Solicitors, conveyancers and the firms who support them

DMARC for UK Law Firms

The morning of a completion is the most valuable hour in the year to impersonate a law firm. Somebody is about to move a life-changing sum on the strength of an email, and the message that redirects it only needs to appear to come from you.

This page sets out what the regulator actually reports about email-borne crime, what the SRA does and does not require, and — carefully — which part of payment diversion fraud DMARC addresses and which parts it leaves entirely untouched.

What the regulator reports

The SRA's own numbers put email at the centre of it.

The Solicitors Regulation Authority published "Risk Outlook report: information security and cybercrime in a new normal" on 1 June 2022. Two sentences in it are worth reading exactly as written, because they are routinely paraphrased into something vaguer.

mail

The headline figure

From the SRA Risk Outlook: "Over 80 percent of all the cybercrime reports we received in 2021 involved email." Not most incidents involving a computer. Most incidents involving a mailbox.

phishing

And what kind of email

The same report describes "phishing and email modification frauds, which make up half of all the cybercrime reports we receive". Half the reported problem is somebody reading, altering or imitating correspondence that a client believes came from their solicitor.

account_balance_wallet

Why it lands harder here

Most sectors lose data to an email fraud. A firm holding client money can lose the money itself, on a day the client has no reason to be suspicious, in a transaction they will only get one attempt at.

Those two quotations are the only statistics on this page and they belong to the SRA. We have not converted them into loss figures or a percentage of firms affected, because the report does not support that. DMARC AI has no affiliation with the SRA.

The honest compliance position

The SRA does not require DMARC. Nobody should tell you otherwise.

We checked the Risk Outlook in full. No SRA rule names DMARC, SPF or DKIM, and none obliges a firm to publish any of them. A supplier implying that a regulator mandates their product is hoping you will not read the source.

What is not there

No named protocol, anywhere

The SRA writes about cybercrime and information security at the level of outcomes and risk, not configuration. It does not publish a technical control list the way some sector requirement documents do, and it does not name an email-authentication standard.

Cyber Essentials does not close that gap either. Its current requirements — v3.3, April 2026, effective 27 April 2026, administered by IASME — cover firewalls, secure configuration, security update management, user access control and malware protection. No DMARC control appears in them.

What is there

A confidentiality duty, and nothing narrower

The SRA Code of Conduct binds solicitors to keep the affairs of current and former clients confidential, at paragraph 6.3. That is a general duty about client information. It is not an email-security requirement and it names no technology.

We are not going to stretch it into one. How that duty applies to your systems is a question for your COLP, your insurer or your own professional adviser, not for a technology vendor's landing page.

balance So why would a firm do it?

Because it is a control you can point to. Not as evidence of meeting a rule that does not exist, but as evidence of having taken a reasonable, documented technical step to protect client confidentiality and client money — dated, and in place before anything went wrong rather than after.

That framing is defensible. "The regulator made us" is not, and it collapses the first time somebody asks which paragraph.

How the fraud actually works

Three different attacks wearing the same disguise.

"Payment diversion fraud" describes an outcome, not a method. Underneath it sit three techniques that arrive looking almost identical to the client and need completely different controls. DMARC addresses exactly one, and being clear about which one is the difference between a useful control and a false sense of security.

account_tree What each one is, and what stops it
Spoofed domain DMARC stops this one. The attacker puts your exact firm domain in the From header of a message they sent themselves. With an enforcing policy published and your senders aligned, receiving mail servers reject or quarantine it before a client sees it.
Compromised mailbox DMARC does nothing here. Somebody has the password to a real account — yours, the estate agent's, the other side's. The message is genuinely from that domain, so it authenticates perfectly and passes every check. This needs multi-factor authentication, conditional access and mailbox rule monitoring.
Lookalike domain DMARC does nothing here either. The attacker registers a name of their own that reads like yours and publishes whatever records they please on it. Your policy has no authority over a domain you do not own. This needs domain monitoring and a human trained to read the address bar.
All three One procedure catches all of them. Verifying bank details by telephone on a previously known number moves the confirmation off the channel the attacker controls. Keep it whatever else you deploy.

