Managed email authentication for law firms

Get your firm’s email authentication finished and documented.

We work with your IT provider to check the services sending email as your firm, resolve the authentication issues you agree to fix, and move towards an enforceable DMARC policy when the evidence supports it.

A defined project, usually over four to six weeks. Your administrator makes the changes. You keep a dated record of the services checked, the settings changed and any work still needed.

Twenty minutes, with or without your IT provider. No passwords, no access to your DNS.

What your firm keeps

  • Every service that sends as your firm, checked. A confirmed list, with a test result for each.
  • A policy decision you can explain. DMARC tightened only when the evidence supports it, with the reasons written down.
  • A dated record for your file. The settings before and after, each change with a way back, and every open item with an owner.

Sample record

See what you keep before you call.

A demonstration record for an invented firm: the scope, the services confirmed, the tests, the settings before and after, and the reasons for each policy step.

From the sample · services confirmed

Microsoft 365Staff email · dmarc=pass
Case management systemClient portal notices · dmarc=pass
Billing serviceInvoices and month-end statements · dmarc=pass
Newsletter platformUpdates to clients · dmarc=pass

Demonstration data for an invented firm on a reserved example domain.

How a project runs

Two sessions, and every change with a way back.

Your IT provider or MSP keeps the relationship and makes the changes. We bring the inventory, the evidence and the record.

  1. 01
    A 20-minute scope call to find out which services send as your firm, who is involved, and whether the standard scope fits.
  2. 02
    The scope in writing, and a record of your current settings before anything is touched.
  3. 03
    Two live sessions with whoever controls your DNS, with the reports reviewed in between.
  4. 04
    Acceptance against the record: what changed, what was tested, and what is still open.

Scope and price

A published price for a defined scope.

The standard project has a fixed price, with what it does not cover listed right next to it. Larger or more complicated set-ups are quoted after a look.

An IT provider or MSP? Bring us in for a client project.

Questions partners ask first

More questions

We already have an IT provider. Why would we need you?

Because the project is built around them. Your IT provider or administrator makes every change in your DNS and mail settings; we bring the inventory of services that send as your firm, the tests, the review of the reports and the record. They keep the relationship, and they end up with a record they can maintain.

Do you need our passwords or access to our systems?

No. We never ask for passwords, and we do not need access to your DNS, your mailboxes or your Microsoft 365 tenant. Your administrator makes the changes while we go through them together, and we work from what is published and from the reports receivers send.

What if a reject policy is not right for us yet?

Then we do not set it. Reject is the aim once every legitimate service passes and the person responsible agrees. If a service cannot be fixed within the project, the record says which one, why, and which policy is safe in the meantime. That is part of the result, not a failure of it.

Who you work with

Adam Sierant

Director of Northstar Infinity Works Ltd, company no. 17326480. mailcounsel is a technology service, not a law firm, and nothing we provide is legal advice.

Or start with your domain

See what your domain publishes today.

A free reading of your public DNS, with the records your IT provider will want to see.

Published records only. It does not read your mail, and a missing record is not proof that anything has gone wrong.

Start with a 20-minute scope call.

With you, and your IT provider if you like. If the standard scope does not fit, we say so on the call.

Request a scope call

What DMARC does not do. It helps participating receivers judge mail that uses your domain. It does not stop every kind of phishing, a compromised mailbox or a lookalike domain someone else registered, and it does not guarantee delivery to the inbox.