Email authentication in Australian financial advisers

A scan of 66 advisers, July 2026

Across every sector I have scanned, about 60 percent of businesses publish nothing that would stop someone forging mail in their name. Financial advisers are the exception, and the exception is worth reading carefully, because it cuts both ways.

I scanned the email authentication of 66 Australian financial advisers in July 2026. 23 of them, just over a third, publish nothing that would stop a forged email. That is the lowest rate of any sector I have looked at, and it is still one adviser in three. The sample is smaller than the sector scans, 66 advisers, so read it as the shape of the thing rather than a precise rate.

Open to forgery means the adviser publishes no DMARC record at all, or publishes DMARC set to p=none, which monitors and reports but blocks nothing. Of the 23, nine have no record and 14 sit at p=none. The other 43 enforce, at p=quarantine or p=reject, and that is the highest share of any sector, which is the half of the finding worth crediting.

DMARC posture of 66 Australian financial advisers, July 2026. "Open" to forgery is no enforcing DMARC, meaning no record or p=none.
DMARC posture Advisers Share
Enforcing (reject or quarantine)4365%
Monitor only (p=none)1421%
No DMARC record914%
All advisers66100%

The reason it matters more here than the raw number suggests is what an adviser's email carries. Client money moves on instruction, a rollover, a contribution, a change to where a distribution or a pension payment lands. A forged email in the adviser's name asking a client to confirm new account details reaches someone who is used to acting on exactly that kind of message, from exactly that sender. For the third of advisers that do not enforce, that email would arrive looking entirely legitimate.

The two in three that enforce did something specific, and it held. Email authentication is the control that fails silently, so the ones who have it right cannot see the attempts it turns away, and the ones who do not have no way of knowing their domain is the one carrying the forged instruction. The records sit in public DNS the whole time. You can read your own in about a minute, and if it needs work, that is what the deliverability service is for.

This scan follows the same method as the others, read from public DNS, counted one organisation at a time. How the scans work.

These scans continue sector by sector. If you want the next one when it is published, ask by email. It will come from me when the report is out, and nothing else will follow it.