Security
SPF, DKIM, and DMARC in Plain English: Stopping Spoofed Law Firm Email
Three DNS records decide whether criminals can send mail that looks like it came from your firm. Many small firms have at least one of them wrong.
Law firms move money and trust through email. Closing instructions, settlement disbursements, retainer payments, and escrow releases all start with a message that the recipient believes came from the firm. That makes a law firm's domain name valuable to criminals. If they can send email that appears to come from yourfirm.com, they can redirect a wire before anyone notices.
Three email authentication standards, SPF, DKIM, and DMARC, exist to make that harder. They are configured in the firm's DNS, they cost nothing to publish, and they are routinely missing or misconfigured on small firm domains. Here is what each one does and how to roll them out without breaking legitimate mail.
SPF: who is allowed to send
Sender Policy Framework is a DNS record that lists the servers and services permitted to send mail for your domain. Microsoft 365 or Google Workspace is usually on it, but so are the services people forget: the practice management system that emails invoices, the e-signature platform, the marketing newsletter tool, the website contact form.
When a receiving server gets a message claiming to be from your domain, it checks whether the sending server is on that list. A common failure is a record that grew by accretion over the years, with old vendors still authorized and the DNS lookup limit exceeded, which can cause SPF to fail for everyone.
DKIM: a signature on every message
DomainKeys Identified Mail adds a cryptographic signature to each outgoing message. The receiving server uses a public key published in your DNS to confirm the message was signed by an authorized system and was not altered in transit. Each sending service, including your mailbox provider and each third-party tool, needs its own DKIM setup, and it is common to find a firm where the main mailbox signs correctly and two or three other services do not.
DMARC: the policy that ties them together
Domain-based Message Authentication, Reporting and Conformance tells receiving servers what to do when a message claiming your domain fails authentication, and it asks them to send you reports about what they saw. The policy has three settings: none (monitor only), quarantine (send failures to spam), and reject (refuse them).
A DMARC record at p=none provides visibility but no protection. Spoofed messages still get delivered. Many firms published p=none at some point, never read the reports, and never moved forward.
Why the bulk sender rules matter even to small firms
Starting February 1, 2024, Google required everyone sending to Gmail accounts to use SPF or DKIM, and required bulk senders (those sending roughly 5,000 or more messages a day to Gmail accounts) to use both, publish a DMARC record, and offer one-click unsubscribe for marketing mail. Yahoo announced parallel requirements. A small firm is unlikely to be a bulk sender, but those rules signaled how large mailbox providers now treat unauthenticated mail generally. Firm newsletters, invoice emails, and client updates sent through misconfigured services are more likely to land in spam or be refused.
Moving from p=none to enforcement safely
The safe sequence is straightforward. First, publish DMARC at p=none with a reporting address, ideally routed to a reporting service that turns the raw XML into something readable. Second, spend a few weeks reading the reports and identifying every legitimate service that sends as your domain. Third, fix SPF and DKIM for each of those services until the legitimate traffic passes consistently.
Then move to p=quarantine, optionally applied to a partial percentage of mail at first, and watch for complaints that real mail is landing in spam. When the reports are clean, move to p=reject. Keep reading reports afterward, because the next new vendor someone signs up for will need to be added. Do not forget domains the firm owns but does not use for email. They should publish records stating that no mail is sent from them, so they cannot be spoofed either.
Authentication does not replace a payment verification process
DMARC stops exact-domain spoofing. It does not stop lookalike domains (yourfirrn.com instead of yourfirm.com) or a genuinely compromised mailbox, where the criminal is sending from your real account. Wire fraud defense needs a process control as well as a technical one.
The control is out-of-band verification. Before any wire is sent, and any time wiring instructions change, confirm the instructions through a channel established independently of the email, such as a phone number already on file, never the number in the message asking for the change. Tell clients in writing at the start of the engagement that the firm will never change wire instructions by email. Make the rule apply to staff and attorneys alike, with no exceptions for urgent closings, because urgency is the tool the fraud relies on.
Next step
Checking SPF, DKIM, and DMARC on every domain the firm owns takes minutes and is part of the LexAIAdvisors security and uptime review. If you would like a readout of where your domains stand and a staged plan to reach enforcement, request an audit at /audit.
Source note
This LexAIAdvisors article summarizes and comments on public legal-industry developments. Source: Google Workspace Admin Help: Email sender guidelines.
LexAIAdvisors is not your lawyer and does not provide legal advice. This article is informational and is intended for law-firm operations, compliance, and workflow planning.