Research · 29 August 2026
We checked 200 UK law firms. 44% can have their email spoofed.
Spoofing is the mechanism behind Friday-afternoon fraud: a criminal emails a client mid-transaction from what looks like the firm’s address, with new bank details. The control that stops it is a single public DNS record called DMARC. We looked up that record for 200 firms on the SRA register. No firm was contacted, nothing was tested, and no firm is named.
No DMARC record at all
44%
Anyone can send email that appears to come from the firm. Nothing tells receiving mail servers to reject it.
DMARC set to monitor only (p=none)
30%
The firm receives reports about spoofing, but spoofed email is still delivered to the recipient.
Enforced (p=quarantine or p=reject)
26%
Receiving servers are told to quarantine or reject email that fails authentication. This is the configuration you want.
200 domains, SRA register, Manchester postcode area (200 small firms), public DNS via DNS-over-HTTPS, 2026-08-29. 89 no DMARC · 60 monitor only · 51 enforced.
Why this matters more for a law firm
Every business can be spoofed if the record is missing. Law firms are the target because the timing of a completion is known, the sums are large, and the client is expecting an email from the firm about where to send money. The SRA has warned on it repeatedly; insurers now ask about it at PII renewal; client panels ask about it in security questionnaires. It is also the one item on that list that is cheap to fix.
How we checked
- Sample: a random draw of 200 incorporated firms (Ltd or LLP) on the SRA register with a head office in the Manchester postcode area and one to five offices, using the website field each firm published on the register. Small and mid-sized firms, one city: not a national figure yet.
- Firm data: Solicitors Regulation Authority, used under its data-sharing terms. SRA attribution statement.
- For each domain we read two public DNS TXT records: the SPF record at the domain, and the DMARC record at
_dmarc.domain. That is the same lookup any receiving mail server performs. - A domain counts as spoofable if there is no DMARC record; monitor only if the record says
p=none; enforced if it says quarantine or reject. - We did not send email, connect to any firm’s servers, or test anything. Only aggregate figures are published; per-firm results are not shared with anyone.
- Caveat: one region and one size band, and DMARC is one control among several. A firm with p=reject can still be phished by a lookalike domain; that is a different check.
What a managing partner should do this week
- Check your own domain below. One second, no signup.
- If it is red or amber, send this to whoever runs your IT: “Please publish SPF, DKIM and a DMARC record for our domain, start at p=quarantine, and move to p=reject once the reports show all our legitimate senders are authenticated.” It is about an hour of work.
- Tell clients, in your engagement letter and on every invoice, that you will never change bank details by email. Ask them to phone a known number to verify.
- If you would rather it were done than explained, we do it for a fixed £450: Fix Your Email Spoofing.
Check your firm’s domain
Instant. We only read public DNS records. No email captured.
Journalists and Law Society branches: the aggregate data, method and a larger national sample are available on request at security@northloopsystems.com. Please link to this page rather than quoting the figure without the method.