The email that quotes your website: how scammers use what you publish
AI-written messages built from your own website sound credible. What a company site tells a scammer, how to spot personalised phishing, and the rules that protect your payments.
A while ago the ShieldWave inbox got an email from a company that wanted to sell us an AI project. The sender said they had read our website and offered a "quote" from it. The quote began with "Stop motion My sites Overview Sites Reports". Those are labels from the dashboard mock-up on our home page: the button that turns off the animation, the menu items and the sample domains. The program that wrote the email had taken interface text for a sentence someone at ShieldWave wrote.
That one was a harmless sales pitch and easy to spot. The same technique, a program that reads a company's website and writes a message from it, is also used by scammers. They get better results from it, because they don't need to understand anything. A few first names, a supplier's name and the tone the company writes in are enough.
Phishing used to give itself away
For years the simplest advice was: watch out for emails with typos, odd grammar and a generic "Dear Customer". That advice has aged. Language models write correctly in any language, almost for free, and they work details from your website into the message: your bookkeeper's first name, the invoicing software you use, a client from your "Trusted by" section.
Tailoring an email to one company used to take a person an hour. Now it costs as much as ordinary spam. That is why personalised fraud now reaches small businesses too.
What your website tells a scammer
You publish most of this on purpose, because it helps customers. It helps to know how it can be used.
People and their roles. A "Team" page with names, job titles and email addresses is a ready-made map: who approves payments, who does the books, who runs the company. The scammer then writes to the bookkeeper as the managing director and greets them by first name.
The address pattern. Once anna.smith@company.com is on the page, every colleague's address is easy to guess. Shared addresses such as office@ or invoices@ give away less.
Suppliers and partners. Client logos, the wholesaler, bank or accounting software you mention. A fake invoice from a real supplier, with their logo and a different account number, is one of the most common frauds against businesses.
Job ads. "Experience with software X required" tells everyone which software you run. An email "from the makers of X" asking you to log in and confirm your licence then lands exactly right.
News. A post saying "we are moving to a new office" or "we are switching to a new ordering system" is a ready excuse for "due to the change, please update our payment details".
The site's technology. WordPress and plugin versions visible in the page code, a forgotten backup file, a missing DMARC record. A normal visitor won't notice, a script checks it in seconds. One of these traces is covered in the article about the backup file left on the server.
You can keep your team page and your client list. Do consider a shared address instead of each employee's personal one, and leave out details customers have no use for, such as the name of your accounting software.
How to spot an email built from your website
The text itself is no longer a good signal, so look at what a script cannot fake as easily.
- The full sender address. Click the sender's name and read the address to the end. Scammers register domains that look like the real one:
cornpany.comforcompany.com,company-uk.com,company.com.invoices.net. - The reply-to address. An email can come from a real address, a hijacked one or a forged one, and the reply still goes somewhere else. Click "Reply" and check which address appears in the "To" field.
- The SPF, DKIM and DMARC result. In Gmail: the three dots next to the message, then "Show original". A FAIL on an email that claims to be from your company or a known supplier is a strong signal. How these protections work is explained in the article on SPF, DKIM and DMARC.
- A request to change something. A new account number, a new address for invoices, an urgent payment "by end of day", a login through a link in the email. The details from your website are only there to stop you checking. The request is the same as it always was.
- A detail that is almost right. Scripts slip on small things: they quote a menu label, get a job title wrong, write to someone who left a year ago. If an email reads like your website as read by a machine, that is probably how it was made.
Rules that work whatever the email says
Nobody spots every scam. What you can do is agree on a few rules under which even a convincing email achieves nothing.
- Confirm any change of bank details by phone. Call a number you already have from the contract or earlier work, never the one in the email asking for the change. Banks give the same advice.
- Larger payments need two people to approve them. Then an email "from the director" to the bookkeeper is not enough.
- Open your bank, accounting software and website admin from a bookmark. Never from a link in an email, however familiar it looks.
- Urgency is a reason to slow down. A real business partner will wait an hour for you to call back.
- In an email you don't trust, don't click "unsubscribe" either. The click confirms that the address works and someone reads it.
You can report suspicious messages to your national cybersecurity agency or CERT. In the UK, forward them to report@phishing.gov.uk. Reports help get fake sites blocked before more people reach them.
Your domain in someone else's emails
There is another side to this: a scammer can pretend to be you and write to your customers. A DMARC record set to p=quarantine or p=reject stops anyone from using your exact domain in the "From" field. Nothing on your side stops a domain that only looks like yours. One thing helps: customers who know your bank details never change by email. You can say so on your invoices, in your email signature or next to the payment details on your website.
You can check whether your domain has SPF, DKIM and DMARC with the free test, no account needed. A ShieldWave scan also shows what your website gives away from the outside: software versions, files left behind and missing security headers.