Email authentication helps receiving systems evaluate whether a message is authorized for a domain. It does not prove that the person asking for money is honest, that an account was not compromised, or that changed bank details are legitimate.
What the evidence supports
CISA states that DMARC protects a domain from direct spoofing but does not protect a recipient from every spoofed message. The FBI describes business email compromise as a financially damaging crime and recommends verifying payment or account changes through a separate, trusted channel.
Why it matters to a Connecticut operator
Cannabis operators manage vendor payments in a banking-constrained environment where urgency and changing instructions may already feel normal. Payment verification must be a business process, not an email judgment.
Operator checklist
- Publish and monitor SPF, DKIM, and DMARC, progressing toward enforcement after legitimate senders are accounted for.
- Require out-of-band verification for new bank details and high-risk payments.
- Use a known phone number or existing vendor contact—not the contact information in the request.
- Define who can change vendor payment records and require a second approver.
