Law firms hold client money, sit at the centre of every transaction they touch, and correspond by email with counterparties they have never met in person. That combination makes the profession one of the most reliably targeted in the economy, and it makes one specific attack — the redirected completion payment — the most expensive thing that happens to firms.
One attack pattern, repeated with small variations, accounts for the profession's most severe financial losses.
A residential conveyance runs on a fixed and publicly visible schedule. Exchange happens, a completion date is set, and on that date a defined sum has to move from the buyer's solicitor's client account to the seller's solicitor's client account. Everybody involved knows the date. The estate agent knows it, the lender knows it, the removal company knows it, and the client has almost certainly mentioned it on social media. An attacker who has been sitting quietly in one mailbox on that transaction knows it too, and the whole scheme depends on doing nothing until the day the money is expected to move.
The mechanics are consistent enough to describe as a template. Access is obtained to a single mailbox, usually through credential phishing against staff at whichever firm has the weakest controls, or at the estate agency or the mortgage broker. The attacker sets a quiet forwarding or folder rule, reads the correspondence for a week or two, and learns the names, the tone, the file reference, the sum and the date. Then, close to completion, they either reply into the existing thread from the compromised account or register a domain differing from the counterparty firm's by a single character and continue the conversation from there. The message carries revised bank details, an apology about an account change following an audit or a bank migration, and a request to use the new details today.
The lookalike domain is the part a firm can actually screen for, because nobody reads a sender address character by character on a busy completion day. A hyphen inserted into a two-word firm name produces hartley-marsh.example.com where the genuine domain is hartleymarsh.example.com. A homoglyph substitutes a visually similar character, so rn stands in for m, or a Latin letter is replaced with an identical-looking character from another script. Other variants append a plausible word: hartleymarsh-conveyancing.example.com, hartleymarshllp-portal.example.com. Each has to be registered and has to resolve in DNS before it can send mail or host a fake login page, and that is the moment it becomes visible to a threat feed.
The other half of the attack runs in the opposite direction, against the firm's own client. Here the impersonated party is the practice itself. The buyer receives an email that appears to come from their solicitor, quoting the correct matter reference and completion figure, saying the firm's client account details have changed and the balance should now go to a different sort code and account number. The client has been told all along to expect payment instructions from the firm and has no reason to doubt a message that quotes their own file number back to them.
What makes this pattern so much more damaging in legal services than in most sectors is the size and irreversibility of a single transaction. A retail phishing loss is a card chargeback. A conveyancing loss is the entire purchase price of a house, moved once, in a window where recall through the banking system rarely succeeds because the receiving accounts are drained within hours. Nor is the damage only financial: there is a client whose purchase has collapsed, a professional indemnity notification, a report to the regulator, a possible negligence claim, and a partner spending months on a matter that generates no fee. The root cause is consistently the same — the instruction looked normal, and no step in the workflow tested whether the domain it came from had existed a fortnight ago.
The pattern worth internalising: in almost every completion-day fraud, the fraudulent domain was registered and resolving days before the money moved. The firm did not lack a control; it lacked a place to put one, because no step in the file's workflow asked a machine whether the counterparty's domain was known to be malicious.
For a law firm, email security is not only an IT question. It attaches to duties the practice already owes.
Most industries approach phishing defence as a risk-management decision: a control is worth buying if the expected loss it prevents exceeds its cost. Legal practice sits differently, because the information moving through the firm's mailboxes is client confidential information and the obligation to protect it is a professional duty rather than a commercial preference. ABA Model Rule 1.6(c) requires a lawyer to make reasonable efforts to prevent the inadvertent or unauthorised disclosure of, or unauthorised access to, information relating to the representation of a client. A credential-phishing page that harvests a partner's mailbox password is precisely the unauthorised access the rule contemplates, and the question asked afterwards is what reasonable efforts the firm had actually made.
Alongside confidentiality sits competence. The comment to Model Rule 1.1 makes clear that maintaining competence includes keeping abreast of the benefits and risks associated with relevant technology. That language has been adopted in most US jurisdictions and it has a practical consequence: a managing partner cannot treat email fraud as somebody else's specialism. Knowing that counterparty impersonation exists, that it is screenable, and that a firm of any size can act on it for a modest annual sum is now part of the working knowledge the profession is expected to hold. Deciding not to screen is defensible if it is a decision; it is much harder to defend if it was never considered.
