DomainGuard for law firms

The fraud never touches your network. It only needs your name.

A domain one letter off the firm's, a mail server pointed at it, and a message in the middle of a live matter with new wire instructions. Nothing was hacked. DomainGuard watches the two things that decide whether that works: what your own mail authentication tells the world to do with a forgery, and who has registered a name that reads as yours.

DomainGuard is in a public TestFlight beta and is not on the App Store yet. The web dashboard is live, and the free plan needs no card.

How the impersonation works

Four steps, none of which are technical.

Every step is cheap, legal to attempt, and invisible from inside the firm. That is what makes it worth watching for from outside.

  1. 01

    They register a name that reads as yours

    A doubled letter, a hyphen, the same name on a different ending, or characters from another alphabet that render as Latin ones. Nobody types those by accident, so a registration is deliberate.

  2. 02

    They point a mail server at it

    That is the valuable part. The website is usually blank. What the attacker wants is the ability to send from an address that survives a glance at the sender line.

  3. 03

    They wait for a matter with money in it

    A closing, a settlement, a retainer. The message arrives mid-thread, in your firm's voice, with revised wire instructions. The FBI's Internet Crime Complaint Center reports business email compromise as one of the highest-loss categories it tracks.

  4. 04

    Your client checks the sender and pays

    They did what they were told to do. The address looked right. Nothing on your network was ever touched, which is why nothing on your network noticed.

What is actually watched

Six signals, checked from outside the firm.

None of these require a mailbox, an agent, or a change to how the practice works. They are records the internet already publishes about you.

A DMARC policy that is actually enforcing
Your published policy is the instruction Gmail and Microsoft follow when someone forges your exact domain. On p=none they follow nothing. DomainGuard reports your current policy per domain, and on Starter and up it ingests the aggregate reports and tells you the day it is safe to advance.
SPF and DKIM that still line up
Alignment breaks quietly when a firm adds a new sending service — a marketing platform, an e-signature vendor, a new billing system. Each scan compares the records to the last one and stores the difference.
A watch on the names you cannot publish policy for
DMARC protects your exact domain. It does nothing about a domain one letter off it, because that domain is somebody else's and they publish their own records. That gap is what the lookalike watch is for.
Certificate and domain expiry
A browser warning on the client portal, or a name that lapses because the renewal notice went to an address on the lapsing domain. Both are checked from public records and alerted off-domain.
Exposure that is already public
Open ports and services on the firm's own hosts, security headers on the site, and known-vulnerability alerts from CISA's KEV catalog and NVD, each carrying a verdict derived from what scans actually observed on your account.
Breached credentials for firm addresses
Dark-web monitoring checks a monitored address against known breach data, so a password reused from a compromised third-party account is something you find out about rather than discover in a log.

What the tool itself can see

A monitoring tool at a law firm has to answer this first.

Before it is worth anything, it has to be safe to point at a practice that holds privileged material. Here is exactly what DomainGuard touches.

It reads public records, not your mail

DNS, RDAP, certificate transparency and what your own site already serves to any visitor. DomainGuard has no mailbox access, no message content, and no place in the mail path.

DMARC reports carry no content

An aggregate report is a count of messages per sending source and whether they aligned. There is no subject, no body, no recipient. Ingesting them tells you who is sending as your domain without exposing anything a client wrote.

Monitored addresses are never stored in the clear

A dark-web address is kept as a SHA-256 hash plus an encrypted envelope. The hash is what the system works with, audit entries carry the hash rather than the address, and the app addresses a monitored address by hash.

Deep scans need proof of control

Port scanning and the active vulnerability scanners only run against a domain after the account proves control of it — a DNS record, a file on the site, or an email at the domain, valid for 90 days. Passive checks stay open because they read what is already published.

For the questionnaire

Client security questionnaires and insurance renewals want dates.

Both ask the same thing in different words: show that somebody is looking, and show when they last looked.

DomainGuard keeps scan history, DNS diffs, certificate timelines, uptime and downtime windows, and a compliance tracker that turns PCI, HIPAA and cyber-insurance requirements into items with a status. PDF reports start on the Starter plan, which is also where email alerts and the nightly re-scan begin. It is not a compliance certification and it does not fill in a questionnaire for you. It is the dated record you would otherwise be reconstructing from memory the week the renewal is due.

The questions that come up

What firms ask before they add a domain.

Does this satisfy the technology-competence duty?

It is evidence toward it, not a certificate of it. Comment 8 to ABA Model Rule 1.1 expects lawyers to keep abreast of the benefits and risks of relevant technology, and Model Rule 1.6(c) expects reasonable efforts to prevent unauthorized disclosure. Knowing your mail-authentication posture, watching for domains registered to impersonate the firm, and keeping a dated record of both is the kind of reasonable effort that is easy to describe and easy to show. What counts in your jurisdiction is a question for your bar, not for us.

Can DomainGuard stop a forged email from reaching a client?

Only indirectly, and it is worth being precise about how. A DMARC policy at quarantine or reject is what makes receiving mail providers refuse a forgery of your exact domain, and DomainGuard tells you where your policy stands and when the report data says it is safe to tighten it. A lookalike domain is a different domain, so no policy of yours governs it. There the answer is detection and a registrar complaint. If you want filtering on inbound mail, that is a different product and it is on our email security page.

Do you need access to our email system?

No. Everything in the health checks comes from public DNS and what your site already serves. DMARC report ingestion is opt-in and works by publishing a reporting address in your own DNS record; the reports it receives contain counts and sending sources, never message content.

Can you get an impersonating domain taken down?

No. That is a complaint to the registrar with evidence attached, or a UDRP filing, and anyone offering a cheap takedown is selling you one of those two things with a markup. DomainGuard finds the registration and assembles the evidence — DNS records, mail records, registry data, certificate history, and whether the page copies yours — so the filing is a matter of attaching what you already have.

What does it cost?

The free plan holds every domain the firm owns and runs every health check on demand, with no card. DMARC report ingestion, email alerts, the nightly re-scan and PDF reports start at $6.99 a month on Starter. Pro is $49.99 and Enterprise is $99.99. Plans are bought through the iPhone app, which is currently a public TestFlight beta.

Start with the firm domain

Find out what your domain currently tells the world to do with a forgery.

The free plan needs no card and holds every domain the firm owns. The iPhone app is in a public TestFlight beta and signs in with the same account.