ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

DMARC, SPF and DKIM: Email Authentication for Law Firm Domains

Email authentication stops criminals from sending messages that appear to come from your firm's domain. Here is what SPF, DKIM and DMARC do, in plain English.

4 min readBy Counsel Cyber Team

Criminals impersonate law firms by sending email that looks like it comes from the firm's own domain. A client receives a message from "you" asking for payment, or a lender receives a message with changed instructions. Three technical standards, SPF, DKIM and DMARC, make this kind of spoofing much harder. They are free or low cost, they work in the background, and many firms have never set them up correctly.

This post explains them without jargon so firm leaders can ask their IT provider the right questions.

The Problem They Solve

Email was designed without strong identity checks. By default, anyone can send a message claiming to be from yourfirm.com. Receiving mail systems need a way to ask, "Is this sender actually allowed to send for that domain?" SPF, DKIM and DMARC provide the answer.

The Three Pieces

SPF: Who may send for us

Sender Policy Framework is a published list, kept in your domain's DNS records, of the servers and services allowed to send email for your domain. When a message arrives, the receiving system checks whether the sending server is on that list.

Common pitfalls: forgetting a legitimate sender, such as a marketing email platform, a billing system or a practice management tool that sends client notifications, and ending up with a list that is too narrow or broken.

DKIM: A signature on the message

DomainKeys Identified Mail adds a digital signature to outgoing messages. The receiving system checks the signature against a public key published in DNS. If the message was altered in transit, or was not signed by an authorized system, the check fails.

Each service that sends on your behalf generally needs its own DKIM setup.

DMARC: What to do when checks fail

Domain-based Message Authentication, Reporting and Conformance ties the other two together. It tells receiving systems what to do with messages that fail the checks, and it requests reports so you can see who is sending mail using your domain. DMARC policy has three levels:

  1. None (monitoring): take no action, but send reports. This is the starting point.
  2. Quarantine: treat failing messages as suspicious, typically sending them to spam.
  3. Reject: refuse failing messages outright.

Moving to reject gives the strongest protection, but only after you are sure all your legitimate mail passes.

Why Law Firms Should Care

  • Fewer spoofed messages appear to come from your domain, which protects clients and counterparties
  • Better delivery of your real email, since receivers trust authenticated senders
  • Visibility into abuse of your domain through DMARC reports
  • Cyber insurance and client questionnaires increasingly ask about email authentication, and some large email providers require it for bulk senders

Authentication does not stop look-alike domains, such as yourfirrn.com, nor does it stop a compromised real mailbox. It is one layer among several, alongside MFA, filtering and call-back verification.

A Safe Rollout

1. Inventory every system that sends email as your domain

Include Microsoft 365 or Google Workspace, scanners, accounting and billing systems, newsletter tools, client portals, e-signature services and websites with contact forms.

2. Publish and fix SPF

Create a single SPF record that covers all legitimate senders. Domains should have only one SPF record, and there are limits on how many lookups it may contain, so work with someone experienced.

3. Enable DKIM for each sender

Turn on signing in your email platform and any third-party service that sends for you.

4. Start DMARC in monitoring mode

Publish a policy of none, directing reports to a mailbox or reporting service. Review reports over several weeks to find legitimate senders that are failing and fix them.

5. Tighten gradually

Move to quarantine, then reject, once reports show legitimate mail passing consistently. Do not rush; blocking your own invoices or client notices causes real problems.

6. Maintain it

Review reports periodically. When you add a new system that sends email, authenticate it before launch.

Protecting Unused Domains

Firms often own old or alternate domains that do not send email. Publish records stating that no mail should be sent from them, which prevents criminals from using them to impersonate you.

Questions for Your IT Provider

  • What are our current SPF, DKIM and DMARC settings?
  • Is DMARC at none, quarantine or reject, and why?
  • Who reviews the DMARC reports?
  • Have we authenticated every third-party sender?
  • Do we have records for parked domains?

What Still Needs Attention

Authentication verifies the domain, not the person. Pair it with external sender banners, link scanning, impersonation detection for your attorneys' names, and staff training. The FBI's Internet Crime Complaint Center continues to emphasize verification through a separate channel for payment instructions, which technology does not replace.

How Counsel Cyber Helps

Counsel Cyber audits law firm email domains, fixes SPF and DKIM, and manages DMARC rollout to enforcement without disrupting legitimate mail. If you are not sure what your domain currently publishes, we can check it quickly.