A hand is holding a smartphone, on which a phishing email is hanging from a fishing hook

This week, I received a message from a long-standing client: «We’ve received the following email. Is it a scam?» The email looked deceptively genuine, and one member of staff had already opened the attachment. Fortunately, nothing happened. But this case is a prime example of what virtually every business in Switzerland faces on a daily basis: phishing emails that are becoming increasingly professional. In this post, I’ll explain where the attackers got hold of your email address in the first place, why the forgeries are now almost impossible to spot, how you and your team should react correctly in an emergency, and what measure I’ve taken to reduce my own spam to practically zero.

Fake email sent in the name of Hostpoint asking for email confirmation
Looks genuine, but it isn’t: the sender’s domain has nothing to do with Hostpoint.

How did they get hold of your email address?

Very few people realise that when you own a domain, your contact details are listed in a public directory. These entries are automatically scoured by spam and phishing networks; every newly registered or amended domain ends up in their databases within hours. On top of that, there are addresses harvested from websites, data leaks and purchased lists. The result: targeted emails sent to senior management and the accounts department, often using real names and plausible sender addresses.

The new generation: AI-perfect forgeries in your hosting provider’s name

Fake emails that appear to come from well-known Swiss hosting providers are currently particularly dangerous. The scam is insidious: every domain owner regularly receives genuine messages from their hosting provider, for example regarding invoices, domain renewals or payment methods. It is precisely these emails that are being faked, and thanks to AI, the language, logo, tone and structure are now spot on down to the last detail. The old tell-tale signs, such as typos or clumsy German, are no longer present. What remains are two reliable rules: check the sender’s domain carefully, and never log in via a link in an email. Always type your hosting provider’s address into the browser yourself. And if your domain and hosting are managed by a web partner, the simplest filter of all applies: genuine communications regarding your domain will come directly from your partner; any email purporting to be from your hosting provider and addressed directly to you is therefore suspect from the outset.

Warnings displayed on a laptop keyboard when entering login details
Never enter your personal login details unless you are 100 per cent sure that the website is genuine.

The three rules for an emergency

If a suspicious email arrives, the same simple procedure applies to all staff:

  • Do not reply.
  • Do not click on any links or open any attachments.
  • If in doubt, forward the email to the web partner or the IT manager, and only then delete it.

If you’ve already opened an attachment: stay calm. Simply viewing a PDF is usually harmless. It only becomes a problem if you’ve clicked on any links or entered any data; in that case, you should change the affected passwords immediately and check your device.

Turning off the tap: domain protection with a proxy service

The most sustainable measure tackles the problem at source. Swiss hosting providers such as Hostpoint offer a domain protection service that combines three elements: a proxy service replaces your personal contact details in the public register, and your data remains under lock and key in Switzerland. A consent-based policy protects the domain from unauthorised changes and takeovers. And loss protection ensures that your domain does not expire even if a renewal payment fails on occasion. I have been using this protection for my own domain for several months now, with measurable results: spam has since fallen to practically zero.

The other side of the coin: Are your own emails ending up in the spam folder?

Phishing protection is one part of the equation; the other concerns your own emails. To ensure that recipients’ servers recognise your messages as genuine, your domain needs three technical verifications: SPF, DKIM and DMARC. Put simply, these are digital signatures that confirm that an email really does come from your company and has not been altered in transit. If these records are missing, two things happen: your emails end up in the quarantine folder for customers with strict email gateways, and fraudsters can send emails in your name without recipients realising. Just this week, I set up exactly these DKIM records for a client because his quotes were ending up in recipients’ spam folders.

How to check your spam score in two minutes

You can check for yourself whether your domain is set up correctly at mail-tester.com: The page displays a one-off test address. Send a standard email to this address from your business account, and you’ll receive a score from 0 to 10, including a detailed analysis of SPF, DKIM and DMARC. A properly configured domain scores 10 out of 10; I verified my own domain in exactly the same way after setting it up. If your score is lower than this, you’ll see straight away from the report where the problem lies.

For my hosting clients: everything under one roof, with no hassle for you

Keep your domain and hosting with me and you don’t have to worry about any of it yourself. I handle all the administration directly: I activate domain protection, configure the proxy service and the consent policy, set up SPF, DKIM and DMARC correctly for your domain, and manage the settings on an ongoing basis. You’ll receive a brief confirmation as soon as everything is set up; that’s all you need to do. That’s precisely the advantage of having your website, domain and hosting managed by a single provider: security measures like these don’t become a project in themselves, but simply involve sending me a quick message. And you have another advantage: as everything to do with your domain is handled by me personally, you’ll immediately recognise any emails purporting to be from your hosting provider that are sent directly to you as suspicious.

Conclusion

Phishing isn’t going to disappear, but your business doesn’t have to be an easy target. Clear guidelines for your team, a properly secured domain registration and correctly configured email authentication significantly reduce the risk. If you’re already a hosting customer with me, just send me a quick message and I’ll set up protection for your domain. For everyone else, I’m happy to check, with no obligation, how exposed your data currently is.

Leave a comment

Your email address will not be published. Required fields are marked *