Benchmarks / UK solicitors
UK solicitors
Completion-money fraud starts with a spoofed email. A criminal who can send mail that appears to come from a firm can redirect a house purchase, and the money is usually gone the same day. Email authentication is the control that stops it, and it is the one most often left incomplete.
can be impersonated by email.
14 of 92 solicitors have no enforced DMARC policy, so a criminal can send mail that appears to come from them. Across 92 domains scanned.
Overall92 domains scanned
Can this sector be spoofed?
DMARC is the record that lets the world reject forged mail. Only an enforced policy (quarantine or reject) actually stops impersonation; p=none only watches.
- Enforced (p=reject) 67.4%
- Enforced (p=quarantine) 15.2%
- Monitor only (p=none) 15.2%
- No DMARC at all 2.2%
What we found, most common first
- 37%have no domain transfer lock34 of 92
Without it, anyone into the registrar account can move the domain away.
- 34.8%do not enforce HTTPS (no HSTS)32 of 92
A visitor’s first request can be downgraded to plain HTTP and intercepted.
- 15.2%can be impersonated by email14 of 92
No enforced DMARC policy, so a criminal can send mail that appears to come from them. This is the root of invoice and payment-redirection fraud.
- 4.3%have a certificate expiring within 30 days4 of 92
An expired certificate shows every visitor a full-page browser warning.
- 2.2%have no SPF record2 of 92
Nothing tells receivers which servers may send mail for them, so more of their genuine mail is treated as spam.
- 1.1%load insecure content on a secure page1 of 92
Mixed content quietly breaks the padlock visitors are told to trust.
Common across the internetcontext, not a sector failing
- 92.4%have DNSSEC switched off85 of 92
DNS answers are unsigned. DNSSEC remains rare across the whole web, so this is context rather than a sector-specific failing.
- 91.3%have no CAA record84 of 92
Any certificate authority may issue a certificate for the domain. CAA adoption is low across the internet generally, not just here.
- 57.6%run third-party scripts on the page53 of 92
Common everywhere. It only becomes a PCI DSS 4.0 obligation on pages that take card details, where each script must be inventoried and watched.
Weakest categories
- 17.4%Email authenticationgraded D or worse
- 1.1%DNSgraded D or worse
How we measure this
Firms listed on the Solicitors Regulation Authority register. We run the same public checks we run for customers, entirely from the public internet, with nothing installed anywhere. We publish sector averages only: no organisation is named, linked or individually reported, and we do not publish findings about any specific business. This sample leans towards larger and better-resourced organisations, so the real figure across the whole sector is likely to be worse, not better.
See how you compare.
Free, no signup, about a minute.