Anyone can send an email that looks like it came from your firm — with their bank details on it.
Professional firms are the favourite target for invoice fraud, because a single email that looks like it came from you can redirect a completion payment or a settled invoice. We make that email impossible to send and we keep your genuine mail out of the spam folder.
Takes about ten seconds. No sign-up, no card — nothing is stored.
Three things that make firms like yours worth attacking
You move client money
Completion funds, settlements, disbursements, fee notes. A convincing email with different bank details is the whole crime and your domain is what makes it convincing.
Your emails are expected
Clients are waiting to hear from you and are primed to act quickly. A message that appears to come from their accountant or solicitor gets read and acted on.
Your name carries the loss
When a client is defrauded by an email carrying your domain, the conversation that follows is with your professional body, your insurer and your client — not the attacker.
The mail that never arrives is the one you never hear about
The same records that stop impersonation decide whether your real mail reaches the inbox. Get them wrong and engagement letters, fee notes and deadline reminders land in spam. Nobody tells you. You find out when a client says they never received it.
Almost nothing
We scan
You give us your domain. We show you, in plain English, who can currently send email in your firm's name.
We set it up
We write the records and either hand your IT person the exact lines or, if you delegate it to us, publish them ourselves. Nothing is installed and no mail is rerouted.
We watch it
Every day, forever. If a record changes, a new supplier starts sending as you or somebody attempts to impersonate the firm, you get told in words you can act on.
Our own domain scores A+ on our own scanner
Read live from our DNS every time the page loads, not typed in. If we ever slipped it would disappear.