Email Security
Stop fake emails from being sent as your firm.
Email impersonation is one of the most common ways law firms are targeted. We configure the controls that prevent spoofing, restrict hidden forwarding, and document the result for clients and cyber insurers.
What we address
The email risks most firms overlook.
Spoofed email
Without SPF, DMARC, and DKIM, attackers can send messages that appear to come from your firm.
Hidden forwarding rules
Attackers who compromise a mailbox often set silent forwarding rules. We audit and restrict them.
Weak impersonation controls
We turn on the Microsoft 365 protections that flag or block impersonation of partners and staff.
Included
What we configure
- SPF, DMARC, and DKIM configuration and tuning
- DMARC policy progression guidance (none → quarantine → reject)
- Microsoft 365 anti-phishing and anti-spoofing policy review
- Mailbox forwarding rule audit and restriction
- External sender banner and safety tip configuration
- Before-and-after evidence for each change
- Plain-English summary for partners and insurers
Deliverables
What you receive
- Updated email authentication records
- Configuration evidence screenshots and reports
- One-page security summary
- Recommendations for ongoing monitoring
Availability
Email hardening is included in Tier 2 — Internal Continuous and Tier 3 — Full Baseline Continuous. It can also be scoped as a standalone one-time service.
Free check
See whether your domain can be spoofed
The free Proprietary Exposure Review shows your SPF, DMARC, and DKIM status in minutes.
