I am trying to protect the email for a company. abcsales.com. someone has registered abcsales.net and is emailing all of the vendors.
I am wondering how I could stop this type of spoofing.
They registered the domain in Russia. They setup an email server and they have copied the exact email structure including signature blocks.
This company ended up on the dark web with an RDP server credentials for sale.
they have had their On site Exchange server targeted. I think they even might have had access to one of the billing computers/email account.
I asked and they said they have thousands of vendors. They have asked me to stop the other emails.