The Page That Proves You Are You
We run several brands from one office and answer all their email from one place, which is exactly what an invoice scam looks like. So we published the list: every domain, the ABN with a link to check it, and a line saying if it is not on this page it is not us.
If you email one of our brands, the reply may arrive from a different domain to the one you wrote to.
That is not a mistake. We run several brands from one office, and mail for all of them lands in one place, so whoever answers you does it from the address they actually work from. It is ordinary and it is efficient.
It is also, character for character, what a payment redirection scam looks like.
The problem with being legitimately confusing
Business email compromise works by getting a real-looking message from a not-quite-right address in front of someone who is expecting an invoice. The advice every bank, insurer and IT provider gives is the same: if the address is not the one you expect, stop.
That advice is correct. It also means that any business whose internal arrangements are more complicated than one brand, one domain, one inbox is generating false positives against the exact rule protecting its customers.
You can respond to that two ways.
You can explain it in the email — “please note we also operate as X” — which is what a scammer would also write, and which asks the customer to take your word for it inside the message they are supposed to be suspicious of.
Or you can put the list somewhere they can check it independently, and tell them plainly that the list is the only one.
What we published
A section on our divisions page, at a fixed address, with four things on it.
Every website we run. Named, linked, with the brand each one belongs to.
Every other domain that reaches us. Four more brands whose mail comes to the same team, plus two domains that carry email and have no website at all. Those two are listed as email-only, because “there is no site there” is exactly what a customer would find if they checked, and an unexplained dead domain looks worse than a disclosed one.
The details you can verify elsewhere. Our ABN, with a direct link to the national register so the reader can confirm the entity and its trading names without taking our word for anything. The office address. The phone number.
The sentence that does the work: if a domain, address or number is not on this page, it is not us. We will never ask you to change bank details by email, and we will never send an invoice from an address outside the list. If something looks wrong, ring the number on this page — not one written in the email you are querying.
That last clause is the one worth copying. Telling someone to “call us to verify” is useless if they call the number in the fraudulent email. The instruction has to name where the trusted number comes from.
★ Insight ─────────────────────────────────────
A verification page only works if it is reachable from somewhere the customer already trusts and is not itself the thing under suspicion. Ours is linked from the footer of every site in the group, so a customer who is unsure can get to it from any brand’s homepage without following a link in the email they are worried about. A page nobody can find without being sent a link to it has the same trust problem as the email.
─────────────────────────────────────────────────
Why the email-only domains are on it
This was the part we argued about, because listing domains that do not serve a website feels like drawing attention to something odd.
The opposite is true. Those domains send mail. A customer receiving one and checking it will find nothing at the web address — and “nothing there” reads as abandoned or fraudulent. Naming them, and saying plainly that they are for email, converts a red flag into a confirmed detail.
The same logic applies to anything in your business that looks irregular from outside but is normal from inside: a trading name that differs from your legal name, an invoice issued by a different entity to the one on your website, a payment page hosted on a third-party domain. Every one of those is a thing a careful customer will pause on. They will either resolve it against a source you provided, or they will resolve it by guessing.
Build one in an afternoon
This is not a project. Four sections.
1. List every domain that sends or receives mail on your behalf. Include the ones with no website, and say so. Include any domain a third party sends from in your name — a booking platform, an invoicing tool, a mail service.
2. Give two or more details a stranger can verify independently. In Australia, your ABN with a link to the register is the strongest, because it is a government source confirming the entity and its registered names. A physical address and a landline help.
3. State what you will never do. Never change bank details by email. Never send an invoice from outside the listed domains. Never ask for a password. These statements are useful precisely because they are specific commitments a scammer impersonating you cannot honour.
4. Tell them where the trusted phone number is. On this page. Not in the email.
Then link it from the footer of every site you run, so it is reachable without a link from you, and keep it current — a verification page that lists a domain you stopped using is worse than none, because it is confidently wrong about the one thing it exists to be right about.
The underlying point
Trust on the internet is mostly a matter of giving people something independent to check against. Not a badge you designed, not a reassurance in the message itself, but a stable list at a stable address, plus a pointer to a register you do not control.
If your business has any arrangement that could look irregular to a customer paying an invoice — and most businesses with more than one brand, entity or domain do — then the list is worth an afternoon, and it is worth more the day something goes wrong than any amount of explaining after the fact.
Ganda Tech Services runs web, cloud, mobile and content operations for a group of Australian brands. Our own verification page is linked from the footer of every site we run. Security and email work is handled through Cloud Geeks.