How Law Firm Email Spoofing Puts Clients at Risk
Law firm email spoofing begins with public DNS records and lookalike domains. Learn how attackers impersonate attorneys and what stops a client from wiring money to the wrong account.
Blog post - By Securing Your Law Firm
Get your free Zero-Access Exposure Review™ | See Email & Sign-In Security
A client receives a wire instruction with the closing details. The email address matches their attorney's exactly. The tone feels familiar. The urgency feels right, because closings are always urgent. They send the funds. The money is gone.
This is how law firm email spoofing works in practice. It does not require a breached server, a compromised password, or an intrusion into the firm's network. It usually begins with public DNS records, a trusted relationship, and a client who is moving quickly.
For law firms, the risk is especially high. Clients trust their lawyers with sensitive information and high-value payment instructions. Many firms assume their domain is already protected, yet missing or weak email authentication remains common across professional services firms. The same outside-in signals attackers query are exactly what the free Zero-Access Exposure Review™ checks.
In this article
- How attackers profile a firm before sending anything
- Why legal clients are so susceptible to spoofed wire instructions
- What controls actually stop the scam before money moves
How law firm email spoofing starts with public DNS records
Attackers do not start by writing a convincing email. They start by reading the firm's DNS records. That reconnaissance phase is the part most attorneys never think about, and it is where the attack plan begins.
What public DNS records expose about your domain
SPF, MX, and DMARC records are public. Anyone with a terminal and a basic understanding of DNS can query them. An attacker can quickly determine whether email authentication is configured. A missing DMARC record, a broken SPF record, or missing DKIM signing sends a clear signal: this firm is easier to impersonate than it should be.
The problem is not theoretical. Research from the Global Cyber Alliance and other security bodies has consistently shown that many domains lack enforced DMARC policies, which leaves them exposed to exact-domain spoofing. For a law firm, that public exposure is effectively an open invitation.
If you want the practical mechanics of a lookalike domain, read What Is a Lookalike Domain? Why Your Law Firm Should Be Concerned.
Certificate transparency logs and WHOIS as reconnaissance tools
Certificate transparency logs expose SSL certificates issued for a domain and its subdomains. Attackers use those records to find internal hostnames, mail infrastructure, and related domains the firm may operate. WHOIS records confirm registration history and often reveal the registrar, which helps attackers build convincing look-alike domains that pass a quick visual inspection on a mobile screen.
Why this starts with weak or missing authentication
Firms with no DMARC policy, broken SPF records, or missing DKIM signing are selected precisely because their infrastructure signals low resistance. This is not random targeting. Attackers query dozens of firm domains and prioritize the ones where the authentication posture is weakest.
From a legal-risk perspective, a weak DNS posture is not just a technical deficiency. It is a business exposure.
How a convincing spoofed attorney email is built
Once the reconnaissance is done, the attacker builds the fake. The techniques used against law firms in 2026 are more sophisticated than most attorneys expect, and several of them do not require a weakness in the firm's own domain to succeed.
Look-alike domains and the one-character swap
Attackers register domains that differ from the firm's real domain by a single character: a transposed letter, a substituted "rn" for "m," an added hyphen, or a different top-level domain. These look-alike domains pass a quick glance, especially in mobile email clients where the full address is truncated.
Because they are separately registered, real domains, even a firm with perfect DMARC on its legitimate domain still has no protection against a look-alike campaign. Email authentication only helps when the attacker is sending from your actual domain. It does not stop a convincing counterfeit domain from being used beside it.
Display name spoofing and header manipulation
Attackers can pair a legitimate-looking display name, such as "John Smith, Esq.," with a completely different sending address. Most email clients show only the display name by default, not the underlying routing address. Header-level manipulation pushes the visible "From" field to show a trusted name while the actual message originates from an unrelated domain.
This technique exploits how people read email, not any weakness in the firm's technical configuration.
Thread hijacking: the hardest spoof to catch
When attackers gain access to a single compromised account, they can reply inside an existing real conversation thread. The spoofed message inherits the full history of legitimate attorney-client exchanges, making a fraudulent wire instruction look like a natural continuation of an ongoing matter.
