Guide
Payment diversion fraud and email: what authentication stops, and what it does not
In short
Payment diversion fraud tricks a client or a firm into sending money to a criminal’s account, usually through an email that appears to come from someone they trust. Email authentication stops messages that forge a firm’s exact domain, but not lookalike domains or hacked mailboxes, so it works best alongside call-back checks and a rule that bank details never change by email.
How the fraud works
The pattern is familiar to conveyancers. A criminal follows a transaction, often from inside a compromised mailbox, and at the moment money is due sends an email that appears to come from the firm or from its client: the bank details have changed, please use this account instead. It is often called Friday afternoon fraud, because completion money tends to move at the end of the week, when there is least time to check.
Take Five warns homebuyers that criminals pose as solicitors to have deposits and purchase money sent to their own accounts, and that they usually gain access to genuine legal email accounts, which makes the fake messages seem real.[1] The SRA’s advice to firms on cybercrime describes the same fraud in conveyancing, with bank details altered during a sale to redirect the completion money.[2]
The scale of the problem
UK Finance reported £1.28 billion stolen through fraud in 2025, up 4% on the year before. Authorised push payment fraud, where the victim is manipulated into making the payment themselves, accounted for £576.4 million of losses across 248,070 cases, with losses up 19%.[3] Not all of it involves email or property, but diverted payments are one of the ways that money is taken.
Three routes into the payment
A diverting email reaches its target in one of three ways, and each needs a different defence.
| Route | Example | Does email authentication help? |
|---|---|---|
| Forged email from the firm’s exact domain | A completion statement from [email protected], sent from a criminal’s server | Yes: DMARC at quarantine or reject asks receivers to junk or refuse it |
| Lookalike domain | The same statement from [email protected] | No: the criminal’s own domain is judged by its own records |
| Compromised mailbox | A genuine email from the fee earner’s real account | No: the message really does come from the firm |
The honest position is that DMARC closes one route completely and leaves the other two open. It is still worth doing. The forged exact domain is the easiest route, it needs no hacking, and without a policy of quarantine or reject nothing asks receiving systems to stop it. The NCSC calls reject the best way to prevent spoofing of your email.[4]
What email authentication adds
- Mail systems at clients, lenders and other firms are asked to refuse or junk messages that forge your domain, instead of delivering them beside your real correspondence.[5]
- DMARC reports show when someone else is sending as your domain, which is often the first sign of a campaign.[5]
- Messages that forge your domain to your own staff, such as a fake request from a partner, meet the same policy when your mail system honours DMARC.[5]
The controls that close the other routes
- A clear rule that the firm never changes bank details by email, repeated in engagement letters and email footers. The SRA suggests telling clients exactly that.[2]
- Call-back checks on a number already held, never one given in the email. Take Five advises confirming payment details, or changes to them, in person or by phone on a trusted number.[1]
- A small test payment before the full amount, which Take Five also suggests.[1]
- Multi-factor authentication on every mailbox, with alerts for new sign-ins and new forwarding rules, which criminals use to follow a transaction quietly.
- Staff who handle payments trained to read the address, not just the display name, and to treat any change of details as a reason to stop and call.
- A named person who approves any payment made on the strength of an email, with the call-back recorded on the file.
If a payment has already been diverted
- Call the bank that sent the payment at once: the sooner it knows, the better the chance of stopping or recovering the money.
- Report it to the police, and tell the client and anyone else in the transaction by phone rather than by email.
- Assume the mailbox involved may be compromised: change its password, review its sign-ins and forwarding rules, and check its multi-factor authentication.
- Keep the emails, their headers and the payment records, which are the evidence the bank, the police and your insurer will ask for.
- Take advice on your firm’s own reporting obligations, which this guide does not cover.
Afterwards, work out which of the three routes the criminal used. If it was a forged exact domain, the fix is in your DNS records. If it was a lookalike domain or a compromised mailbox, the fix is in accounts, habits and call-back checks.
What the SRA’s advice says about email
The SRA’s advice on reducing the risk of cybercrime mentions DMARC, which the NCSC recommends, among the ways to prevent email modification fraud and phishing, alongside practical checks before money moves.[2] It does not set a particular DMARC policy for firms. Whatever the regulatory position in a given case, a firm is better placed when it can show what it put in place, and when.
A practical order of work
- Check your domain to see whether it publishes DMARC, and at which policy.
- Confirm multi-factor authentication on every mailbox, and review existing forwarding rules.
- Write down, and tell clients, how bank details are and are not communicated.
- Finish email authentication: every sending service passing, then quarantine, then reject.
- Record each step with its date, so that the firm can show what it did.
mailcounsel does the fourth and fifth steps with your IT provider. It is a technology service, not a law firm, and this guide is general technical information rather than legal advice. To talk through your firm’s position, arrange a 20-minute scope call.
Next step
See what your domain publishes today.
The free check reads your public DNS records. The scope call takes twenty minutes, with your IT provider if you like.
Sources
- Conveyancing scams. Take Five to Stop Fraud. Checked 10 September 2026.
- How to reduce the risk of being affected by cybercrime. Solicitors Regulation Authority, 23 November 2020. Checked 10 September 2026.
- Fraud remains a national security threat as criminals steal almost £1.3 billion. UK Finance, 15 June 2026. Checked 10 September 2026.
- Email security and anti-spoofing: reject spoof emails. National Cyber Security Centre, 7 October 2019. Checked 10 September 2026.
- Set up DMARC to validate email in Microsoft 365. Microsoft Learn, updated 17 July 2026. Checked 10 September 2026.