Anyone can send an email that claims to come from your firm's domain. Without extra protections, an attacker can send messages that appear to be from a partner to clients, lenders or title companies. SPF, DKIM and DMARC are three standards that help receiving mail systems decide whether a message really came from you.
They are not glamorous, but they matter for law firms. Impersonation of attorneys is a common ingredient in wire fraud and business email compromise, and many cyber insurance applications ask whether you have these in place. Setting them up wrong can also block legitimate mail, so a careful approach is worth explaining.
The three pieces in plain English
SPF: who is allowed to send
Sender Policy Framework is a DNS record that lists the servers and services permitted to send email for your domain. A receiving system checks whether the message came from one of them. Your list typically includes Microsoft 365 or Google Workspace, plus services like a newsletter platform, a billing system or a client intake tool that send as your domain.
DKIM: a signature that proves integrity
DomainKeys Identified Mail adds a cryptographic signature to outgoing messages. The signature is verified using a public key published in your DNS. It shows the message was authorized by the domain owner and was not altered in transit.
DMARC: the policy and reporting layer
Domain-based Message Authentication, Reporting and Conformance ties SPF and DKIM together. It tells receivers what to do when a message fails authentication: do nothing but report, quarantine it, or reject it. It also sends you reports showing who is sending mail using your domain, including attackers.
What each policy level does
DMARC has three policy settings:
- None (monitoring): receivers take no action, but you receive reports. Start here.
- Quarantine: failing messages are typically sent to spam.
- Reject: failing messages are blocked. This provides the strongest protection against direct domain spoofing.
Why a staged rollout matters
Most firms discover, once reports start arriving, that several legitimate services send mail as the firm, and some were never documented. Jumping straight to reject can silently block a newsletter, a payment reminder or a client portal notification. The staged process avoids that.
A step-by-step approach
Step 1: Inventory senders
List every system that sends email using your domain: the main mail platform, marketing tools, accounting and billing software, practice management notifications, e-signature services, website contact forms, scanners and copiers, and any vendors who send on your behalf.
Step 2: Configure SPF
Publish a single SPF record that includes every approved sender. Keep in mind two common technical limits: only one SPF record per domain, and a cap on the number of DNS lookups it can trigger. Your IT provider should check both.
Step 3: Enable DKIM
Turn on DKIM signing in your mail platform and for each third-party sender that supports it, publishing the keys in DNS as instructed.
Step 4: Publish DMARC in monitoring mode
Add a DMARC record with a policy of none and an address to receive reports. Raw reports are unwieldy, so many firms use a reporting service to turn them into readable dashboards.
Step 5: Review and fix
Over several weeks, examine the reports. Identify legitimate senders that fail authentication and fix their configuration. Identify unknown senders and decide whether to authorize or block them.
Step 6: Move to quarantine, then reject
When legitimate mail passes reliably, change the policy to quarantine and, after a period of stable results, to reject. Some firms use a percentage setting to apply the policy gradually.
Step 7: Maintain
New tools and vendors will appear. Add a step to your vendor onboarding process: any service that sends email as the firm must be added to SPF and DKIM before launch. Review DMARC reports monthly or quarterly.
What these standards do not do
They protect against someone sending mail that claims to come from your domain. They do not stop:
- Lookalike domains that differ by a character or two.
- Messages from compromised legitimate accounts, which pass authentication.
- Phishing aimed at your staff from other domains.
You still need email filtering, MFA, mailbox monitoring, staff training and payment verification procedures. Consider registering obvious lookalike domains and watching for new ones.
Check your current status
Free online tools can show whether SPF, DKIM and DMARC are present and valid for a domain. If your DMARC policy is missing or set to none with nobody reading the reports, treat that as a to-do item.
Getting it done
Counsel Cyber configures email authentication for law firms, including sender inventories, monitoring and safe progression to enforcement. If you are not sure what your domain's records say today, we can check them and explain the results in plain language.