It reads public records, not your mail
DNS, RDAP, certificate transparency and what your own site already serves to any visitor. DomainGuard has no mailbox access, no message content, and no place in the mail path.
DomainGuard for law firms
A domain one letter off the firm's, a mail server pointed at it, and a message in the middle of a live matter with new wire instructions. Nothing was hacked. DomainGuard watches the two things that decide whether that works: what your own mail authentication tells the world to do with a forgery, and who has registered a name that reads as yours.
DomainGuard is in a public TestFlight beta and is not on the App Store yet. The web dashboard is live, and the free plan needs no card.
How the impersonation works
Every step is cheap, legal to attempt, and invisible from inside the firm. That is what makes it worth watching for from outside.
01
A doubled letter, a hyphen, the same name on a different ending, or characters from another alphabet that render as Latin ones. Nobody types those by accident, so a registration is deliberate.
02
That is the valuable part. The website is usually blank. What the attacker wants is the ability to send from an address that survives a glance at the sender line.
03
A closing, a settlement, a retainer. The message arrives mid-thread, in your firm's voice, with revised wire instructions. The FBI's Internet Crime Complaint Center reports business email compromise as one of the highest-loss categories it tracks.
04
They did what they were told to do. The address looked right. Nothing on your network was ever touched, which is why nothing on your network noticed.
What is actually watched
None of these require a mailbox, an agent, or a change to how the practice works. They are records the internet already publishes about you.
What the tool itself can see
Before it is worth anything, it has to be safe to point at a practice that holds privileged material. Here is exactly what DomainGuard touches.
DNS, RDAP, certificate transparency and what your own site already serves to any visitor. DomainGuard has no mailbox access, no message content, and no place in the mail path.
An aggregate report is a count of messages per sending source and whether they aligned. There is no subject, no body, no recipient. Ingesting them tells you who is sending as your domain without exposing anything a client wrote.
A dark-web address is kept as a SHA-256 hash plus an encrypted envelope. The hash is what the system works with, audit entries carry the hash rather than the address, and the app addresses a monitored address by hash.
Port scanning and the active vulnerability scanners only run against a domain after the account proves control of it — a DNS record, a file on the site, or an email at the domain, valid for 90 days. Passive checks stay open because they read what is already published.
For the questionnaire
Both ask the same thing in different words: show that somebody is looking, and show when they last looked.
DomainGuard keeps scan history, DNS diffs, certificate timelines, uptime and downtime windows, and a compliance tracker that turns PCI, HIPAA and cyber-insurance requirements into items with a status. PDF reports start on the Starter plan, which is also where email alerts and the nightly re-scan begin. It is not a compliance certification and it does not fill in a questionnaire for you. It is the dated record you would otherwise be reconstructing from memory the week the renewal is due.
The questions that come up
It is evidence toward it, not a certificate of it. Comment 8 to ABA Model Rule 1.1 expects lawyers to keep abreast of the benefits and risks of relevant technology, and Model Rule 1.6(c) expects reasonable efforts to prevent unauthorized disclosure. Knowing your mail-authentication posture, watching for domains registered to impersonate the firm, and keeping a dated record of both is the kind of reasonable effort that is easy to describe and easy to show. What counts in your jurisdiction is a question for your bar, not for us.
Only indirectly, and it is worth being precise about how. A DMARC policy at quarantine or reject is what makes receiving mail providers refuse a forgery of your exact domain, and DomainGuard tells you where your policy stands and when the report data says it is safe to tighten it. A lookalike domain is a different domain, so no policy of yours governs it. There the answer is detection and a registrar complaint. If you want filtering on inbound mail, that is a different product and it is on our email security page.
No. Everything in the health checks comes from public DNS and what your site already serves. DMARC report ingestion is opt-in and works by publishing a reporting address in your own DNS record; the reports it receives contain counts and sending sources, never message content.
No. That is a complaint to the registrar with evidence attached, or a UDRP filing, and anyone offering a cheap takedown is selling you one of those two things with a markup. DomainGuard finds the registration and assembles the evidence — DNS records, mail records, registry data, certificate history, and whether the page copies yours — so the filing is a matter of attaching what you already have.
The free plan holds every domain the firm owns and runs every health check on demand, with no card. DMARC report ingestion, email alerts, the nightly re-scan and PDF reports start at $6.99 a month on Starter. Pro is $49.99 and Enterprise is $99.99. Plans are bought through the iPhone app, which is currently a public TestFlight beta.
Start with the firm domain
The free plan needs no card and holds every domain the firm owns. The iPhone app is in a public TestFlight beta and signs in with the same account.