ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

DMARC, SPF and DKIM: A Plain-English Guide for Law Firms

A non-technical explanation of SPF, DKIM and DMARC email authentication, why they help stop spoofing of your firm's name, and how to roll them out safely.

3 min readBy Counsel Cyber Team

Fraudsters love to send messages that appear to come from a law firm. Maybe it is a fake invoice to a client or a note to a title company with new wiring instructions. If your domain is not protected, anyone can often send email that claims to be from you.

Three technical standards help prevent this: SPF, DKIM and DMARC. The names are unfriendly, but the ideas are simple, and every firm administrator should know enough to ask the right questions of whoever manages your domain.

The Problem They Solve

Email was designed without strong identity checks. Anyone can type your domain in the "From" line. SPF, DKIM and DMARC give receiving mail servers a way to check whether a message really came from a source you authorized, and to decide what to do if not.

SPF: The Approved Sender List

Sender Policy Framework is a list published in your domain's DNS records naming the servers allowed to send mail for your domain. When a message arrives claiming to be from your firm, the receiving server checks whether the sending server is on the list.

Common pitfalls:

  • The list forgets a legitimate sender, such as your billing system, newsletter tool or practice-management platform.
  • The list grows so long that it breaks technical limits.
  • Old vendors remain on it for years.

DKIM: The Tamper-Evident Seal

DomainKeys Identified Mail attaches a digital signature to outgoing messages. The receiving server checks the signature against a public key in your DNS. If it matches, the message came from an authorized system and was not altered in transit.

Each service that sends mail for you, such as Microsoft 365 or a marketing platform, should be configured to sign with your domain.

DMARC: The Policy and the Reporting

Domain-based Message Authentication, Reporting and Conformance ties the two together. It tells receivers what to do when a message fails SPF and DKIM checks and asks them to send you reports.

A DMARC policy has three levels:

  1. none: Monitor only. Failing messages are still delivered, but you receive reports.
  2. quarantine: Failing messages are typically sent to spam.
  3. reject: Failing messages are refused.

Reaching reject gives the strongest protection against others spoofing your exact domain, but only after you are sure your legitimate mail passes.

A Safe Rollout Plan

  1. Inventory your senders. List every system that sends email as your firm: Microsoft 365, accounting, e-signature, case management, CRM, marketing.
  2. Publish SPF and enable DKIM for each legitimate sender.
  3. Start DMARC at "none" with reports going to a mailbox or reporting service.
  4. Review reports for several weeks. Find the legitimate sources failing and fix them. Identify suspicious traffic.
  5. Move to "quarantine," perhaps starting with a percentage of mail, then increase.
  6. Move to "reject" when reports look clean.
  7. Keep monitoring. New tools and vendors will appear.

Many firms stall at step 3 for years. Publishing a monitoring-only policy is better than nothing, but it does not stop spoofing.

What These Standards Do Not Do

It matters to be clear about limits.

  • They do not stop lookalike domains, such as a domain with one letter changed. Attackers register these, and DMARC on your real domain cannot block them.
  • They do not stop a compromised real account from sending fraudulent mail, since messages from a hijacked mailbox are properly authenticated.
  • They do not read the message for deception.

So pair them with MFA, email filtering that flags lookalike domains and a firm-wide rule about verifying payment instructions by phone.

Benefits Beyond Security

Authentication also helps legitimate mail reach inboxes. Major mailbox providers have tightened expectations for senders, so a properly authenticated domain is less likely to have your messages land in spam.

Quick Self-Check

Ask your IT provider three questions.

  • Do we have SPF, DKIM and DMARC records published for every domain we own, including old ones?
  • What is our DMARC policy today, and what is the plan to reach enforcement?
  • Who reviews the DMARC reports?

Counsel Cyber manages email security for law firms, including DMARC rollouts that avoid blocking your own mail. If you would like a quick check of your domain's current records, we can do that and explain the results in plain language.