Preventing misdirected email in a law firm.
Autocomplete, reply-all, the wrong attachment — the error is human and universal. Every prevention control that exists, where each one fails, and how firms stack them.

First principles
The error, in plain terms.
Misdirected email is not a technology failure and rarely a knowledge failure. Autocomplete offers the wrong "John," reply-all goes where reply was meant, yesterday's draft rides along as today's attachment. In the Verizon DBIR's error data, misdelivery accounts for 88% of error-related breaches; 91% of those are classified as plain carelessness, not process or system failure.1 The lawyer is not the villain; a workflow that depends on perfect attention is. The duties this error triggers are covered in the rules guide. This one is about stopping it, and about knowing when you didn't.
The timeline of an error
Every control acts at one of four moments.
Before send
Policy & training
A written policy for what may move by email and to whom, naming conventions that keep matters distinct, and training that keeps the risk in view. Necessary — the rules assume it — but never sufficient: the DBIR classifies 91% of misdelivery as momentary carelessness, and training does not fix a moment's attention.1
At send
Friction & pre-send DLP
External-recipient banners, attachment checks, and data-loss-prevention rules that warn or block before the message leaves. Effective against errors the sender can see when prompted — and blind to the ones that look correct: the wrong John Smith reads exactly like the right one. Over-tuned warnings breed the click-through reflex.
Seconds after
Delay windows
Gmail's Undo Send holds a message for at most 30 seconds — it delays delivery, it does not retrieve anything.2 Outlook's recall works only inside the same Microsoft 365 organization; a message to opposing counsel, a client, or any external address cannot be recalled.3 Cheap and worth enabling — for the mistakes noticed instantly.
After delivery
Detection & review
The layer the other three cannot replace. Every notification duty — ABA Formal Opinion 483, PIPEDA, Quebec's Law 25 — starts its clock when the firm knows. A systematic review of what actually left the firm is the only control that bounds the time between the error and the knowing.4
The blind spots
What the usual stack still misses.
The lapse
Attention fails silently
Training raises awareness; it cannot guarantee attention at 6:40 p.m. on a filing day. The senders in the error data are not untrained — they are busy. A control that depends on the human noticing is a control that fails exactly when the human is most likely to err.
The invisible error
Wrong can look right
Pre-send warnings interrupt the sender and ask: are you sure? For a stale autocomplete entry or a lookalike address, the honest answer is yes — it looks correct. The most damaging misdirections are precisely the ones no banner can make visible at the moment of sending.
The closed window
Recall is mostly myth
Thirty seconds of undo, recall that stops at the firm's own walls — then nothing.2,3 Most misdirections are noticed later: when the real recipient asks where the document is, or the wrong one replies. By then every send-side control has long since run out.
The gap the rules actually measure
No regime punishes a firm for a typo. What the rules measure is the distance between the error and the response — and every clock starts at knowledge.4
Detection speed decides:
- Whether privilege survives — courts weigh how promptly the error was addressed
- When Opinion 483's duty to notify the client begins
- Whether PIPEDA and Law 25 reporting happens on the firm's terms or a regulator's
- Whether the client hears it from you — or from the stranger who received the file
A firm that detects in minutes argues diligence. A firm that finds out from opposing counsel argues nothing.
The failure mode
The data is unambiguous.
88%
of error-related breaches are misdelivery — sending information to the wrong recipient.1
91%
of those are plain carelessness — not process or technology failure.1
52%
of legal-sector data breaches come from sharing with the wrong person — most often by email.5
Read together: the dominant breach in a law firm is an attentive professional having one inattentive second. Controls that ask for more attention treat the symptom. A layered defense assumes the lapse will happen — and makes sure the firm knows before it matters.
In practice
The layered defense, step by step.
Write the email policy first.
What categories of client information may move by email, to whom, and with what protections — the judgment the duties expect firms to make deliberately. Every later layer enforces this document; without it they enforce nothing in particular.
Train for reporting, not perfection.
The training that changes outcomes is not "don't make mistakes" — it is "report the mistake in minutes, without fear." Every notification clock starts at knowledge; a culture of silence is a compliance risk in itself.
