{"id":567,"date":"2026-07-08T11:06:11","date_gmt":"2026-07-08T09:06:11","guid":{"rendered":"https:\/\/swissmediadesign.com\/?p=567"},"modified":"2026-07-31T09:39:05","modified_gmt":"2026-07-31T07:39:05","slug":"phishing-emails-protection-for-small-businesses","status":"publish","type":"post","link":"https:\/\/swissmediadesign.com\/en\/phishing-mails-kmu-schutz\/","title":{"rendered":"Why your firm receives phishing emails and how to put a stop to them"},"content":{"rendered":"<p>This week, I received a message from a long-standing client: \u00abWe\u2019ve received the following email. Is it a scam?\u00bb The email looked deceptively genuine, and one member of staff had already opened the attachment. Fortunately, nothing happened. But this case is a prime example of what virtually every business in Switzerland faces on a daily basis: phishing emails that are becoming increasingly professional. In this post, I\u2019ll explain where the attackers got hold of your email address in the first place, why the forgeries are now almost impossible to spot, how you and your team should react correctly in an emergency, and what measure I\u2019ve taken to reduce my own spam to practically zero.<\/p>\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"691\" src=\"https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-beispiel-hostpoint-fake-1024x691.jpg\" alt=\"Fake email sent in the name of Hostpoint asking for email confirmation\" class=\"wp-image-573\" srcset=\"https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-beispiel-hostpoint-fake-1024x691.jpg 1024w, https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-beispiel-hostpoint-fake-300x203.jpg 300w, https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-beispiel-hostpoint-fake-768x518.jpg 768w, https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-beispiel-hostpoint-fake-1536x1037.jpg 1536w, https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-beispiel-hostpoint-fake.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Looks genuine, but it isn\u2019t: the sender\u2019s domain has nothing to do with Hostpoint.<\/figcaption><\/figure>\n\n\n<h2>How did they get hold of your email address?<\/h2>\n\n<p>Very few people realise that when you own a domain, your contact details are listed in a public directory. These entries are automatically scoured by spam and phishing networks; every newly registered or amended domain ends up in their databases within hours. On top of that, there are addresses harvested from websites, data leaks and purchased lists. The result: targeted emails sent to senior management and the accounts department, often using real names and plausible sender addresses.<\/p>\n\n<h2>The new generation: AI-perfect forgeries in your hosting provider\u2019s name<\/h2>\n\n<p>Fake emails that appear to come from well-known Swiss hosting providers are currently particularly dangerous. The scam is insidious: every domain owner regularly receives genuine messages from their hosting provider, for example regarding invoices, domain renewals or payment methods. It is precisely these emails that are being faked, and thanks to AI, the language, logo, tone and structure are now spot on down to the last detail. The old tell-tale signs, such as typos or clumsy German, are no longer present. What remains are two reliable rules: check the sender\u2019s domain carefully, and never log in via a link in an email. Always type your hosting provider\u2019s address into the browser yourself. And if your domain and hosting are managed by a web partner, the simplest filter of all applies: genuine communications regarding your domain will come directly from your partner; any email purporting to be from your hosting provider and addressed directly to you is therefore suspect from the outset.<\/p>\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"610\" src=\"https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-warnung-logindaten-1024x610.jpg\" alt=\"Warnings displayed on a laptop keyboard when entering login details\" class=\"wp-image-571\" srcset=\"https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-warnung-logindaten-1024x610.jpg 1024w, https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-warnung-logindaten-300x179.jpg 300w, https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-warnung-logindaten-768x457.jpg 768w, https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-warnung-logindaten-1536x914.jpg 1536w, https:\/\/swissmediadesign.com\/wp-content\/uploads\/2026\/07\/phishing-warnung-logindaten.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Never enter your personal login details unless you are 100 per cent sure that the website is genuine.<\/figcaption><\/figure>\n\n\n<h2>The three rules for an emergency<\/h2>\n\n<p>If a suspicious email arrives, the same simple procedure applies to all staff:<\/p>\n\n<ul>\n<li>Do not reply.<\/li>\n<li>Do not click on any links or open any attachments.<\/li>\n<li>If in doubt, forward the email to the web partner or the IT manager, and only then delete it.<\/li>\n<\/ul>\n\n<p>If you\u2019ve already opened an attachment: stay calm. Simply viewing a PDF is usually harmless. It only becomes a problem if you\u2019ve clicked on any links or entered any data; in that case, you should change the affected passwords immediately and check your device.