Skip to main content
← Back to blog

Email Authentication Does Not Replace Payment Verification

Why SPF, DKIM, and DMARC reduce spoofing risk but cannot make an invoice or payment request trustworthy by themselves.

By Alex Castrillo3 min readFact-checked August 28, 2026
Email Authentication Does Not Replace Payment Verification

Email authentication helps receiving systems evaluate whether a message is authorized for a domain. It does not prove that the person asking for money is honest, that an account was not compromised, or that changed bank details are legitimate.

What the evidence supports

CISA states that DMARC protects a domain from direct spoofing but does not protect a recipient from every spoofed message. The FBI describes business email compromise as a financially damaging crime and recommends verifying payment or account changes through a separate, trusted channel.

Why it matters to a Connecticut operator

Cannabis operators manage vendor payments in a banking-constrained environment where urgency and changing instructions may already feel normal. Payment verification must be a business process, not an email judgment.

Operator checklist

  • Publish and monitor SPF, DKIM, and DMARC, progressing toward enforcement after legitimate senders are accounted for.
  • Require out-of-band verification for new bank details and high-risk payments.
  • Use a known phone number or existing vendor contact—not the contact information in the request.
  • Define who can change vendor payment records and require a second approver.
Scope note: This briefing separates documented facts from practical recommendations. It is cybersecurity guidance, not legal advice or a statement that every recommended control is expressly required by Connecticut cannabis regulations.

Primary sources

About the author

Alex Castrillo

Founder of CannaShield. Working cyber incident response analyst and vCISO for licensed cannabis operators. Writes on cannabis breach analysis, GRC, cyber insurance readiness, and email-spoofing risk.

CannaShield on LinkedIn →

Make the risk concrete.

Start with the free CannaShield Email Security Scorecard to see whether your domain can be spoofed and whether DMARC, SPF, and DKIM are giving attackers room to impersonate your cannabis business.

Run the free scorecard →

Keep sharpening the cannabis security picture.