A no-cost look at how your firm's email and public presence appear from the outside, using only publicly available information.
Prepared for Gulfshore & Marsh, Attorneys at Law (a fictional firm) · July 2026 · by Mario Del Mazo, IT First Response
Each item below is something any outsider can observe about your firm today. A green result is a good sign. Anything flagged is worth a short conversation, not an alarm. The overall standing above is calculated from these results using a fixed rule rather than assigned by opinion: a single gap prevents a solid rating, and two or more mean it needs attention.
Whether someone can send a message that appears to come from your firm and have it land in a client's inbox looking legitimate. Covers the three published records (SPF, DKIM and DMARC) that let a recipient reject a forgery.
Whether anyone has registered a near-miss of your web address, the usual groundwork for impersonating your firm to a client.
Whether addresses at your domain appear in known public breach data, which is where an attacker starts when choosing a firm to target.
The questions a cyber-insurance application asks. Your answers, not our findings. A "not sure" is not a failure; it is usually the most useful answer on the page.
When a domain has no spoofing protection, anyone can send email that appears to come from your firm. For a law office that is the setup behind client wire-fraud, where a fake message reroutes a closing payment. What a check like this cannot see is anything inside your systems, which is why the section above asks rather than tells.
In priority order. Some of these you can do yourselves in an afternoon, and I have said which.
A short call to talk through anything flagged above, at no cost and with nothing to decide. Then the three items get closed, and I will tell you which of them you can do yourselves in an afternoon. After that the useful question is not what to fix, it is what keeps it from drifting back, which is the part ongoing support actually pays for.
This is a complimentary, outside-only snapshot based on publicly available information as of the date shown. No systems belonging to the firm were accessed, scanned, or tested. It is not a security audit, a legal opinion, or a compliance certification. Findings reflect what is observable externally and may change. A fuller review, looking at the controls inside your systems, is available if it would be useful. This sample describes a fictional firm; all findings are illustrative.