Before You Wire Closing Funds, Check the Email That Sent the Instructions
Real estate wire fraud cost buyers and sellers over $275 million in 2025, almost always through an email that looked exactly like it came from the title company or agent. Email Forensics reads the headers and routing behind that message before you act on it.
The email looks completely normal. That's the problem
The FBI's 2025 Internet Crime Report recorded 12,368 real estate wire fraud complaints and more than $275 million in losses — an increase of roughly 58% year over year. Business email compromise drove most of it: a fraudster either spoofs a domain that looks one character off from the real one, or genuinely compromises a title company, agent or lender's mailbox and waits, reading real correspondence until the moment closing funds are about to move — then sends new wiring instructions from inside a thread that already looks legitimate.
The report's own case notes make the pattern concrete. In one, a Missouri buyer received what looked like a message from their title company with instructions to wire over $1.3 million to a fraudulent account; the FBI's Recovery Asset Team managed to freeze it because it was reported within hours. In another, an Oregon city government wired over $6 million to an account tied to the same fraud ring weeks later, and recovery there took cross-border cooperation that doesn't always succeed. FBI figures put the recovery rate for reported wires still inside the US banking system at 58% in 2025 — and near zero once funds move overseas or into cryptocurrency, which is where an increasing share of BEC proceeds now go.
A concrete example
What to check before a closing-day wire
Use this on any email carrying wiring instructions, whether it's the first one you've received on this transaction or a "corrected" one that arrived later.
The situation
An email arrives two days before closing, apparently from the title company, with a bank account that's slightly different from the one quoted verbally at the start of the transaction. It's a reasonable, professionally worded message with no obvious spelling mistakes.
Source and destination you choose
Where it comes from
The original email file (.eml or .msg)
Saved directly from your mail client rather than a forwarded copy, so the headers stay intact
Why this one: The headers — not the visible text — are where routing and authentication evidence actually lives.
Also works with
- Pasted raw headers if you can't save the file
- PST export if the email is one of several on the same transaction
Where the result goes
Forensics report (PDF or CSV)
Header-by-header analysis, SPF/DKIM/DMARC results, routing hops and any flagged anomalies
Why this one: This is what you'd want in hand if you also need to report the incident afterwards.
Or choose
- On-screen review before download
- Plain text summary
What the analysis actually looks at
-
1
Authentication results
SPF, DKIM and DMARC are checked and shown pass, fail or unknown — a genuine account sending a message will usually pass all three.
-
2
The routing path
Each hop the email took, with the servers and IP addresses involved, flagged if the path looks unusual for that sender.
-
3
Sender domain details
Domain age, DNS records and how they compare to what you'd expect from an established business, which can surface a lookalike domain.
-
4
A plain-language summary
What looks normal, what's worth questioning, and why — without needing to read raw header syntax yourself.
SPF and DKIM passing does not mean the wiring instructions are genuine. If the title company's actual mailbox has been compromised, mail sent from it will pass authentication because it really was sent from that account — the criminal is inside it, not spoofing it. Header analysis narrows down what looks wrong; it can't certify what's right.
The one step this can't replace
Every fraud-prevention guide on this topic — from FBI advisories to title industry guidance — converges on the same instruction: call the title company or agent using a phone number you already had before this transaction started, never a number taken from the email itself, and verbally confirm any account number before you wire anything. Header analysis is useful evidence for deciding whether to be suspicious and for reporting fraud afterwards. It is not a substitute for that phone call.
Questions buyers and agents ask
Can this tell me for certain whether an email is fraudulent?
No tool can give that certainty from headers alone, especially with a compromised legitimate account. It flags anomalies worth investigating; final verification should always include an independent phone call.
What if the instructions came by a portal message, not email?
Email Forensics only analyses email. If your closing platform uses a secure portal for fund instructions, treat any email-only version of the same instructions as a reason for extra suspicion, not less.
Is this useful after the fact, for a police or bank report?
Yes — a header and routing analysis is exactly the kind of technical detail banks, the FBI's IC3 and any subsequent investigation will ask for.
Related guides
Verifying a vendor's changed bank details
The same fraud pattern, aimed at business accounts payable instead of a closing.
What email forensics actually looks at
Headers, hops and authentication, without a closing-day deadline.
Redacting emails before pasting into AI tools
A different everyday email risk worth a habit change.
Read the headers before the money moves