Verified sender identity checked against the public bar register, firm-owned mailboxes, expiring document links, and IMAP so Outlook keeps working.
The pattern is well known and still works. A matter reaches the point where money moves. A message arrives that appears to come from the attorney handling it, from a domain that differs by a single character, revising the wire instructions. The funds go to the wrong account, and by the time anyone notices, they are gone.
Every technical check passes, because the attacker owns the lookalike domain and configured SPF, DKIM and DMARC on it correctly. Telling clients to read the address carefully is the standard advice and it does not work — the address looks correct, particularly on a phone.
A verified identity page changes what the recipient is able to do. Instead of judging an address, they open a link and see that the mailbox belongs to a named attorney whose licence was checked against the public register by a person. An impersonator with a lookalike domain cannot reproduce that, because they cannot pass the credential review.
It is not encryption and it does not stop a spoofed message arriving. It changes the question from "does this look right" to "can I confirm this", which is the only version of the question a non-expert can reliably answer.
Checked against the public licensing register for your jurisdiction and reviewed by a person, then published at a link the other side can open.
Administrators can suspend, reassign, export and audit any mailbox on a firm domain — which matters when someone leaves mid-matter.
IMAP, POP and SMTP from Starter upward. Nothing forces the firm into a proprietary web client or a new way of working.
Send documents as expiring links with logged access rather than files that persist in a recipient’s mailbox indefinitely.
Client correspondence is part of the matter. If it lives in an account the firm does not control, then a departure, a dispute or a request for records becomes a negotiation with an individual rather than an administrative task.
Mailboxes on a firm domain belong to the firm. Suspension, reassignment, export and audit are all administrator functions. The individual verification badge is billed to the attorney personally and travels with them — the identity is theirs, the correspondence is the firm's.
Because business email compromise targets exactly this. Wire-transfer fraud in conveyancing and settlement work almost always begins with a message that appears to come from a known attorney at a lookalike domain. A verified identity page gives the other side something to check that a spoofed display name cannot reproduce.
Against the public licensing register for the relevant jurisdiction, reviewed by a person before the badge is issued rather than granted automatically on a form submission.
Yes. Mailboxes on a firm domain belong to the firm: an administrator can suspend, reassign, export and audit them. That matters when someone leaves mid-matter and the correspondence has to stay with the file.
Yes. IMAP, POP and SMTP are available from the Starter tier, so Outlook and Apple Mail work as they do now. Nothing forces the firm into a proprietary web client.
Start free, connect the firm domain, and add verification for the attorneys who need it.
Create your free accountNo credit card. No trial clock.