ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

SPF, DKIM and DMARC: Email Authentication for Law Firms

Email authentication makes it harder for criminals to send mail that appears to come from your firm. Learn what SPF, DKIM and DMARC do and how to roll them out.

4 min readBy Counsel Cyber Team

If an attacker can send an email that appears to come from your managing partner's address, your clients, vendors and staff have little reason to doubt it. That kind of impersonation is a staple of wire fraud and invoice scams. Three email authentication standards, called SPF, DKIM and DMARC, exist to make that spoofing much harder. They are not exotic, and they are largely a one-time configuration project, but many small law firms have never fully set them up.

This post explains what each does in plain English and how to roll them out safely without breaking legitimate email.

The three standards in plain English

SPF: who may send mail for us

Sender Policy Framework is a published list, in your domain's DNS records, of the servers allowed to send email using your domain name. A receiving server checks whether the message came from one of them.

DKIM: this message was not altered and really came from us

DomainKeys Identified Mail adds a digital signature to outgoing messages. The receiving server checks the signature against a public key in your DNS. A valid signature indicates the message was authorized by your domain and was not changed in transit.

DMARC: what to do when checks fail

Domain-based Message Authentication, Reporting and Conformance ties the two together. It tells receivers how to treat messages that fail authentication, whether to do nothing, send them to junk or reject them outright, and it sends you reports about who is sending mail using your domain.

The policy levels are commonly called none (monitor only), quarantine and reject. Reject is the strongest protection against spoofing of your exact domain.

What these standards do and do not do

They help prevent criminals from sending email that falsely uses your exact domain. They do not stop:

  • Look-alike domains, such as a slightly misspelled version of your firm's name.
  • Compromised real mailboxes, including those of clients and vendors.
  • Phishing aimed at your staff from other domains.

So authentication is one layer. It pairs with MFA, email filtering, training and verification procedures for payment changes.

Why law firms should care

Clients may be asked to trust your emails with sensitive instructions. If your domain is easy to spoof, a criminal can impersonate the firm to the client and redirect funds. Many large mail providers also apply stricter treatment to unauthenticated email, so poor setup can also cause your legitimate messages to land in spam. Cyber insurers and client questionnaires increasingly ask whether DMARC is in place.

Rolling it out safely

The common mistake is jumping straight to a strict policy and blocking your own invoices, newsletter or billing system emails. Follow a staged approach.

  1. Inventory every source of email for your domain. This includes Microsoft 365, practice management or billing platforms, marketing tools, e-signature services, scanners and copiers, website forms and any vendor sending on your behalf. Staff will remember some; others only appear in DMARC reports.
  2. Publish SPF listing authorized senders. Keep it accurate; SPF has technical limits on the number of lookups, so avoid piling on unnecessary entries.
  3. Enable DKIM signing for each sending service that supports it, including Microsoft 365.
  4. Publish DMARC at monitor-only (p=none) with a reporting address. Review reports for several weeks to find legitimate senders failing checks.
  5. Fix the failures. Add missing senders, configure DKIM for third parties, retire unneeded services.
  6. Move to quarantine, then reject, in steps, watching for problems after each.
  7. Maintain it. Whenever the firm adds a new tool that sends email, update the records.

Reports are your friend

DMARC reports are machine-generated and hard to read directly. Use a reporting service or have your IT provider summarize them. They show you volume, sources and failures, including unexpected senders that might indicate abuse.

Don't forget other domains

If your firm owns old domains, alternate spellings or domains that no longer send mail, publish records that say no mail should come from them. Unused domains are attractive to spoofers.

Check inbound too

Authentication also protects what you receive. Ensure your email filtering honors other domains' policies and flags failures. And remember that a message that passes authentication is not necessarily safe: criminals can register their own look-alike domains and authenticate them perfectly.

Who owns the DNS?

Many firms do not know who controls their domain registration and DNS. It might be a former web designer or a long-gone employee. Confirm ownership, enable MFA on the registrar account and document who can make changes. A hijacked domain defeats every other control.

How Counsel Cyber can help

Counsel Cyber sets up and monitors SPF, DKIM and DMARC for law firms and works through the sender inventory with you so legitimate mail keeps flowing. If you would like to know where your domain stands today, we can check it and explain the results.