Outside the US the framing differs but the destination is the same. Regulators of solicitors and licensed conveyancers in England and Wales, law societies in Canada and Australia, and the supervisory bodies for notarial practice across continental Europe all impose detailed rules on the handling of client money, on the operation of the client account and trust ledger, and on the systems and controls maintained around them. They expect firms to mitigate risks to client funds that the profession has been warned about, and warning notices on payment-diversion fraud have been issued repeatedly. The firm's compliance officer, whether titled COLP, practice manager or general counsel, is the person who has to describe those controls when asked. Where the firm is within scope of anti-money-laundering legislation, client due diligence adds a further layer, and the identity and source-of-funds checks already performed at matter opening are a natural moment to screen the counterparty's domain too.
The final source of obligation is contractual rather than regulatory, and for firms doing corporate work it is often the most demanding. Outside-counsel guidelines from banks, insurers, healthcare groups and technology companies now routinely include a security schedule: multi-factor authentication on remote access, encryption of client data at rest and in transit, breach notification within a specified period, restrictions on offshore processing, and an annual attestation. Several of those questionnaires now ask directly whether the firm screens inbound domains and whether it has a documented out-of-band verification procedure for payment instructions. A firm that cannot answer yes does not lose the panel place immediately, but it will be asked again next year.
Most firms already check suspicious domains. The problem is who checks, how, and whether anyone can prove it later.
A partner receives a payment instruction that feels slightly off. She forwards it to the IT manager, or to the outsourced support provider, with the subject line "is this genuine?". The IT manager opens it, looks at the sender address, notices nothing obviously wrong, perhaps searches the domain in a browser, and replies that it looks fine. The whole exchange takes forty minutes and produces no record beyond an email thread nobody will find again.
The domain is submitted to /api/v1/check by whatever system is already handling the message or the matter. The answer comes back in under 50 milliseconds as structured data: whether the domain is present in the database, its category, whether it currently resolves in DNS, and when it was last checked. Every domain in that database has been resolved through live DNS before being retained, so a match is not a guess about a name that might exist.
Payment diversion is the most expensive, but it is not the only route into a firm.
Law firms present an unusual attack surface because so much of the work is conducted with strangers. A commercial associate may exchange fifty emails with opposing counsel over a deal without ever meeting them, and will accept documents, links and portal invitations from that counterparty as a matter of course. Court systems, e-filing services, expert witnesses, costs draftsmen, e-discovery vendors, translators, process servers and counsel's chambers all generate legitimate mail that looks structurally identical to the fraudulent version. The professional norm of prompt, courteous responsiveness works directly against the instinct to slow down and check.
The six patterns below cover the great majority of what firms actually see. What they have in common is a domain: something has to be registered and has to resolve before it can send mail, host a cloned login page or serve a document. That shared dependency is the one point a firm can act on, because the domain is checkable in a way that the persuasiveness of the message is not. Screening it does not require the firm to analyse the content of the message, only to ask whether the name it came from is already known.
The dominant pattern in transactional work. A near-identical domain stands in for the firm on the other side of a conveyance, a corporate acquisition, a probate distribution or a personal-injury settlement, and it appears late in the matter carrying revised payment details. Timing is pegged to exchange and completion because that is when a payment is expected and scrutiny is lowest.
Highest financial impactA notification claiming to come from an e-filing system, a docket alert service or a court office, telling a litigator that a document has been filed, a hearing has been relisted or a deadline is imminent. The urgency is built into the subject matter, and the landing page is a credential form styled as the filing portal. Firms that use several court systems across jurisdictions are least able to tell the real notification from the fake.
Credential harvestingSecure client portals and document-exchange platforms have trained everyone in the profession to click a link in order to collect a file. A cloned portal at a domain like secure-exchange-verify.example.com inherits that training. The prize is either the credentials to the real document management system or a signed engagement letter and identification documents uploaded straight to the attacker.
Disbursements are a soft target because the firm pays them on behalf of the client and the sums are large enough to matter but small enough to avoid partner sign-off. Fraudulent invoices arrive from lookalike domains impersonating expert witnesses, medical reporting agencies, e-discovery providers, counsel's clerks or translation services, quoting a genuine matter reference and revised remittance details.
Accounts payableAssociates are approached constantly by legitimate recruiters, so an approach carrying a link to a confidential role specification or a salary benchmarking document is entirely unremarkable. The lure is aimed at a population with wide access to the document management system and a strong incentive to open the message privately, away from anyone who might question it.