Thread hijacking is where business email compromise becomes nearly indistinguishable from legitimate communication. That is also why account security and MFA matter alongside email authentication controls.
For a more detailed breakdown of how spoofing turns into payment fraud, see How Law Firms Get Hit by Wire Fraud – Even When No One Was Hacked.
Why law firm clients are such effective targets
The technical mechanics explain how spoofing works. This section explains why it works so well against legal clients specifically, and why the financial stakes are higher than in most other industries.
The attorney-client relationship is built on trust and deference
Clients are conditioned to trust communications from counsel. They rarely second-guess an email from their lawyer about a wire transfer deadline or a change in payment routing. The professional credibility built over months of a legal engagement becomes the attack vector itself.
An attacker impersonating an attorney is not fighting skepticism. They are riding a current of established trust that took the firm years to build.
High-value transactions and deadline pressure create the perfect conditions for fraud
Real estate closings, settlement disbursements, trust account distributions, and M&A transaction costs all move through attorney-client communication. The FBI's IC3 2025 Internet Crime Report showed BEC complaints averaged roughly $122,900 in losses per incident, and law firms handling high-value transactions represent the upper end of that range.
Attackers time spoofed legal notices and fraudulent wire instructions around real transaction deadlines because urgency is already a feature of legal practice. When a closing is tomorrow and the wire instruction arrives today, clients act. That pressure is exactly what impersonation attacks are designed to exploit.
Preventing law firm email spoofing with SPF, DKIM, and DMARC
These controls form the technical foundation of any serious spoofing prevention effort. Understanding what each one does, and what each one does not do, is essential before a firm chooses where to invest.
What SPF, DKIM, and DMARC each do and why all three matter
SPF tells receiving mail servers which IP addresses are authorized to send email for the firm's domain. DKIM adds a cryptographic signature to outgoing messages that receivers can verify against a public key in DNS. DMARC ties both together: it tells receiving servers what to do with mail that fails authentication, and it sends aggregate reports back to the domain owner so the firm can see exactly who is sending email in its name.
None of these controls is optional. SPF without DMARC enforcement gives receivers no instruction on what to do with unauthenticated mail. DMARC without DKIM leaves an authentication path open to failure, because DKIM alignment is required for DMARC to function reliably when SPF alignment breaks down.
Moving from p=none to p=reject without breaking legitimate mail
The phased approach matters. Start with `p=none` to collect DMARC aggregate reports without affecting delivery. Inventory every system that sends mail as the firm's domain, including Microsoft 365, billing platforms, practice management tools, and any marketing or vendor services. Fix alignment issues for each sender, then move to `p=quarantine`, and finally to `p=reject` once reports confirm no legitimate mail sources are failing authentication.
Skipping steps is how firms accidentally block their own outbound mail, or stall at `p=none` indefinitely, which gives the appearance of having DMARC configured while offering little protection against spoofing.
What email authentication does not protect against
Be clear about this: DMARC at `p=reject` stops exact-domain spoofing. It does not stop look-alike domains, display-name spoofing, or phishing sent from compromised legitimate accounts. Law firm email security requires a layered approach. Authentication is necessary, but it is not complete protection.
Supplementary controls, including inbox-rules audits, forwarding checks, and staff verification procedures for wire instructions, address the attacks DMARC cannot stop.
Detecting active law firm email spoofing and responding when it is confirmed
Prevention is the goal, but detection and response matter when something slips through. Many firms discover spoofing only after a client reports a suspicious message or after funds have already moved.
Signals that your domain is being spoofed right now
DMARC aggregate reports showing unauthorized sending sources are the clearest early indicator. Other signals include client reports of suspicious emails that appear to come from the firm, unusual bounce-back messages arriving in the firm's own inbox, and certificate transparency alerts for look-alike domains registered close to the firm's real domain.
Many firms lack continuous monitoring of these channels, which means the first sign of an active attack is often a phone call from a defrauded client rather than an internal alert.
Immediate steps when business email compromise is confirmed
The response sequence matters as much as speed. Verify the incident before taking disruptive action. Then isolate compromised accounts without wiping evidence, preserve logs, email headers, and audit trails, and contact the bank immediately if wire fraud is possible.