Because .co.uk is a public suffix, the organisational domain for example.co.uk is that whole name. A registration such as example-legal.co.uk is a separate domain that can never align with yours, and no record you publish reaches it.

warning Please do not relax the phone call

This is the sentence we most want a managing partner to read. The procedure covers all three attacks; the DNS record covers one. If the record ever becomes an argument for dropping the call, it has done net harm.

visibility What you gain besides blocking

Aggregate reports name every source sending as your domain, including the ones you never authorised. A firm running monitoring learns its name is being used roughly when it starts, rather than when a client rings about an account change.

Who actually gets hurt

Your domain is used on people who never instructed you.

An unprotected firm domain is not only a risk to your own files. It is a usable asset for defrauding anyone in the transaction, most of whom never signed a client care letter and never saw your warnings.

groups

The other side of the transaction

A buyer, a seller, a lender's team, an estate agent, a family member helping with the deposit. They receive mail apparently from your firm and have no basis on which to doubt it.

schedule

The timing is public

Completion dates are known to a dozen people across two firms, two agencies and a lender. An attacker need not guess when money moves, only send one message on the right morning.

description

The format is copyable

Letterheads, signature blocks and the phrasing of a completion statement are stylistically predictable and largely public. Imitation takes no special skill, which is why the sending address is where the check has to happen.

campaign

The reputational half

Even where no money moves, spoofed mail carrying a firm's name reaches clients and referrers. Explaining afterwards that the messages were not yours is harder than stopping them being deliverable.

What goes alongside it

The telephone call is still the control that does the most work.

The official response to payment diversion fraud in the UK is procedural rather than technical, and it has not changed. Nothing on this page is a reason to alter it.

The Law Society's public guidance on payment diversion fraud puts it in two sentences: "Emails can be intercepted or diverted... Check by calling before you transfer money." The same message runs through National Crime Agency and Stop! Think Fraud material aimed at the public.

The two controls do different jobs

  • check_circleThe phone call works from the client's side: confirmation moves onto a channel the attacker does not control, whichever technique was used.
  • check_circleDMARC works from the firm's side: it removes the attacker's ability to put your exact domain in the From header and have the message delivered.
  • check_circleUse a number the client already held — from the client care letter, the website or an earlier call — never one printed in the email asking for the transfer.
  • check_circleTell clients at the outset that your bank details will never change by email, and that any message saying they have is wrong by definition.
  • check_circleRecord which step of the procedure was completed, by whom and when, on the file. That record is worth more afterwards than any DNS screenshot.

Stated plainly: DMARC AI has no affiliation with the SRA, the Law Society, the National Crime Agency or the NCSC, and is not approved, endorsed or accredited by any of them. Nothing here is legal advice or a compliance opinion. Where a professional duty is engaged, take that question to your own regulator, insurer or adviser.

Rollout, and the provider view

A firm has few domains and several forgotten senders.

Compared with a council or a hospital trust this is a small job. The risk is sender count rather than domain count: case management, e-signature, the client portal, an outsourced marketing list. Each has to be found before enforcement is safe.

search

Find the senders first

Publish a monitoring policy with a working reporting address, then let a full cycle of aggregate reports name every source. Guessing the list from memory is how a completion statement stops arriving.

lock

Lock the dormant names

Merger names, a predecessor practice, defensive registrations bought years ago. Anything that should never send mail goes straight to an enforcing policy with a null MX record.

groups_3

Several firms at once

Providers serving legal clients get this conversation repeatedly, usually after a near miss at one of them. A portfolio view answers it once and keeps reporting separate per client.

stairs The steps, and one thing that changed

The sequence runs p=none, then p=quarantine, then p=reject. DMARCbis removed the percentage tag in RFC 9989, published May 2026, so each step applies to all of your mail or none of it.

No partial ramp is left to hide a missing sender behind. The completeness of the inventory is the only thing standing between an enforcement change and a client not receiving a document on the day they needed it.

Who reads the reports next month?

The NCSC retired Mail Check and Web Check on 31 March 2026, and its remaining Email Security Check is an on-demand lookup that does not ingest aggregate reports.

Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains. There is no free tier, only a free trial.

Related sectors: accountancy practices and financial services. Continuous reporting: DMARC monitoring. Migrating off the retired NCSC service: the Mail Check replacement page.

Common questions

Questions UK MSPs ask us.

