Sample. This check was prepared for a fictional firm so you can see exactly what you receive. Every finding below is illustrative. Yours reports what is actually visible about your firm from the outside, and it is free.
IT First ResponseManaged IT and security | Fort Myers, Lee County FL
Complimentary
Security Check

Law Office Security Check

A no-cost look at how your firm's email and public presence appear from the outside, using only publicly available information.

Prepared for Gulfshore & Marsh, Attorneys at Law (a fictional firm)  ·  July 2026  ·  by Mario Del Mazo, IT First Response

Overall standing
A few gaps
1 good · 1 worth a look · 1 gap

The bottom line

From the outside the firm looks legitimate and well kept, but email can currently be forged in its name, and that is the exact setup behind wire-fraud attempts on closings. One published record closes it, and it is the first thing I would fix.

What we looked at

Each item below is something any outsider can observe about your firm today. A green result is a good sign. Anything flagged is worth a short conversation, not an alarm. The overall standing above is calculated from these results using a fixed rule rather than assigned by opinion: a single gap prevents a solid rating, and two or more mean it needs attention.

Email impersonation
Gap

Whether someone can send a message that appears to come from your firm and have it land in a client's inbox looking legitimate. Covers the three published records (SPF, DKIM and DMARC) that let a recipient reject a forgery.

The firm's domain publishes no DMARC record and its SPF record is set to soft-fail. In practice, a message forged in the firm's name would land in most inboxes unchallenged. This is a configuration fix, not a purchase.
Look-alike domains
Worth a look

Whether anyone has registered a near-miss of your web address, the usual groundwork for impersonating your firm to a client.

Nobody has registered a look-alike of the firm's address yet, but the two closest variants are available to anyone for about $15 each. Registering them first is cheap insurance.
Exposed credentials
Good

Whether addresses at your domain appear in known public breach data, which is where an attacker starts when choosing a firm to target.

No addresses at the firm's domain appear in the public breach data checked today. Good news, and worth rechecking periodically.

What only you can answer

The questions a cyber-insurance application asks. Your answers, not our findings. A "not sure" is not a failure; it is usually the most useful answer on the page.

Multi-factor sign-in is on for every mailbox, not only the partners.
Not sure
A backup has actually been restored and checked in the last year, not just reported as running.
No
You know who still has access to firm systems after someone leaves.
Not sure
If the power or the internet went out for a day, the firm could keep working.
Yes
Everyone at the firm has had security awareness training in the last year.
No

Why this matters for a law firm, and what it misses

When a domain has no spoofing protection, anyone can send email that appears to come from your firm. For a law office that is the setup behind client wire-fraud, where a fake message reroutes a closing payment. What a check like this cannot see is anything inside your systems, which is why the section above asks rather than tells.

The first three things I would fix

In priority order. Some of these you can do yourselves in an afternoon, and I have said which.

1
Publish a DMARC record and tighten SPF so forged email in the firm's name gets rejected instead of delivered. A configuration change, done in under an hour, and it closes the door wire-fraud walks through.
2
Register the two look-alike domains before someone else does. About $30 a year total, and this one you can do yourselves this afternoon.
3
Turn on multi-factor sign-in for every mailbox, not only the partners. It is included in Microsoft 365, and the whole firm can be covered in a morning.

What happens next

A short call to talk through anything flagged above, at no cost and with nothing to decide. Then the three items get closed, and I will tell you which of them you can do yourselves in an afternoon. After that the useful question is not what to fix, it is what keeps it from drifting back, which is the part ongoing support actually pays for.

This is a complimentary, outside-only snapshot based on publicly available information as of the date shown. No systems belonging to the firm were accessed, scanned, or tested. It is not a security audit, a legal opinion, or a compliance certification. Findings reflect what is observable externally and may change. A fuller review, looking at the controls inside your systems, is available if it would be useful. This sample describes a fictional firm; all findings are illustrative.

Request yours, free Back to IT for law firms