ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Stopping Spoofing of Your Law Firm's Domain with Email Authentication

Email authentication stops criminals from spoofing your firm's domain. Learn what SPF, DKIM and DMARC do and how to roll them out without breaking your email.

3 min readBy Counsel Cyber Team

Criminals frequently send fraudulent emails that appear to come from a law firm's own domain, either to clients, who are told to wire money to a new account, or to the firm's own staff. Three email authentication standards, SPF, DKIM and DMARC, make this kind of spoofing much harder. They are inexpensive, mostly a matter of DNS configuration, and increasingly expected by mail providers and cyber-insurance questionnaires. Yet many firms have them only partly set up.

This explainer covers what each does and how to deploy them carefully.

What each standard does

SPF

Sender Policy Framework lets you publish a list of servers allowed to send email for your domain. Receiving servers check whether a message came from an authorized source. If your firm uses Microsoft 365, a marketing platform and a billing system that sends invoices, each should be included in the SPF record.

DKIM

DomainKeys Identified Mail adds a cryptographic signature to outgoing messages. The receiving server uses a public key published in your DNS to verify that the message was really sent by your domain and was not altered in transit.

DMARC

Domain-based Message Authentication, Reporting and Conformance builds on both. It tells receiving servers what to do when a message fails SPF and DKIM checks that align with the visible From address: nothing, quarantine it, or reject it. It also asks receivers to send you reports, which show who is sending email using your domain, legitimately or not.

Why it matters to a law firm

  • Protecting clients. A client who receives a message appearing to come from your domain, containing altered wire instructions, may trust it. With enforcement, many receiving servers will reject the fake.
  • Protecting your own staff from spoofed internal messages.
  • Deliverability. Major mail providers have tightened requirements for senders, and properly authenticated mail is more likely to reach inboxes.
  • Insurance and client expectations. Questionnaires increasingly ask whether DMARC is enforced.

Authentication does not stop every attack. It does not stop lookalike domains, such as a name with one letter changed, nor a compromised legitimate mailbox. It is one layer among several.

A careful rollout

The main risk is breaking legitimate email, so go in stages.

Step 1: Inventory every sender

List every system that sends email as your domain: Microsoft 365 or Google Workspace, practice-management software, billing and e-signature tools, newsletter platforms, website forms, scanners and copiers, and any third-party vendors. Missing one is the usual cause of problems.

Step 2: Publish SPF correctly

Create one SPF record that includes all legitimate senders. A domain should have a single SPF record, and there is a limit on the number of DNS lookups it may trigger, so keep it lean. End with an appropriate policy for unauthorized senders.

Step 3: Enable DKIM

Turn on DKIM signing in your mail platform and for each third-party sender that supports it. Publish the keys in DNS as instructed.

Step 4: Start DMARC in monitoring mode

Publish a DMARC record with a policy of "none" and a reporting address. This does not block anything, but it begins collecting reports. Use a reporting service or your IT provider to read them, since the raw reports are difficult to interpret.

Step 5: Fix what the reports reveal

Review for several weeks. Fix any legitimate sender that fails authentication, and identify unfamiliar sources.

Step 6: Move to enforcement

Progress to "quarantine," then to "reject," once legitimate mail passes consistently. Many firms move gradually, for example by applying the policy to a percentage of messages at first.

Step 7: Do not forget other domains

Secure parked or unused domains by publishing records that say no mail should be sent from them. Attackers can spoof these as readily as your main domain.

Pitfalls

  1. Having more than one SPF record
  2. Adding a new vendor without updating DNS
  3. Staying at "none" indefinitely and thinking the job is done
  4. Not monitoring reports
  5. Forgetting subdomains

Pair it with other controls

Authentication works best alongside MFA on every mailbox, email filtering that flags lookalike domains and external senders, alerts for suspicious forwarding rules, and a callback procedure for any payment instruction. CISA and the FBI both recommend a layered approach to business email compromise.

Maintenance

Review your records when you adopt or retire a system. Check DMARC reports monthly, and confirm after any email migration that signing is still active.

Counsel Cyber configures and monitors email authentication for law firms, and can review your current records in a short assessment. If you are unsure what your domain publishes today, we can check it with you.