DMARC Engine
Home/For law firms
For your sector

DMARC for law firms

Conveyancing and settlement fraud start with a spoofed email. Enforced DMARC stops anyone sending mail as your firm, protecting client funds and your reputation.

Law firms move money in the exact way fraudsters love: large sums, on a deadline, between parties who have never met, on the strength of an email. A completion payment, a settlement, money held in escrow or on client account, all of it can be redirected by a single convincing message that appears to come from your firm or from the other side. When the From address genuinely reads conveyancing@yourfirm.co.uk, nobody on the receiving end doubts it. This page explains why law firms and conveyancers are a favourite target, how the attack works, why a p=none DMARC record stops none of it, and how enforced DMARC closes the door, safely and with no email outage.

Why law firms and conveyancers are a favourite target

Fraudsters target where money moves and trust is high, and few businesses concentrate both as sharply as a law firm. On a routine matter you are dealing with:

  • High-value, time-critical transfers, completion funds on a property purchase, settlement sums, escrow releases, where the amount is known to the attacker and the deadline is real.
  • Counterparties who correspond almost entirely by email and rarely meet in person, so a message about where to send funds looks entirely normal.
  • Confidential client data, financial details, identities, transaction histories, that makes a convincing forgery easy to assemble.
  • A culture of acting on written instructions promptly, because delay in a transaction has real consequences.

That is close to an ideal environment for the attacker. The well-known version, often called conveyancing or completion fraud, is depressingly simple: a criminal sends a buyer, or the buyer's solicitor, an email that appears to come from the firm, saying "our bank details have changed, please send the completion funds to this account instead". The money is sent, it disappears, and the question of who bears the loss becomes a long and bitter dispute. The deposit or completion sum on a single property transaction is frequently a six figure amount, and the attacker's marginal cost is close to nothing.

The uncomfortable starting point. If your firm's domain has no DMARC record, or one stuck at p=none, a criminal can send an email that genuinely shows your firm's address in the From line. Nothing on the recipient's side will flag it. The forged "new bank details" email looks exactly like the real one.

The specific attack, step by step

This is not a technical exploit. It is patient, human, and cheap, which is why it keeps working. A typical sequence against a conveyancing matter runs like this:

  1. The attacker identifies a live transaction. Property transactions are partly public, and a criminal who has compromised one party's mailbox, or simply guessed who is acting, knows roughly when completion is due and how much is moving.
  2. Near completion, they send a message that appears to come from your exact domain, or from the firm on the other side, saying the account for the funds has changed and giving new details.
  3. Because the From address is genuinely conveyancing@yourfirm.co.uk, the letterhead and signature are right, and the timing fits the transaction, it clears the human filter. Urgency, "we need this before completion today", discourages the recipient from telephoning to verify.
  4. The funds go to an account the attacker controls, are moved on within hours, and are effectively unrecoverable by the time the substitution is noticed.

The damage runs in both directions. A fraudster can spoof your firm to redirect a client's funds, or spoof a client or counterparty to instruct you. Either way, your firm is dragged into the aftermath, because the money was moving through your transaction and, often, in your name.

Why p=none does not stop any of this

Many firms assume they are protected because they "have DMARC". What matters is not whether you publish a record, but what policy it enforces. There are three values, and only two block anything:

  • p=none tells receiving mail servers to take no action and just send you reports. It blocks nothing. A spoofed completion-funds email under p=none is delivered exactly as if you had no DMARC at all.
  • p=quarantine tells receivers to divert failing mail to the spam folder.
  • p=reject tells receivers to refuse failing mail outright, before it reaches the inbox.

The vast majority of domains that publish DMARC sit at p=none. It feels safe and reports neatly, and it stops nothing. A firm at p=none is watching its own impersonation after the fact: the reports tell you a forged email went out in your name, but only once the client has already received the fraudulent bank details. To stop the forgery at the recipient's mail server, the policy must reach p=quarantine or p=reject. The full mechanics are on our invoice and payment-redirection fraud page.

How enforced DMARC stops the exact-domain attack

DMARC works by combining three checks at the recipient's mail server, before a human reads the message:

  • SPF checks whether the sending server appears on a list your domain publishes.
  • DKIM attaches a cryptographic signature, verified against a public key at selector._domainkey.yourfirm.co.uk, proving the message was authorised by your domain and not altered in transit.
  • Alignment is the part that defeats spoofing. DMARC requires that the domain which passed SPF or DKIM matches the domain shown in the visible From address. An attacker can make their own server pass SPF for their own domain, but they cannot make it align with yourfirm.co.uk, because they do not hold your DKIM private key and your domain has not authorised their server.

Once your domain publishes v=DMARC1; p=reject; rua=mailto:reports@yourfirm.co.uk, a forged message claiming to be from your firm fails alignment and is refused by Gmail, Yahoo, Outlook and every other receiver that honours DMARC. The fraudulent "new account for completion funds" email from conveyancing@yourfirm.co.uk never lands in the inbox. The check runs automatically, on the recipient's side, for every message claiming to be you.