Turn on the native controls today.
Thirty-second undo in Gmail, delayed-delivery rules and external-recipient banners in Outlook — near-zero cost, real (if narrow) coverage.2,3 No firm should skip them; no firm should mistake them for a system.
Add pre-send DLP where volume warrants it.
Rules that catch client identifiers or privileged markers heading to unexpected domains earn their keep in high-volume practices. Tune conservatively: a warning lawyers click through by reflex protects no one.
Close the loop with post-send review.
The only layer that catches the invisible error (the send that looked right) and the only one that bounds the error-to-knowledge gap the rules measure. A systematic compliance review of every outgoing email, flagging misdirected recipients and policy violations while there is still time to act, is the specific job Super's email compliance review was built for.
Rehearse the first hour.
Who contains, who assesses materiality, and who notifies under Opinion 483, PIPEDA, or Law 25 are all decided before the incident. The duties are mapped in the rules guide; the rehearsal turns them into muscle memory.
Questions firms ask.
What comes up when firms build the stack — answered from the sources above.
Can we recall an email sent outside the firm?
No. Outlook's recall works only when sender and recipient are inside the same Microsoft 365 organization — a message to a client, opposing counsel, or any external address cannot be recalled, and external mail systems ignore recall requests entirely. Gmail's Undo Send is not a recall at all: it delays delivery by up to 30 seconds, after which nothing can be pulled back. Any plan built on retrieving external email is built on a myth.
Is a 30-second undo window worth enabling?
Yes — it is free and it catches the mistakes noticed in the act of clicking send. But the error data shows most misdirections are noticed much later: when the intended recipient follows up, or the unintended one replies. A delay window is a seatbelt for one narrow class of error, not a prevention system.
Does encryption prevent misdirected email?
No — it solves a different problem. Encryption protects a message from interception in transit; a misdirected email is delivered, perfectly securely, to the wrong person. If the recipient can authenticate (or the portal link simply lands in their inbox), encryption offers no protection against misdirection at all. The two controls address separate duties and firms need both judgments.
Do clawback agreements protect privilege after a misdirection?
They help, but they are not self-executing. Under Federal Rule of Evidence 502(b) and its state analogues, surviving inadvertent disclosure typically requires that reasonable steps were taken to prevent it and that the holder acted promptly to rectify it once known. Both prongs reward systems: layered prevention supports the first, fast detection supports the second. A clawback letter sent weeks late, after the firm finally learned of the error, argues against itself.
What should happen in the first hour after we discover one?
Contain (request deletion, disable shared links), assess what was in the message and whether material client confidences or personal information are involved, and route to the notification analysis: Opinion 483 for clients, PIPEDA or provincial regimes in Canada, Law 25 in Quebec. The duties — and their triggers — are laid out with primary sources in the companion rules guide. The firms that handle the hour well are the ones that decided the roles before the day arrived.
You can't prevent every misdirected email. You can always know.
The fifth layer above is the one email providers don't ship. Super reviews every outgoing email the moment it's sent and delivers an immediate compliance audit — bounding the gap between the error and the firm knowing.
Sources
- Verizon Data Breach Investigations Report (2026) — misdelivery as the dominant error action in confirmed breaches.
- Google, "Send or unsend Gmail messages" — Undo Send cancellation window (maximum 30 seconds; delays delivery rather than retrieving).
- Microsoft, "How to recall an email in Outlook: requirements, limitations" — recall requires both mailboxes in the same organization; external messages cannot be recalled.
- ABA Formal Opinion 483 (2018); PIPEDA mandatory breach reporting; Quebec Law 25 confidentiality-incident obligations. These duties are detailed, with primary sources, in the companion rules guide.
- Information Commissioner's Office data analyzed by NetDocuments, reported by Legal IT Insider.
- Federal Rule of Evidence 502(b) — inadvertent disclosure and the reasonableness of steps taken to rectify the error.
This guide is general information for law firm operations, not legal advice. Product capabilities and provider settings change; verify current documentation and your bar or law society's guidance for your jurisdiction.