Does the SRA require law firms to have DMARC? add

No. The SRA does not require DMARC, SPF or DKIM, and no SRA rule names any of them. We checked the full text of the SRA's "Risk Outlook report: information security and cybercrime in a new normal", published on 1 June 2022, and there is no email-authentication requirement in it. Any supplier telling you the regulator mandates this is overselling.

What the SRA does report is where the harm comes from. The same document states: "Over 80 percent of all the cybercrime reports we received in 2021 involved email", and describes "phishing and email modification frauds, which make up half of all the cybercrime reports we receive".

The useful framing is therefore not compliance but evidence. DMARC is a technical control a firm can point to as a reasonable, documented step taken to protect client confidentiality and client money — dated and in place beforehand, rather than reconstructed afterwards.

Does paragraph 6.3 of the Code of Conduct mean we need email authentication? add

Not as written. Paragraph 6.3 binds solicitors to keep the affairs of current and former clients confidential. It is a general duty about client information; it names no technology and sets out no technical control.

We are deliberately not going to interpret it further. How a professional duty applies to a particular firm's systems is a question for your COLP, your insurer or your own professional adviser, not for a technology vendor. DMARC AI has no affiliation with the SRA and nothing on this page is legal advice.

Will DMARC stop payment diversion fraud? add

It stops one of the three ways it happens, and it is important to be precise about which, because a firm that overestimates this is more exposed rather than less.

DMARC at an enforcing policy stops a spoofed domain: an attacker putting your exact firm domain in the From header of a message they sent themselves. Receiving mail servers reject or quarantine it, so the client never sees it.

It does nothing about a compromised mailbox. If somebody has the password to a real account — yours, the estate agent's, the other side's — the message is genuinely from that domain, authenticates cleanly and passes every check. That needs multi-factor authentication, conditional access and monitoring for mailbox forwarding rules.

It also does nothing about a lookalike domain. Because .co.uk is a public suffix, the organisational domain for example.co.uk is that whole name, and a registration such as example-legal.co.uk is a separate domain the attacker controls entirely. Your policy has no authority over it.

If we publish DMARC, can we relax our bank detail verification calls? add

No, and this is the one answer on the page we would ask you to read twice. The verification procedure covers all three versions of the attack. The DNS record covers one of them. If publishing a record ever becomes the argument for softening the call, it has done net harm.

The official UK response to payment diversion fraud remains procedural. The Law Society's public guidance puts it plainly: "Emails can be intercepted or diverted... Check by calling before you transfer money." Use a number the client already held — from the client care letter, the website or an earlier conversation — never one printed in the email asking for the transfer.

The two controls work from opposite ends. The call moves confirmation onto a channel the attacker does not control. DMARC removes the attacker's ability to use your exact domain in the first place. Both are worth having; neither replaces the other.

Our firm is small and we only send from Microsoft 365. Is there anything to do? add

Usually more than expected, and the surprise is rarely the mail platform. Practices accumulate sending systems: case management, e-signature, the client portal, accounts software issuing bills, an outsourced marketing list, a booking tool somebody set up without telling IT. Each of those sends as your domain and each has to authenticate before an enforcing policy is safe.

Start by publishing a monitoring policy with a working reporting address and letting a full cycle of aggregate reports name the sources for you, rather than assembling the list from memory. Then deal with the dormant names separately — merger names, a predecessor practice, defensive registrations — which need no inventory at all and can go straight to an enforcing policy with a null MX record.

One thing that changed: DMARCbis removed the percentage tag in RFC 9989, published May 2026. Each policy step now applies to all of your mail or none of it, so the completeness of that sender list is the only thing protecting a completion statement from being undeliverable.

Does Cyber Essentials or our insurer cover this already? add

Cyber Essentials does not. The current requirements — v3.3, published April 2026, effective from 27 April 2026, administered by IASME — cover five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. There is no DMARC, SPF or DKIM control among them, so a certificate is not an answer to this question.

Your insurer is a separate matter and we cannot speak for your policy. Cyber and professional indemnity wordings differ considerably on what they expect of email controls and verification procedures, and that is a conversation for your broker rather than something to infer from a vendor page.

Find out who is already sending as your firm.

Start a free trial, point the aggregate reports at DMARC AI, and get a dated sender inventory for every domain the practice holds inside 48 hours. Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.