What enforced p=reject stops, and what it does not.
Stops: any message that puts your exact domain in the From address and cannot authenticate as you. The forged completion-funds email from conveyancing@yourfirm.co.uk, the fake partner instruction sent from your real domain, and bulk phishing that abuses your firm by spoofing your exact domain.
Does not stop: lookalike domains (yourfirm-legal.co.uk), display-name tricks ("Your Firm Conveyancing" over a Gmail address), or a genuinely compromised mailbox where the attacker has logged in and sends authenticated mail from inside. Those need monitoring, process and training alongside DMARC. We set out that split honestly on the invoice fraud page.

Reaching enforcement without an email outage

The fear that keeps firms at p=none is that tightening the policy will block their own legitimate mail, the case management system, the e-signature platform, the accounts package, the marketing newsletter. It is a reasonable fear, and avoiding exactly that outcome is the point of our process. We never jump blindly to p=reject. We move in monitored stages:

Monitor (p=none)
Gather aggregate reports, find every system sending mail in your name, confirm the legitimate ones align
Quarantine
Tighten once the legitimate pass rate sits at effectively 100%, holding to confirm nothing real is junked
Reject
Move only when the pass rate is proven stable, so forgeries are refused while your mail is untouched
Typical timeline
Around a few weeks, paced to your senders, never rushed

Because your legitimate mail passes authentication at every stage, tightening the policy is invisible to your clients, your counterparties and your own fee-earners. The only people who notice are the criminals forging your domain, and what they notice is that it stopped working. The full journey, and why every step is reversible with a single DNS edit, is on our guide to reaching enforcement. The audit shows what we find first: your current policy and every sender we can see.

No drama, by design. Staged enforcement, with reports in front of you the whole way, is low-risk and reversible. We hold at quarantine until your legitimate pass rate is proven, then change a single word to reject. Your case management mail, client updates and completion statements keep flowing exactly as before.

The compliance, insurance and client-care angle

Stopping fraud is the headline, but authenticated email is increasingly expected of a law firm in its own right, and the pressure comes from several directions:

  • Professional and regulatory expectations. Firms are expected to protect client money and confidential data with reasonable technical controls. Enforced email authentication is now a recognised part of that, and the Law Society and others have long warned the profession specifically about conveyancing and completion fraud.
  • Cyber-insurance. Professional indemnity and cyber insurers increasingly ask whether you enforce email authentication. A truthful "yes, at p=reject" is a far better answer at renewal, and after an incident, than "we publish DMARC but it does nothing".
  • Bulk-sender rules. Google and Yahoo's requirements, in force since 1 February 2024, and Microsoft's tightening for high-volume senders to Outlook.com, Hotmail and Live, all assume genuine authentication, which matters for firms sending client updates at volume.
  • PCI DSS 4.0. Requirement 5.4.1 made anti-phishing controls mandatory from 31 March 2025, relevant wherever your firm or its clients touch card payments.

What assessors and insurers actually look for is set out on our compliance and cyber-insurance page. The short version: when a transaction goes wrong and the question becomes who took reasonable care, a firm that can evidence enforced DMARC is in a markedly stronger position than one that left its domain open to spoofing.

In a completion-fraud dispute, the firm that left its own domain spoofable is the firm that handed the criminal its credibility. Enforced DMARC is how you take that weapon off the table before the money moves.

What we set up and host for you

This is a done-for-you service, not a tool you have to operate. We take your firm's domain from wherever it is today through to enforced p=reject, and we host the underlying records so they stay correct: DMARC, SPF, DKIM, MTA-STS and BIMI. We ingest your aggregate (RUA) reports so monitoring is continuous rather than a one-off check, and we hold your policy at each stage only until the reports confirm it is safe to advance. The full scope is on the products page, and common questions are answered on the FAQ.

The pricing is deliberately simple: a flat one-time enforcement fee, currently an introductory £200 (normally £500), plus monitoring at £19/month (normally £39). One fee to reach enforcement, a small monthly fee to keep you there and watch the reports.

Where to start

Begin by finding out whether your firm's domain can be spoofed right now. Our free tools check whether you publish DMARC, whether it is at p=none or actually enforcing, and whether your SPF and DKIM align. If your record reads p=none, or you have no record, a forged completion-funds email from your firm will reach a client's inbox today. The requirements page shows what we need from you, usually very little, and the path to enforcement shows how we reach p=reject without catching your own mail.

When you are ready, you can sign up here. Conveyancing and settlement fraud succeeds because it abuses trust the firm has spent years building, and it strikes at the single moment when the most money is in motion. Enforced DMARC takes your own domain off the table as a weapon against your clients, automatically and at the inbox. It does not solve every form of fraud, but it shuts the door criminals reach for first, and for a law firm that door opens onto someone's house deposit.

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.