Targets fee earnersHere the firm is the brand being abused rather than the victim being tricked. A lookalike of the practice's own domain sends clients revised client-account details, fake completion statements or invitations to a cloned portal. The firm often learns about it only when a client calls to ask why the bank details changed, which is why monitoring for lookalikes of the firm's own name matters as much as screening inbound mail.
Brand abuseFive practical placements, from the mail gateway to the cashier's payment-verification sheet.
The first and broadest placement is the mail gateway. Whether the firm runs Microsoft 365 with a third-party filtering layer, a hosted gateway from its IT provider, or an appliance in a server room, there is a point at which sender domains can be extracted and evaluated before delivery. Sending each distinct sender domain to /api/v1/check, or batching the day's new senders through /api/v1/batch in groups of up to one hundred, adds a verdict that the gateway can act on: quarantine on a match, or tag the subject line so the recipient sees a warning before opening. This catches the widest range of the six patterns above because everything arrives by mail.
The second placement is the document exchange. Firms that operate a secure client portal or a managed file transfer service can screen the domain of any external party invited to a data room or a matter workspace, and can screen the domains embedded in inbound share notifications. The third, and the one most specific to legal practice, is the matter-management system itself. At matter opening the fee earner or the new-business team records the counterparty's solicitors, the estate agent, the lender, the expert and the other side's counsel. Screening those contact domains at the moment they are entered means the file starts with a known-clean set of correspondents, and a lookalike that appears later in the matter stands out because it does not match what is on the record.
The fourth placement is the one that stops the money. Most firms already require a telephone call to a previously known number before acting on any change of bank details. A domain check belongs in the same procedure as a second, independent question: not only "did I speak to someone" but "is the domain this instruction arrived from known to be malicious". The accounts clerk runs the check as part of preparing the payment, staples the response to the payment authorisation, and escalates to the COLP or the partner supervising the matter on a positive result rather than proceeding and mentioning it later.
The fifth placement suits the smallest practices, which often have no gateway to integrate with and no development capacity at all. The daily feed can be downloaded as a CSV and loaded into whatever DNS filter or firewall the firm already runs, so that any attempt to reach a known phishing domain fails at the network level regardless of which mailbox the link arrived in. The feed is exported at 04:30 UTC each day and carries the columns domain,category,dns_status, which most filtering products will import without custom work. That approach requires the daily threat feed subscription rather than credits, and it is the only option that protects a click made on a personal phone connected to the office network.
curl -s "https://phishingdetectionapi.com/api/v1/check?domain=hartleymarsh-conveyancing.example.com&apikey=YOUR_API_KEY"
{
"domain": "hartleymarsh-conveyancing.example.com",
"is_phishing": true,
"category": "phishing/malware",
"dns_status": "resolves",
"last_checked": "2026-07-27 04:31:12",
"confidence": 0.98,
"database_size": 212370
}
A positive result is an instruction to the accounts clerk, not a discussion point. The payment does not leave the client account. The clerk records the response against the matter, notifies the supervising partner and the compliance officer, and the firm telephones the genuine counterparty on a number taken from the original engagement correspondence or the regulator's public register — never a number in the suspect email. If funds have already been sent, the bank is contacted immediately, because recall depends almost entirely on how quickly the receiving bank is told.
<?php
// Domains taken from the matter's contact list: other side's solicitors,
// estate agent, lender, counsel's chambers, expert witness.
$domains = [
'hartleymarsh.example.com',
'hartleymarsh-conveyancing.example.com',
'ridgeway-surveyors.example.net',
'chambers-eastgate.example.org'
];
$payload = json_encode([
'apikey' => getenv('PDA_API_KEY'), // server-side only, never in client code
'domains' => $domains // maximum 100 per request
]);
$ch = curl_init('https://phishingdetectionapi.com/api/v1/batch');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ['Content-Type: application/json'],
CURLOPT_POSTFIELDS => $payload,
CURLOPT_TIMEOUT => 10
]);
$res = json_decode(curl_exec($ch), true);
curl_close($ch);
foreach ($res['results'] as $row) {
if (!empty($row['is_phishing'])) {
// Flag the matter, block the contact, alert the supervising partner.
matter_flag($matterRef, $row['domain'], $row['category'], $row['last_checked']);
}
}
// $res['checked'], $res['phishing_found'] and $res['credits_used'] go to the audit log.
