If a criminal sends an email that appears to come from a partner at your firm, the recipient may see nothing unusual: the display name matches and the domain looks right. Spoofing a domain is far easier than most people realize, unless the domain owner has published certain records that tell receiving mail systems how to treat messages claiming to come from it.
Those records are SPF, DKIM and DMARC. They sound technical, but a firm administrator can understand them well enough to ask good questions and oversee the setup. For law firms, they matter because impersonation of attorneys is a common ingredient in payment redirection and phishing against clients, and because major email providers have been tightening expectations for senders.
What each one does
SPF: who may send
Sender Policy Framework is a DNS record listing the servers allowed to send mail for your domain. A receiving server checks whether the message came from one of them. SPF is useful, but it has limits: it checks a hidden address, not necessarily the one people see, and it breaks in some forwarding situations.
DKIM: was it altered
DomainKeys Identified Mail adds a cryptographic signature to outgoing messages. Your sending system signs the message with a private key, and the receiver verifies it using a public key published in DNS. A valid signature shows the message came through an authorized system and was not changed in transit.
DMARC: what to do about failures
Domain-based Message Authentication, Reporting and Conformance builds on the other two. It requires that the visible From domain align with an SPF or DKIM pass, and it tells receivers what to do when a message fails: nothing, quarantine it or reject it. It also asks receivers to send you reports, which show who is sending mail using your domain.
Why a policy of "none" is only a start
Many domains publish DMARC with a policy of none, which only monitors. That is a sensible first step, because it shows who is sending as you without blocking anything. But a policy of none does not stop spoofing. The goal is to move to quarantine and ultimately reject once you are confident all legitimate senders are covered.
A safe rollout plan
- Inventory your senders. Identify every system that sends mail as your domain: Microsoft 365, practice management software, billing tools, newsletter services, e-signature platforms, website forms, scanners and any marketing system. Shadow senders are the main cause of breakage.
- Publish SPF including your legitimate senders, and watch the record's limits on lookups.
- Enable DKIM for each sending service that supports it.
- Publish DMARC with p=none and a reporting address, and collect reports for several weeks.
- Fix failures. Review reports, identify legitimate senders that fail and configure them properly.
- Move to quarantine, possibly applying it to a percentage of mail first.
- Move to reject when reports are clean.
- Monitor ongoing, since new tools get added over time.
The raw DMARC reports are not meant for humans, so use a reporting service or have your IT provider review them.
Common pitfalls
- Moving to reject too early and blocking invoices or client notifications.
- Forgetting a third-party service that sends on your behalf.
- Leaving old SPF entries for vendors you no longer use.
- Setting records on the main domain and forgetting subdomains or parked domains you own but do not use. Parked domains can publish a policy that nobody should send from them.
- Believing DMARC prevents lookalike domains. It does not. A criminal can register a similar name, so you still need filtering and staff awareness.
What DMARC will not do
DMARC protects your own domain from direct spoofing. It does not stop an attacker who has genuinely compromised a mailbox, and it does not stop lookalikes. That is why multi-factor authentication, monitoring for suspicious rules and phone verification of payment instructions remain essential.
Questions to ask your IT provider
- What is our current DMARC policy?
- Who reviews the reports, and how often?
- When will we reach quarantine or reject?
- Which services send mail as us?
- Are our parked and secondary domains protected?
Insurance and client questionnaires
Cyber insurance applications and client questionnaires increasingly ask about email authentication. Having these in place gives you an honest, favorable answer.
How Counsel Cyber helps
Counsel Cyber manages email authentication for law firms, from sender inventory to enforcement. If you are not sure what your domain publishes, ask us for a quick check.