The email looks right. The name is a managing partner's. The signature is familiar. The only problem is that the address behind the name ends in a domain that is one character off from the firm's real one, or is a free webmail address with the partner's name on it. Impersonation of this kind is among the cheapest and most effective tricks in the criminal playbook, and it targets law firms because they move money and handle sensitive information.
The FBI's Internet Crime Complaint Center has described business email compromise as a persistent financial threat. Many of those schemes rely on impersonation instead of any technical break-in. Understanding the common variants helps staff catch them.
The main tricks
Display-name spoofing
Email clients show a friendly name before the address. Anyone can set that name to anything. On a phone, where only the name appears, a message that says "Jane Partner" may actually come from a random address. This requires no domain registration at all.
Lookalike domains
Criminals register domains that resemble the real one by:
- Swapping similar characters, such as a lowercase letter L for the capital letter I, or the letters "rn" for an "m".
- Adding or dropping a letter.
- Appending words like "law" or "legal" or changing the ending from .com to .net.
- Using lookalike characters from other alphabets.
They then set up mailboxes and send convincing messages, often replying inside a real conversation after seeing a thread through another compromised account.
Reply-to manipulation
A message may appear to come from a trusted address but carry a different reply-to. When the recipient answers, the response goes to the criminal.
Compromised third parties
Messages from a genuine but hijacked account at a title company, lender or client are the hardest to detect, since the sender and domain are legitimate. That is why verification by phone matters even with perfectly authentic-looking mail.
Habits that catch fakes
- Check the full address, not just the name. On a phone, tap or expand the sender details.
- Read the domain slowly, letter by letter, especially on anything involving money or credentials.
- Hover over links before clicking, and be suspicious of unexpected attachments.
- Look at the reply-to when answering a request for money, documents or access.
- Notice urgency, secrecy and requests to bypass normal process. These are pressure tactics.
- Verify by phone using a number you already have, not one in the message.
Technical controls
External sender banners
Configure the email system to label messages from outside the firm, so an unexpected "internal" executive request that carries an external tag stands out.
Impersonation protection
Modern email security tools can flag messages where the display name matches a known partner but the address does not, and can detect domains similar to yours. Ask your provider whether such protection is enabled, and add your leadership's names to a protected list.
Authentication records
Publishing SPF, DKIM and DMARC and enforcing a strict policy prevents criminals from sending mail that truly claims to be from your exact domain. It does not stop lookalike domains, but it removes the easiest option.
Register defensive domains
Consider registering obvious variations of your domain, such as common misspellings and other endings, and keep them parked with a no-send email policy. This is not exhaustive, but it covers the most predictable cases.
Monitor for new lookalikes
Some services alert you when a domain similar to yours is newly registered. This is optional but helpful for larger firms or those frequently targeted.
Train with examples
Show staff real examples of display-name and lookalike emails with names redacted. Run periodic phishing simulations, and focus on reporting rather than punishment. Make a one-click "report this email" button available so that reporting is easier than ignoring.
What to do if you replied
Tell IT immediately. Do not delete the message. If you sent credentials, change passwords and revoke sessions. If you sent or planned money, call your bank at once. Quick reporting is more valuable than embarrassment management.
Remember the limits
No single check catches everything. Layers, including filtering, authentication, training and phone verification, work together. The most reliable defense for payments remains a procedure that does not depend on judging whether an email looks real.
How Counsel Cyber helps
Counsel Cyber configures impersonation protection, authentication records and reporting tools for law firms, and trains staff using realistic examples. Ask us for an email security review if you want to see how your firm would handle a convincing fake.