The API key is the username chosen at registration and is passed as the apikey parameter or in the POST body. It must stay server-side: in a practice-management integration that means an environment variable on the server, never a value embedded in a browser script or a desktop client. Full field definitions are in the API documentation, and an account can be opened at registration.
The same check lands in a different place depending on whether the firm has an IT department at all.
A sole practitioner doing residential conveyancing faces exactly the same attack as a hundred-partner firm, at exactly the same value per transaction, with none of the infrastructure. There is no gateway to integrate with, no security team to escalate to, and often no IT provider beyond the person who set up the laptops. For that practice the realistic deployment is manual: the domain is checked in the browser before any payment is authorised, and the response is printed or pasted into the file note. A Starter pack at $59 for 10,000 credits covers a small practice for years at that rate of use, since credits are valid for twelve months and a firm doing this properly might run a few hundred checks a month.
A mid-size firm with an IT manager and a practice-management system has different options. Here the check goes into the mail flow and into the matter-opening workflow, which raises volume from hundreds to tens of thousands of lookups a month depending on how much inbound mail is screened. Growth at $99 for 25,000 credits or Professional at $249 for 100,000 credits is the usual bracket, and the batch endpoint keeps cost predictable because a hundred domains travel in one request at one credit each. The decisive advantage at this size is not the technology but the workflow: the firm can make a positive result trigger a defined escalation to the COLP rather than an ad hoc conversation.
An international firm with its own security operations centre will not want per-lookup calls at all for its bulk use. It will pull the full database daily and load it into the existing detection stack: a SIEM watch list, a DNS resolver policy, an email-gateway block list. That is the daily threat feed, from $499 per month, and it changes the economics because volume stops mattering. Larger credit packs remain useful alongside it for interactive checks — Business at $499 for 250,000, Enterprise at $999 for 750,000, Enterprise Plus at $1,997 for 2,000,000 and Scale at $3,999 for 5,000,000 — but the feed is what a SOC will build on.
| Decision | Sole practitioner / small practice | Mid-size firm with an IT manager | International firm with a SOC |
|---|---|---|---|
| Who runs it | The practice manager or the cashier, by hand, as part of preparing a payment. | The IT manager builds it once; the accounts team and new-business team use it daily. | The security team owns the feed; detection engineering maintains the rules that consume it. |
| Enforcement point | The payment-verification step, plus the CSV loaded into the office DNS filter. | Mail gateway, matter-management contact records, client portal invitations. | SIEM correlation, DNS resolver policy, secure web gateway and mail-gateway block lists. |
| Volume and cost | Hundreds of checks a month. Starter $59 / 10,000 credits at $0.0059 each, valid twelve months. | Thousands to tens of thousands a month. Growth $99 / 25,000 or Professional $249 / 100,000. | Bulk ingestion rather than lookups. Daily feed from $499/month, with larger credit packs for interactive checks. |
| Evidence for the regulator or insurer | The saved JSON response filed with the matter and the record of the verification call. | Gateway logs plus a flag on the matter record, exportable per file on request. | Full audit trail in the SIEM, retained to the firm's policy and available for client security audits. |
| What breaks first | Nobody does the check when the cashier is on holiday and a partner is chasing completion. | Alert fatigue: too many domains tagged, so the warning banner stops being read. | The feed becomes one more list nobody tunes, and matches are triaged at low priority. |
Credits are pay-as-you-go through PayPal, one credit per domain looked up, valid for twelve months. A 14-day refund applies to unused credits where under 10% has been consumed. Full detail on the pricing page.
What a domain check does for the firm's cover, what it cannot do, and what to keep.
Professional indemnity insurance. Proposal forms and renewal questionnaires for solicitors' PI cover now routinely ask about payment-verification controls: whether the firm calls a previously known number before acting on changed bank details, whether that procedure is written down, whether it applies to every fee earner and every disbursement, and increasingly whether inbound domains are screened. Underwriters ask because payment diversion is the claim they see most often in this class. Being able to describe a documented, automated check — and to produce the record of it on a specific matter — is materially better than describing a culture of carefulness. Firms should confirm the position with their own broker; this is a description of what is being asked, not advice on cover.
