Why a spam filter is not enough to stop email fraud.
Your spam filter is doing important work. It quietly removes an enormous amount of junk, malware and obvious phishing before you ever see it, and you should absolutely keep it. The problem is what it is built to catch. A filter works on volume, reputation and known-bad patterns, so the one email most likely to cost you money is the one it is least equipped to stop.
What a spam filter does well
A spam filter is genuinely good at the high-volume, already-known threats:
- Bulk junk sent to thousands of people at once.
- Known-bad senders, domains and servers that already have a poor reputation.
- Malware and dangerous attachments that match a known signature.
- The obvious phishing that reuses a link or a template seen many times before.
The gap it leaves
A filter decides using patterns and reputation. A targeted fraud email gives it neither. There is no bad attachment, no link the filter has ever blocked, and the domain has never sent a single piece of spam, so it carries a clean reputation. Often there is no link at all, just a few lines of plausible text and a bank account. To the filter it looks exactly like the ordinary business mail it is meant to let through, because that is precisely what it was designed to imitate.
What slips straight through
- Invoice fraud, a fake or altered bill that reads like routine admin.
- A supplier changing their bank details, sometimes from the supplier's own compromised account, so the email really is genuine.
- CEO fraud, an urgent request that appears to come from your boss.
- A lookalike domain, a clean, brand-new domain registered to imitate one you trust.
How to close the gap
The answer is not a stricter filter, which would only start blocking real mail. It is a second, human check on the messages that ask you to move money or change a detail, plus a view your own filter does not have: what other businesses are already seeing. When one organisation reports a suspicious sender, everyone else who checks it benefits, so a fresh fraud campaign is recognised across the network instead of building a bad reputation one victim at a time.
Not sure about an email your filter let through? Forward it, free.
Send it to Sender Registry and we assess the sender, the domain, and what the wider network already knows about it. No account, no card. You get a plain-English verdict back.
Common questions
Do spam filters stop invoice fraud?
Rarely, on their own. A spam filter is tuned to catch high-volume junk and mail from senders with a bad reputation. A fraudulent invoice is usually a low-volume, well-written email from a clean domain, sometimes the genuine supplier whose account was broken into, so there is little for a filter to flag.
Why do phishing emails still get through our filter?
The dangerous ones are built to. A targeted email carries no bad attachment, no known-bad link, and comes from a domain that has never sent spam. The filter has no pattern to match, because the message is designed to look exactly like ordinary business.
If our filter passed it, does that mean the email is safe?
No. Passing a spam filter only means the message did not match anything the filter already knows is bad. It is not a judgement that the sender is genuine or that the request is safe to act on. Treat a clean filter result as the absence of a known problem, not proof of safety.
What catches what a spam filter misses?
A shared intelligence network. When one business reports a suspicious sender, everyone else checking that sender benefits, so a brand-new fraud campaign gets recognised across the network rather than waiting to build a bad reputation one victim at a time. Forwarding a suspect email to Sender Registry checks it against exactly that.