of cyberattacks start with an email. For Perth businesses, phishing is no longer a problem of obvious scam messages from foreign princes - today's attacks are convincing, targeted, and increasingly hard to spot. Here's how to fight back.
What Modern Phishing Looks Like
The phishing emails hitting Perth businesses in 2026 look nothing like the obvious scams of a decade ago. Attackers now send emails that:
- Appear to come from a real supplier, your bank, or the ATO - using spoofed or lookalike domains
- Reference your actual business name, staff names, or recent invoices (gathered from LinkedIn and public sources)
- Impersonate your CEO or director, asking staff to urgently transfer funds or share credentials
- Contain links to convincing Microsoft 365 or Google login pages that steal your password
Business Email Compromise (BEC) - where attackers impersonate executives to authorise fraudulent payments - cost Australian businesses over $80 million in a single year. Perth businesses are not immune.
Layer 1: DNS Authentication Records (SPF, DKIM, DMARC)
These three DNS records are the foundation of email security and prevent attackers from sending emails that appear to come from your domain. Most Perth businesses have SPF set up but are missing DKIM and especially DMARC.
- SPF - lists which mail servers are allowed to send email for your domain
- DKIM - adds a cryptographic signature to outgoing emails that receiving servers can verify
- DMARC - tells receiving mail servers what to do when SPF or DKIM checks fail (quarantine or reject) and sends you reports on who is sending email using your domain
Setting DMARC to p=reject means any email claiming to be from your domain that fails authentication is rejected outright - protecting both your customers and your brand from being impersonated.
Layer 2: Email Filtering
Microsoft 365 includes Defender for Office 365, which scans incoming emails for phishing links, malicious attachments, and impersonation attempts. Out of the box it's not configured to its full potential - policies need to be tuned. Key settings to enable:
- Safe Links - rewrites URLs and scans them at click-time, not just delivery-time
- Safe Attachments - detonates attachments in a sandbox before delivering them
- Anti-impersonation protection - flags emails that appear to come from your own domain or specific protected users
Layer 3: Multi-Factor Authentication
Even if a phishing email successfully steals a staff member's password, MFA stops the attacker from using it. This is the most impactful single control you can apply to your Microsoft 365 or Google Workspace accounts. No excuses for not having it enabled across your entire organisation.
DNS authentication, email filtering, and MFA enforcement are all configured as part of our cybersecurity services.
Cybersecurity Services →Layer 4: Staff Awareness
Technology filters catch most phishing attempts but not all. Staff who know what to look for are your last line of defence. Key things to train your Perth team on:
- Always check the sender's actual email address, not just the display name
- Be suspicious of any urgent request involving money, credentials, or sensitive data - even from a known name
- Hover over links before clicking to see the real destination URL
- Call to verify any unexpected invoice or payment request via a known phone number - not the one in the email
- Know how to report a suspicious email to your IT provider immediately
Simulated phishing tests - where your IT provider sends fake phishing emails to your staff - are the most effective way to measure and improve awareness without the risk of a real attack.
Layer 5: Separate Email for Finance
For any Perth business processing invoices or transfers, consider having a specific internal process for payment approvals that requires verbal confirmation for any new payee or changed bank details. This single process has prevented countless BEC frauds.
Frequently Asked Questions
What's the single most important thing we can do to stop phishing?
Multi-factor authentication is the most impactful single control, because it stops a stolen password from being enough on its own to get into an account. It won't stop every phishing email from landing in an inbox, but it dramatically reduces the chance that a moment of staff error turns into a full account compromise.
We already have SPF set up, isn't that enough?
Not on its own. SPF, DKIM, and DMARC work together, and most Perth businesses we see have SPF configured but are missing DKIM and especially DMARC. Without DMARC in particular, there's nothing telling receiving mail servers what to do when a fake email claiming to be from your domain fails those checks, which leaves your business name open to being impersonated.
Is Microsoft 365's built-in email filtering good enough by itself?
It's a solid foundation, Defender for Office 365 does scan for phishing links and malicious attachments, but the default settings aren't tuned to their full potential out of the box. Features like Safe Links, Safe Attachments, and anti-impersonation protection generally need to be configured deliberately rather than left on default.
How often should staff go through phishing awareness training?
Once is rarely enough, since attackers' tactics keep changing and awareness fades over time. Regular simulated phishing tests, alongside periodic refresher training, tend to be far more effective at keeping staff sharp than a single onboarding session that's never repeated.
Want to know how exposed your Perth business email is?
Call 0433 087 091 - we'll check your DNS records, Microsoft 365 policies, and staff awareness in a free security review.
Book a Free Security ReviewFor related reading, see our guides to Phishing & Staff Security Training for Perth Businesses, What an IT Security Audit Covers, and SPF, DKIM, and DMARC Explained.