Email authentication in Australian accounting and financial advice

A national scan of 70 practices, June and July 2026

No sector's email is trusted the way an accountant's is. A client who receives an email from their accountant saying pay this amount to this account, before this date, pays it, because that is the whole arrangement. Tax debts, super contributions, ASIC fees and trust distributions all move on an accountant's word, delivered by email, often at exactly the deadline pressure that makes a client act without ringing first. A forged payment instruction in a practice's name is among the most valuable emails an attacker can send, and whether a given practice's domain can be used to send it is not guesswork. It is a matter of public record, and it can be checked from the outside.

So I scanned the email authentication of 70 Australian accounting and financial advice practices across June and July 2026, 69 of them with a domain that resolves. The result is the strongest of any sector I have scanned, and it still leaves a third of the profession exposed. 22 of the 69, 32 percent, publish nothing that would stop someone forging mail in their name.

Open to forgery means one of two things. The practice publishes no DMARC record at all, leaving the domain completely unprotected, or it publishes DMARC set to p=none, which monitors and reports but blocks nothing. Of the 22, 6 have no record and 16 sit at p=none, the more deceptive of the two, because it reads as protection on paper while a spoofed sender still arrives. The 47 practices at p=quarantine or p=reject, 68 percent, actually stop the forgery, the highest enforcement rate of any sector in the pool.

DMARC posture of 69 Australian accounting and financial advice practices with a resolving domain, June and July 2026. "Open" to forgery is no enforcing DMARC, meaning no record or p=none.
DMARC posture Practices Share
Enforcing (reject or quarantine)4768%
Monitor only (p=none)1623%
No DMARC record69%
All practices69100%

The strong sector rate cuts both ways for the practices still open. Across the sectors I have scanned, roughly six in ten domains are open to forgery, so a forged email is, in a bleak sense, unremarkable. In accounting, more than two thirds of practices enforce, which means clients of this profession are being trained that mail from their accountant is real. The 22 practices still open are exposed inside a sector whose reputation says otherwise, and their clients' guard is down accordingly.

Forgery is the exposure a practice cannot see. There is a second fault it often can. 2 of the 69 publish no SPF record at all, and 2 more publish an SPF record grown past the ten-lookup limit, the point at which many receivers stop checking and fail the record outright. Small counts, but the mail that quietly fails in this profession is a lodgement reminder or a payment deadline, and it does not bounce. It lands in spam while the date it carried passes.

Email authentication is the control that fails silently. Nothing bounces, nobody is told, and a practice has no way of knowing its domain is the one carrying the forged payment instruction to its own clients. The records sit in public DNS the whole time. You can read your own practice's in about a minute, and if they need work, that is what the deliverability service is for.

This scan follows the same method as the others, read from public DNS, counted one organisation at a time. How the scans work.

These scans continue sector by sector. If you want the next one when it is published, ask by email. It will come from me when the report is out, and nothing else will follow it.