A client receives an email that appears to come from your firm. It asks them to update their wire instructions. The message did not come from your mail system at all. The criminal simply forged your domain in the From line. Without email authentication, nothing stops that.
Three DNS-based standards, SPF, DKIM and DMARC, let receiving mail systems check whether a message claiming to come from your domain really did. They will not stop every scam, such as lookalike domains, but they close an obvious gap, and they increasingly matter for deliverability too. CISA and other agencies recommend them.
What each one does
SPF: who is allowed to send
Sender Policy Framework is a DNS record listing the servers and services authorized to send email for your domain. Receiving systems check whether the sending server is on the list.
DKIM: is the message authentic
DomainKeys Identified Mail adds a cryptographic signature to outgoing messages. The receiving system looks up your public key in DNS and checks that the signature is valid and the message was not altered.
DMARC: what to do with failures
Domain-based Message Authentication, Reporting and Conformance ties the two together. A DMARC record tells receivers what to do when a message fails SPF and DKIM checks in a way that matches your domain: do nothing (monitor), quarantine, or reject. It also asks receivers to send you reports about who is sending mail using your domain.
Why law firms should care
- Criminals can spoof your domain to impersonate partners or staff in payment fraud attempts against clients, vendors and your own employees
- Clients and insurers increasingly ask whether DMARC is enforced
- Large mailbox providers now expect authenticated mail, so your legitimate messages are more likely to reach inboxes
- A published, enforced DMARC policy reduces the usefulness of your name to scammers
Deploying in a safe order
The risk with DMARC is blocking your own legitimate mail, such as a billing platform, a marketing system or a scanner that sends on your behalf. A careful rollout avoids that.
- Inventory every sender. List the systems that send email using your domain: Microsoft 365 or Google Workspace, practice management billing emails, e-signature, newsletters, scan-to-email devices, website forms and any application alerts.
- Publish SPF. Include each authorized sender. SPF has technical limits, including a cap on lookups, so keep the list tidy.
- Enable DKIM for your main mail platform and for each third-party sender that supports it.
- Publish DMARC in monitoring mode. Use a policy of none, with a reporting address. Collect reports for several weeks.
- Read the reports. Use a reporting tool or your IT provider's service, as the raw files are hard to read. Identify legitimate senders that fail, and fix them.
- Move to quarantine, then reject. Increase gradually. Many firms use a percentage setting to phase in enforcement.
- Maintain it. When you add a new software service that sends email, add it to the process.
Common mistakes
- Publishing multiple SPF records for the same domain, which breaks the check
- Ending SPF with an overly permissive setting that allows anyone
- Forgetting a third-party sender and having its mail rejected after enforcement
- Never moving beyond monitoring mode
- Ignoring subdomains and parked domains that you do not send from, which should have a reject policy
- Assuming it protects against lookalike domains, which it does not
Complementary protections
Authentication covers your own domain. For threats from lookalikes and compromised third parties, also use:
- Impersonation protection in your email security tool
- Alerts for newly registered domains resembling yours, and consider registering obvious variants
- External sender banners
- Staff training and a call-back procedure for payment changes
How to check where you stand
Ask your IT provider to look up your domain's current SPF, DKIM and DMARC records, and to tell you the DMARC policy in effect. If it says none, or no record exists, the work above remains to be done. Many free lookup tools can display the same information.
Support from Counsel Cyber
We inventory senders, configure the records and manage the move to enforcement for law firms, so you gain protection without losing legitimate mail. Ask us for a domain check.