← Industries
For Law Firms

One misdirected email can waive privilege on a matter you've spent months protecting.

Autocomplete doesn't know the difference between "John Smith, your associate" and "John Smith, opposing counsel." At a firm, that isn't an awkward correction — it's a disclosure you can't take back.

The problem

It's not the careless associate. It's the deadline.

The misdirected email doesn't happen on a slow Tuesday morning. It happens at 8:52pm, eight minutes before a filing deadline, when someone is drafting a reply to a client named John Smith while a discovery email thread with opposing counsel's John Smith is still open in another window. Outlook autocomplete fills in whichever John it saw more recently. Nobody notices until the read receipt comes back from the wrong side.

At most firms, that single click is the difference between a routine status update and a violation of the duty of confidentiality under ABA Model Rule 1.6 — or the functional equivalent in your jurisdiction's rules of professional conduct. Once privileged material lands in an adversary's inbox, you can't un-send it. Courts have found subject-matter waiver over exactly this kind of accident, and even where a "claw-back" or inadvertent-disclosure clause exists in a protective order, you're now spending partner hours negotiating around a mistake instead of billing the matter.

And it's rarely just embarrassment. A privileged email sent to the wrong recipient can trigger a conflicts review, a malpractice notification to your carrier, or a bar complaint if the client finds out before you tell them. The firm's exposure doesn't scale with how "obvious" the mistake was — it scales with what was in the email.

What the sender sees in Outlook — before the email leaves the outbox.

What firms already try

"Double-check before you send" doesn't survive a busy Tuesday.

Most firms' answer to this risk is a policy, not a system: review the recipient list before you hit Send. That works exactly until the associate is juggling four matters at once and the email is the fortieth one that day. Policy that depends on a tired human remembering to slow down at the exact moment they're least likely to isn't a control — it's a hope.

Enterprise DLP (data loss prevention) tools exist, but they're built for a different problem — scanning content for social security numbers or credit card patterns — and they're expensive, IT-heavy to configure, and blind to the thing that actually matters at a law firm: who is on the thread, not what's in the body. A DLP rule won't catch "opposing counsel got Cc'd," because nothing in the text looks sensitive. The problem is purely about the recipient list, and most tools weren't built to look there.

Some firms add a "delay send" rule — a five-minute window to recall a message. It helps sometimes. It does nothing if the recipient already has their inbox open, which, at 8:52pm before a deadline, is often exactly when they do.

How Sendasta helps

A check that runs at the one moment it matters — right before Send.

Sendasta sits inside Outlook and checks the recipient list — To, Cc, and Bcc — against rules your firm sets, at the exact moment someone clicks Send. It doesn't read the email body or attachments, and nothing is transmitted to a server: the check runs locally, which matters when the thing you're protecting is privilege in the first place.

Three rule types cover how firms actually get burned:

  • Blocked domains — flag a competing firm or an adversary's domain outright. If it shows up as a recipient, the send is paused before it goes out.
  • No-combine pairs — the one built specifically for the John Smith problem. Flag two domains that should never appear on the same thread (your client and opposing counsel, for instance), and Sendasta blocks the send if both are present, regardless of how they got there.
  • Trusted pairs — for the legitimate exceptions (co-counsel, a client's outside vendor), mark the combination as trusted once and you won't be interrupted again.

For firm-wide protection, an admin sets these policies once and pushes them to every attorney's Outlook via the Microsoft 365 Admin Center — no per-user setup, no relying on each associate to configure it themselves. Personal use (checking just your own To field) is free and takes minutes to install if you want to try it before rolling it out firm-wide.

See pricing for firm-wide deployment
Questions from firms

Frequently asked

Does Sendasta read the content of my emails or attachments?

No. Sendasta only checks the addresses in the To, Cc, and Bcc fields against your firm's rules. It never opens, scans, or transmits the subject line, body, or attachments — the check happens locally in Outlook at the moment you click Send. Nothing privileged ever leaves your machine.

Can Sendasta stop an email to opposing counsel's domain on a matter where they shouldn't be included?

Yes — that's what "no-combine pairs" are for. You flag two domains that should never appear on the same thread (say, opposing counsel and your client), and if autocomplete or a stray Cc puts both on one email, Sendasta blocks the send until someone reviews it.

Will this slow down associates during a filing deadline?

No — the check runs in under a second and only interrupts you when something actually matches a rule. Every other send goes through exactly as fast as it does today. It's designed for the 9pm deadline crunch, not against it.

Do we need firm-wide IT approval to use this, or can one attorney try it first?

Either works. Personal use (checking your own To field) is free and installs in minutes with no IT involvement. Firm-wide policy — shared blocked domains, no-combine pairs, and Cc/Bcc checking — is the paid tier and typically gets rolled out by IT or a managing partner across everyone at once.

Protect privilege before the send, not after.

Get started free for personal use, or reach out and we'll walk you through setting up firm-wide policy for your team.