Initiating a recall request is one of the most time-sensitive financial steps in any BEC response, and banking guidance from FinCEN and the FBI consistently emphasizes acting within hours rather than days. Engage breach counsel early to protect privilege over the investigation, then reset credentials and revoke active sessions for affected accounts.
Client notification after a spoofing or BEC event
The initial client notice should confirm an incident occurred, describe the potential exposure honestly without overstating what is known, and give clear instructions: verify any payment instructions by phone using a number already on file, and contact the firm immediately if funds have already moved.
The language of any client notice should be reviewed by outside counsel before it goes out. That protects privilege and helps the firm satisfy its confidentiality and notification obligations under the applicable ethics rules.
Finding your firm's email spoofing exposure before an attacker does
Knowing the attack methods is useful. Knowing your firm's actual exposure is what makes action possible. A public-facing exposure review examines the same signals an attacker would query without requiring access to the firm's systems.
What a public-facing exposure review actually checks
The free Zero-Access Exposure Review™ from Securing Your Law Firm covers the same public signals any attacker would query: DNS records for SPF, DKIM, and DMARC configuration, MX record setup, certificate transparency logs for look-alike domains, and other publicly visible indicators that the firm's domain can be impersonated.
None of this requires access to the firm's systems, passwords, or internal infrastructure. Everything reviewed is already visible to anyone motivated to look.
Why this matters even if the firm already has IT support
The common objection is that the MSP or IT provider already handles this. General IT providers configure email delivery. They rarely audit the firm's email authentication posture through the lens of legal-risk security, and they are not usually asking whether a firm's domain is being actively profiled for an attorney impersonation campaign.
The Zero-Access Exposure Review™ is designed to surface the spoofing vulnerabilities that general infrastructure support usually leaves unchecked, with findings delivered in plain language that attorneys and firm managers can act on without a technical translator.
Closing the gap before the next spoofed email goes out
Law firm email spoofing succeeds because it operates in the space between what attackers know about a firm's domain and what the firm knows itself. The reconnaissance is quiet. The fake message arrives in a trusted inbox. The client acts. By the time anyone realizes something is wrong, the financial damage is already underway.
The controls covered here are not complicated in isolation: enforced email authentication, a known-phone verification process for payment changes, and monitoring for look-alike domains. What most firms lack is a clear picture of their current exposure before they know what to fix. That gap is exactly where attackers operate.
The free Zero-Access Exposure Review™ from Securing Your Law Firm starts with that picture: a scan of the public signals attackers already use to profile your domain, with findings framed in legal-risk language rather than technical jargon. There is no system access required, no commitment to anything beyond understanding your exposure, and no report emailed out. The only email retained is the work inbox that requested the review, and the submitted domain is kept only during the verification window before it is removed.
That is the practical difference between a generic technical check and a legal-risk review: the goal is not to collect more data. It is to give a firm a clear view of what attackers can already see before a client ever receives a spoofed wire instruction.
Next articles to read
If your firm is dealing with a spoofed email, the next questions are usually the same: Is this a lookalike domain problem, a wire-fraud workflow problem, or both? These articles build on the same legal-risk themes and are worth reading in order:
- What Is a Lookalike Domain? Why Your Law Firm Should Be Concerned — how attackers create nearly identical domains that fool busy clients and staff.
- How Law Firms Get Hit by Wire Fraud – Even When No One Was Hacked — the payment-fraud playbook behind many BEC incidents.
- A Town Lost $545,000 Over One Swapped Letter in a Domain Name — a real-world example of how one typo can trigger a six-figure payment error.
- What Law Firm Cybersecurity Rules Actually Require – and Where Most Firms Fall Short — how the legal and insurance expectations connect to everyday controls.
Start with a free Zero-Access Exposure Review™
You submit two things: your firm domain and a matching work email. We send a verification link only to that work inbox, and the review runs only after you confirm that you control it.
The report is viewable through the verification link. It is not emailed. The submitted domain is retained only during the verification window, typically up to 60 minutes. The report and scan findings are not saved, and only the requesting work email is retained for follow-up.
If you want to start with the practical next step, visit our free review page or review our email security services.
This article is informational and does not constitute legal or compliance advice.
