This is a sample. It was prepared for a fictional firm so you can see exactly what you receive. Every finding below is illustrative. Yours reports what is actually visible about your domain on the day it is run.
Managed IT and security · Fort Myers, Lee County FL
Complimentary Security Check
A forged email from your domain can redirect a client's money.
The money does not come back
Funds moved on forged instructions are rarely recovered. Recall depends on catching it within hours.
Then you tell the client
The Florida Bar requires reasonable efforts to safeguard client information. Rule 4-1.6(e).
It almost always starts in email
The one thing an outsider can check for you. Nothing signed, no file opened.
Prepared for Wexford & Vance, P.A. · August 2026
by Mario Del Mazo
Overall standing
Not yet scored
Set each item below
The bottom line
Anyone can send email that appears to come from your domain, which is the setup behind a redirected closing payment. Publishing a DMARC record closes it, and it is a same-day change your own IT help can make.
What we looked at
Standing derived from these three · never assigned by opinion
Email impersonation
Can a stranger send mail that looks like it came from you? SPF, DKIM, DMARC.
No DMARC record is published, and the SPF record ends in a soft fail. A forged message from your domain will usually reach the inbox rather than being rejected.
Look-alike domains
Has anyone registered a near-miss of your web address?
Nothing registered against your name. This one is clean.
Exposed credentials
Do addresses at your domain show up in known public breach data?
Six addresses at your domain appear in public breach data, including one shared reception mailbox.
What only you can answer
Your answers, not our findings · does not affect the standing
Multi-factor sign-in on every mailbox, not only the partners.
Wire instructions are verified by voice to a known number before any funds move.
A backup restored and checked in the last year, not just reported as running.
Access removed the same day someone leaves the firm.
The firm could keep working if power or internet went out for a day.
Security training this year for everyone, paralegals and part-time included.
The first three things I would fix
In priority order
1
Publish a DMARC record at p=quarantine and change the SPF soft fail to a hard fail. Stops a forged message from your domain reaching a client. About an afternoon, and your own IT help can do it.
2
Put wire instructions behind a voice callback to a number you already had on file, not one printed in the email. This is the control that stops the loss, not the one that detects it.
3
Force a password reset on the six exposed addresses and retire the shared reception mailbox in favour of named accounts.
Book a free 15-minute call
We walk through anything flagged above. Nothing to decide on the call.
Forward it, or ask for your own. Any Lee County firm.
●Registered Florida LLC●Tech E&O and cyber liability insured●No tier one, no ticket queue
A complimentary, outside-only snapshot based on public information as of the date shown; findings may change. No systems belonging to the firm were accessed, scanned, or tested, and no client information was requested, received, or reviewed. It is not a security audit, a legal opinion, or a compliance certification, and it does not assess whether the firm meets any Bar obligation. A fuller review, looking at the controls inside your systems, is available if it would be useful.