The limit of a domain check. A domain-reputation lookup answers one question: is this domain known to be an active phishing domain. It cannot tell you that a genuine, legitimate mailbox at the counterparty firm has been compromised and is being used to hijack the thread from the real address. In that scenario the domain is the real domain and the check will correctly return no match. This is why the telephone call to a previously known number remains the control that stops the money, and why the domain check is an addition to it rather than a replacement for it. Any firm told that a lookup service removes the need for out-of-band verification is being told something untrue.
Keep the record. The value of the check compounds when it is retained. Store the full response — domain, verdict, category, DNS status and the last_checked timestamp — on the matter file alongside the note of the verification call and the name of the person who made it. Two or three years later, in a negligence claim or a regulatory enquiry, that record is the difference between asserting that the firm was careful and demonstrating what it actually did on a specific date. It costs nothing beyond the discipline of filing it.
The six questions that come up most often when a firm evaluates domain screening.
The request contains a domain name and your API key. It does not contain the message, the sender's or recipient's address, the matter reference, the client's name, the sum involved or any attachment. A domain name is not information relating to the representation of a client in the sense contemplated by Model Rule 1.6, in the same way that resolving a domain in DNS in order to deliver the email is not a disclosure.
The analysis still belongs to the firm. Most compliance officers record domain screening in the data-processing register and in outside-counsel disclosures alongside the other technical services already in the mail path, and check any engagement terms that restrict processing to named jurisdictions.
No, and it is important to be direct about that. When an attacker replies into an existing thread from the counterparty's real account, the sending domain is legitimate and the lookup will correctly report no match. Nothing about a domain-reputation service detects a compromised account at another organisation.
What the check does address is the larger share of cases where the attacker moves the conversation to a lookalike domain, because they lost access to the mailbox, never had it, or want replies to reach them rather than the real firm. Against the compromised-mailbox case, the controls that work are the call to a previously known number and a standing rule that bank details never change mid-matter.
Less than most firms expect, because the volume is low. A ten-person practice screening every counterparty domain at matter opening and every payment instruction before release might use a few hundred credits a month. The Starter pack at $59 for 10,000 credits works out at $0.0059 per lookup and credits are valid for twelve months.
If the firm also screens all inbound mail at the gateway, volume rises and Growth at $99 for 25,000 credits or Professional at $249 for 100,000 becomes the right bracket. There is no subscription and no minimum on credit packs; the daily feed is a separate subscription from $499 per month for firms loading the whole database locally.
Yes, in two ways that require no development work. The first is manual: a single-domain check is one URL, so the practice manager or cashier can run it in a browser as part of the payment-verification procedure and paste the result into the file note. That is a workflow change rather than an IT project, and it lands exactly where the money is at risk.
The second is to hand the daily CSV feed to whoever supplies your DNS filter, firewall or managed email service. The file has three columns and is regenerated every day, so most products accept it as a scheduled list import, and many outsourced IT providers will set it up under an existing support contract. Either route gives you a documented control you can describe to an insurer.
The database contains domains observed in active phishing use and confirmed to be resolving in DNS, which includes homoglyph and hyphenated lookalikes once they are in use. Every candidate is resolved using 50 concurrent threads through rotating proxies with a 10 second timeout, and only domains with an active A record are retained; domains that stop resolving are pruned. The result is a list of things that currently work, not an archive of everything ever reported.
The honest limitation is timing. A domain registered this morning and used for the first time this afternoon may not yet have been observed by any feed. Treat the check as one layer: it removes the large volume of attacks reusing known-bad infrastructure, and the verification call covers what it misses. The database is rebuilt every 24 hours with the feed export at 04:30 UTC, so the gap between observation and availability is short.
Each lookup returns structured JSON: the domain queried, whether it matched, the category, the DNS status, a last_checked timestamp and the size of the database at the time of the query. Batch responses add the number of domains checked, the number of matches and the credits consumed. Store those responses against the matter and you have a dated, machine-generated record of what the firm knew and when.
Combined with the firm's written payment-verification procedure and the note of the telephone call, that gives a compliance officer a complete answer to the question a regulator or underwriter actually asks, which is not "were you careful" but "show me what you did on this file on this date". Retention periods should follow the firm's existing file-retention policy rather than being set separately.
Screen counterparty domains at matter opening, at the mail gateway and at the moment funds leave the client account. Hundreds of thousands of DNS-verified active phishing domains, rebuilt every 24 hours, answered in under 50 milliseconds.
Adjacent industry briefs: Banking & financial services · Insurance · Higher education · Email security