Email protection
Email & Microsoft 365 Security for Law Firms
Email security for law firms is for firms that need domain authentication hardened and selected Microsoft 365 mailbox controls checked without replacing their existing IT provider. DNS and mail-flow work uses the firm's authorized domain access; mailbox checks are performed only within the agreed scope and authorization.
Law firms move money by email. That makes fake wire instructions and fake partner requests especially dangerous.
Attackers usually do not need to break into your systems. They only need a message that looks close enough to your firm for one person to trust it.
If your MSP runs email day to day, we focus on the controls that stop spoofing, not on ticket handling.
If you want a narrower fix, see our fixed-price one-time services or start with the free Zero-Access Exposure Review™ and we will show you what the public internet already sees. The full services overview is on the services page.
The problem
A few settings can stop most spoofing before it reaches clients.
Without the right email settings, anyone on the internet can send a message that appears to come from your firm. The recipient sees a message that looks legitimate because nothing tells their email system to distrust it.
Many firms have partial protection and think they are done. A DMARC setting of p=none only reports suspicious messages; it does not block them. That can look complete on paper while doing very little in practice.
Money moved by wire fraud is often unrecoverable. The loss is not only the client's money. It is the firm's relationship, reputation, and the question of why obvious email controls were never enforced.
DMARC reduces direct spoofing of your firm's domain. It does not stop lookalike domains, compromised accounts, display-name tricks, or every impersonation attempt, so verification and authorized mailbox checks still matter.
What we do
Four steps, staged so the fix does not break the firm.
Step 1
Assess
We inventory every service currently sending mail on your firm's behalf: the mail platform, practice management system, e-signature vendor, billing platform, marketing tools, and any legacy relay.
This inventory is where most DMARC projects fail, because enforcement without it blocks legitimate mail.
Step 2
Configure
SPF is corrected and consolidated, DKIM signing is enabled on every sending service, and DMARC is published in monitoring mode with reporting enabled.
That gives us the baseline before we ask a receiving server to start rejecting anything.
If mailbox forwarding or account controls are in scope, we coordinate the required authorized access with the firm's administrator or existing IT provider.
Step 3
Monitor
We review aggregate DMARC reports for a 60-day observation window, identify every legitimate sender not yet authenticated, and correct the gaps as we go.
This takes 60 days rather than an afternoon because enforcement too early can break firm email, and firms that experience that usually roll it back and never try again.
Step 4
Enforce
DMARC is moved in stages to quarantine, then to full reject, with verification at each step.
The result is a policy that blocks spoofing without disrupting the mail your firm actually needs.
What you receive
Proof that the protection is working.
- Full inventory of authorized sending services
- SPF, DKIM, and DMARC configured through a staged path to enforcement
- Before and after evidence of authentication status
- A one-page summary suitable for cyber insurance applications and client security questionnaires
- Lookalike domain findings with a defensive registration priority list
- Written handoff documentation for the firm's IT provider
Who this is for
Use this when email is part of the firm's money movement.
This is a good fit if
- Your firm sends wires, closings, or settlement instructions by email.
- You have more than one system sending mail on your behalf.
- You need evidence that clients and insurers can understand quickly.
- You want the problem fixed in a staged way instead of a rushed DNS change.
This is not the right service if
- You only need a one-time SPF, DKIM, or DMARC setup and do not want a 60-day rollout.
- You are not prepared to inventory every legitimate sender before enforcement.
- You want passive monitoring only and do not want the policy moved to reject.
Pricing and timeline
Single domain, 60 days to enforcement.
$1,450 for a single domain, with a 60-day path from start to enforcement. Additional domains are $295 each.
Pricing shown is for firms of 1 to 10 users. Firms with 11 to 25 users add 40 percent. Firms with 26 to 50 users add 80 percent.
Final scope and price are confirmed in writing before work begins. The price changes when the sender inventory is larger, additional domains need hardening, or the rollout requires more than one domain owner to be coordinated.
Frequently asked questions
The questions partners ask before they sign.
Microsoft 365 or Google Workspace. Email authentication, mailbox rule audits, and domain cleanup work the same either way. Our deeper tenant-hardening engagements are Microsoft 365 today – if you’re on Workspace, tell us and we’ll scope the equivalent.
DMARC is a DNS record that tells receiving mail servers what to do with messages that claim to come from your domain but fail authentication. Without it at enforcement, anyone can send email that appears to come from your firm. For any firm that handles client funds, communicates about closings, or sends wire instructions, it is the single highest-value email control available.
Many can configure the records. The difficulty is not the configuration – it is the sender inventory and the staged rollout. Enforcement deployed without a complete inventory of every service sending mail on your behalf will block legitimate firm email, usually from the practice management or e-signature platform. That is why so many firms have a DMARC record permanently stuck in monitoring mode.
Not if it is done in stages. We publish the record in monitoring mode first, watch 60 days of real mail flow, authenticate every legitimate sender we find, and only then move to enforcement. The staged approach exists specifically to prevent that outcome.
About 60 days from start to full enforcement. Most of that is the monitoring window, which cannot be compressed without accepting the risk of blocking legitimate mail. Configuration work is a small part of the calendar time.
SPF lists which servers are permitted to send mail for your domain. DKIM adds a cryptographic signature proving a message was not altered in transit. DMARC ties them together, tells receiving servers what to do when a message fails, and sends you reports on what is being sent in your name. All three are required; DMARC is what makes the other two enforceable.
Microsoft 365 configures SPF and DKIM for its own sending, but it does not publish a DMARC enforcement policy for you, and it has no knowledge of the other services sending mail on your firm's behalf. The default state of a new tenant is not protected.
A domain registered to resemble yours closely enough to pass a quick glance, using a substituted character, an added word, or a different extension. Attackers register these ahead of a targeted wire fraud attempt. Registration of a lookalike is often the earliest warning a firm gets, and it is visible in public records before any email is sent.
Related services
If you need a different starting point, these pages may help.
Free check
See whether your domain can be spoofed
2 minutes. No internal access. No passwords.
The free Zero-Access Exposure Review™ shows your SPF, DMARC, and DKIM status in minutes.
