Back to BlogEmail Security Case Studies

Can DMARC stop lookalike email scams? Lessons from a $158,000 strawberry-seed fraud

StopSpoofingMe TeamPublished 6 min read

On September 16, 2026, Georgia's Attorney General announced the sentencing of a Decatur woman who received $158,000 that an agricultural company wired after a payment request from a near-identical copy of its strawberry-seed supplier's email address. DMARC can't block a lookalike address, so read addresses letter by letter and confirm bank details by phone.

Key takeaways

  • In June 2021, an agricultural company buying strawberry seeds from an Oregon company wired $158,000 in two payments after a request from an email address nearly identical to the supplier's, according to the Georgia Attorney General.
  • The woman who received the money was sentenced under Georgia's First Offender Act to 10 years, with 90 days in prison and the rest on probation. The AG says the scam itself was carried out by unknown person(s).
  • DMARC protects a supplier's exact domain. A near-identical address is a different address, so DMARC doesn't catch it.
  • A short phone call to a number you already have is one of the simplest fraud controls there is.

What happened?

Business email compromise (BEC) usually brings to mind big corporations and huge wire transfers. This one started with an order for strawberry seeds.

According to the Georgia Attorney General's office:

  • The order. An agricultural company was contracting with an Oregon company to buy strawberry seeds.
  • The email. The company then received a request for payment from an email address that was nearly identical to the one the Oregon company used.
  • The payments. Following that request, the company sent two wires, on June 15 and June 30, 2021, totaling $158,000.
  • The money. Ogechi Urenna Udunka, 44, of Decatur, Georgia, received both wires. The AG's office says the money was the proceeds of a BEC scam carried out by unknown person(s).
  • The sentence. Udunka pleaded to two counts each of theft by taking and money laundering. A Gwinnett County Superior Court judge sentenced her under the First Offender Act to 10 years, with the first 90 days in prison and the remainder on probation. She must also pay full restitution to the victim and complete 200 hours of community service.

So the wires went out in June 2021, and the sentencing was announced more than five years later. The people who actually wrote the fake emails were not identified in the announcement. The case that reached court was about the money: who received it and where it went.

The AG's release doesn't say how the scammers knew about the seed order. In other cases, criminals have worked from inside real mailboxes: federal prosecutors said the attacker in the $7.5 million charity fraud we covered in August used hijacked mailboxes alongside lookalike domains.

Why does this matter for your business?

This is the most ordinary kind of BEC there is: a real supplier, a real order, a payment request tied to that deal, and an email address that looks right at a glance. It's the kind of request a busy small team could pay without a second look.

What does DMARC stop, and what doesn't it?

DMARC, together with SPF and DKIM, lets receiving mail servers check whether a message really comes from the domain shown in the From address. If a supplier publishes a DMARC policy of p=reject, a criminal can't simply put that supplier's exact address in the From line and expect it to be delivered by receivers that honor the policy.

But nearly identical is not identical. A lookalike (or cousin) domain is a different domain, often registered by the attacker, who can set up valid SPF, DKIM and DMARC records for it. Microsoft's documentation says impersonation can pass all three checks when an attacker creates a lookalike domain and publishes valid DNS records. For a recent example of a lookalike in use, the fake CEO invoice campaign Microsoft disclosed last week registered service-nowinc[.]com on July 31 and used it for fake ServiceNow addresses inside its emails and invoice.

DMARC still matters. An enforced DMARC policy pushes criminals off your exact domain and onto lookalikes, which people and filters have a fighting chance of spotting. It just can't be your only defense.

How do you spot a near-identical address?

The public record doesn't say which trick was used in the strawberry-seed case, so here are the common ones, using made-up addresses:

Trick Real address Lookalike
A letter swapped for a number [email protected] [email protected]
A doubled or extra letter [email protected] [email protected]
"rn" pretending to be "m" [email protected] [email protected]
A different ending [email protected] [email protected]
An extra word or hyphen [email protected] [email protected]
The same name at a free email service [email protected] bloomseed.orders@ (free webmail)

(Every address in this table is made up. The .example ending and the example.com and example.net domains are reserved for documentation, so none of them belongs to a real business.)

Try reading the domain out loud, one letter at a time. It feels silly, but it makes you look at every character.

What should you do now?

  1. Make a callback rule for bank details. Any request to pay a new account, or any change to a supplier's bank details, gets confirmed by phone using a number you already have on file. Never use the number in the email or on the new invoice.
  2. Verify bank details before the first payment to a new supplier. New relationships are the riskiest moment, because you don't yet know what "normal" looks like.
  3. Start from your saved contacts. When you reply about money, type the supplier's address from your own records rather than hitting Reply.
  4. Turn on sender warnings. If you use Microsoft 365, the first contact safety tip warns people when they don't often get email from a sender, and Microsoft recommends turning it on. Defender for Office 365 adds domain impersonation protection that can watch your key suppliers' domains.
  5. Check your own domain, and your suppliers'. Run your domain through our free domain scanner to confirm SPF, DKIM and DMARC are in place. Check your key suppliers' domains too, and nudge them if they aren't protected.
  6. Know what to do if money goes out. Call your bank immediately to try to stop or recall the wire. Then report it to the FBI's Internet Crime Complaint Center (IC3) and local police.

If you'd like help putting these controls in place, you can reach us at (818) 574-8240.

Frequently asked questions

Would DMARC have stopped the strawberry-seed scam?

Probably not on its own. The Georgia AG says the payment request came from an email address nearly identical to the supplier's, which means it wasn't the supplier's real address. DMARC only protects the exact domain it's published on. A phone call to the supplier on a known number, confirming the request and the bank details before paying, is the control that fits this scam.

What is a cousin domain?

"Cousin domain" is another name for a lookalike domain: a real, registered domain chosen to resemble a trusted one, for example by swapping a lowercase letter l for the digit 1. Because the attacker controls it, they can make it pass email authentication checks. It still isn't the real company, so the defense is careful reading, sender warnings and verifying payment requests another way.

Why was the person who received the money sentenced, and not the scammer?

According to the AG's office, the scam was carried out by unknown person(s). Udunka received the two wires, and she pleaded to two counts each of theft by taking and money laundering. The people who sent the emails were not identified in the announcement.

How can I check whether a supplier's domain uses DMARC?

Enter the supplier's domain in a DMARC checker such as our free scanner, which looks up its published SPF and DMARC records and checks common DKIM selectors. A domain at p=reject is much harder to forge exactly. Remember that a strong DMARC record protects the real domain only, so it won't warn you about a lookalike address.

Sources

  1. Georgia Office of the Attorney General — Carr: Decatur Woman Sentenced for Involvement in $158k Business Email Compromise Scam (September 16, 2026)
  2. Microsoft Security Blog — Protecting organizations from AI-assisted executive impersonation and invoice fraud (September 10, 2026)
  3. U.S. Attorney's Office, District of Maryland — press release on Olusegun Adejorin's conviction by a federal jury (December 2025)
  4. Microsoft Learn — Anti-phishing policies in cloud organizations (reference documentation, undated)

Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.

Related Topics

lookalike domain scamcousin domain email fraudvendor payment fraudbusiness email compromise small businessdoes DMARC stop lookalike domainshow to spot fake supplier emailsverify vendor bank details

Ready to Secure Your Email?

Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.