Law Firm Stops Email Spoofing with DMARC
The Challenge
Wright, Harrison & Associates discovered their domain was being used to send phishing emails to clients. Three clients received fake invoices that appeared to come from firm partners. One client paid $175K to attackers before discovering the fraud.
The firm's reputation was at stake. Clients began questioning whether emails from the firm were legitimate. Some switched to competitors citing security concerns.
Previous DMARC implementation attempts had stalled at 'monitor' mode due to fears of blocking legitimate email from the firm's complex email ecosystem spanning multiple sending services.
Our Approach
Email Ecosystem Discovery
Week 1Identified all legitimate email sources (marketing, billing, practice groups). Found 14 sending services, 6 unknown to IT.
SPF/DKIM Configuration
Week 2Configured SPF and DKIM for all legitimate senders. Optimized SPF to stay under 10 DNS lookups.
DMARC Enforcement
Week 3-5Progressively increased DMARC policy from none to quarantine to reject. Monitored for legitimate mail impact.
BIMI Implementation
Week 6Obtained VMC certificate and implemented BIMI for verified logo display in Gmail, Apple Mail, and other supporting clients.
Solution Overview
Full email security implementation including DMARC at p=reject, SPF optimization, DKIM signing, BIMI logo display, and ongoing monitoring with threat intelligence.
The Results
Business Impact
"Our clients now see our verified logo in their inbox. PlatOps stopped attackers from impersonating us completely."
TThomas Wright, Managing PartnerCorporate Law Firm
"Clients comment on seeing our verified logo. It's a small thing that builds enormous trust."
MMargaret Chen, Client Relations PartnerCorporate Law Firm
Key Takeaways
- Email authentication protects both firm and client reputation
- Shadow IT email services are common and must be discovered
- BIMI provides visible trust signal to email recipients
- Progressive DMARC enforcement prevents legitimate mail disruption
Key Outcome
Technologies Used
Compliance Frameworks
Want Similar Results?
Let's discuss how we can help your organization achieve its goals.
Get Free AssessmentIndustry Solutions
Ready to Write Your Success Story?
Join the organizations that have transformed their security and infrastructure with PlatOps.