<\/p>\n\n<h2>Turning off the tap: domain protection with a proxy service<\/h2>\n\n<p>The most sustainable measure tackles the problem at source. Swiss hosting providers such as Hostpoint offer a domain protection service that combines three elements: a proxy service replaces your personal contact details in the public register, and your data remains <a href=\"https:\/\/swissmediadesign.com\/en\/swiss-based-small-business\/\">under lock and key in Switzerland<\/a>. A consent-based policy protects the domain from unauthorised changes and takeovers. And loss protection ensures that your domain does not expire even if a renewal payment fails on occasion. I have been using this protection for my own domain for several months now, with measurable results: spam has since fallen to practically zero.<\/p>\n\n<h2>The other side of the coin: Are your own emails ending up in the spam folder?<\/h2>\n\n<p>Phishing protection is one part of the equation; the other concerns your own emails. To ensure that recipients\u2019 servers recognise your messages as genuine, your domain needs three technical verifications: SPF, DKIM and DMARC. Put simply, these are digital signatures that confirm that an email really does come from your company and has not been altered in transit. If these records are missing, two things happen: your emails end up in the quarantine folder for customers with strict email gateways, and fraudsters can send emails in your name without recipients realising. Just this week, I set up exactly these DKIM records for a client because his quotes were ending up in recipients\u2019 spam folders.<\/p>\n\n<h2>How to check your spam score in two minutes<\/h2>\n\n<p>You can check for yourself whether your domain is set up correctly at <a href=\"https:\/\/www.mail-tester.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">mail-tester.com<\/a>: The page displays a one-off test address. Send a standard email to this address from your business account, and you\u2019ll receive a score from 0 to 10, including a detailed analysis of SPF, DKIM and DMARC. A properly configured domain scores 10 out of 10; I verified my own domain in exactly the same way after setting it up. If your score is lower than this, you\u2019ll see straight away from the report where the problem lies.<\/p>\n\n<h2>For my hosting clients: everything under one roof, with no hassle for you<\/h2>\n\n<p>Keep your domain and <a href=\"https:\/\/swissmediadesign.com\/en\/services\/hosting-maintenance\/\">hosting with me<\/a> and you don\u2019t have to worry about any of it yourself. I handle all the administration directly: I activate domain protection, configure the proxy service and the consent policy, set up SPF, DKIM and DMARC correctly for your domain, and manage the settings on an ongoing basis. You\u2019ll receive a brief confirmation as soon as everything is set up; that\u2019s all you need to do. That\u2019s precisely the advantage of having your website, domain and hosting managed by a single provider: security measures like these don\u2019t become a project in themselves, but simply involve sending me a quick message. And you have another advantage: as everything to do with your domain is handled by me personally, you\u2019ll immediately recognise any emails purporting to be from your hosting provider that are sent directly to you as suspicious.<\/p>\n\n<h2>Conclusion<\/h2>\n\n<p>Phishing isn\u2019t going to disappear, but your business doesn\u2019t have to be an easy target. Clear guidelines for your team, a properly secured domain registration and correctly configured email authentication significantly reduce the risk. If you\u2019re already a hosting customer with me, just send me a quick message and I\u2019ll set up protection for your domain. For everyone else, <a href=\"https:\/\/swissmediadesign.com\/en\/contact\/\">I\u2019m happy to check, with no obligation<\/a>, how exposed your data currently is.<\/p>","protected":false},"excerpt":{"rendered":"<p>This week, I received a message from a long-standing customer: \u00abWe\u2019ve received the following email. Is it a hoax?\u00bb The email looked deceptively genuine, and an employee had \u2026<\/p>","protected":false},"author":2,"featured_media":568,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-567","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-allgemein"],"_links":{"self":[{"href":"https:\/\/swissmediadesign.com\/en\/wp-json\/wp\/v2\/posts\/567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/swissmediadesign.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/swissmediadesign.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/swissmediadesign.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/swissmediadesign.com\/en\/wp-json\/wp\/v2\/comments?post=567"}],"version-history":[{"count":0,"href":"https:\/\/swissmediadesign.com\/en\/wp-json\/wp\/v2\/posts\/567\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/swissmediadesign.com\/en\/wp-json\/wp\/v2\/media\/568"}],"wp:attachment":[{"href":"https:\/\/swissmediadesign.com\/en\/wp-json\/wp\/v2\/media?parent=567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/swissmediadesign.com\/en\/wp-json\/wp\/v2\/categories?post=567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/swissmediadesign.com\/en\/wp-json\/wp\/v2\/tags?post=567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}