Email authentication in Australian member organisations and charities

A national scan of 412 organisations, June and July 2026

A member organisation is built on the willingness of its members to act on what it sends. The renewal notice, the event invitation, the appeal at the end of the financial year, each one arrives in the organisation's name and each one asks for money or details, and members give both because they trust the sender. That trust is exactly what a forged email spends. A fake renewal notice or donation appeal in the organisation's name reaches people who have paid it before and expect to pay it again, and whether a given organisation's domain can be used to send that email is not guesswork. It is a matter of public record, and it can be checked from the outside.

So I scanned the email authentication of 412 Australian member organisations and charities across June and July 2026. 211 of them, 51 percent, publish nothing that would stop someone forging mail in their name.

Open to forgery means one of two things. The organisation publishes no DMARC record at all, leaving the domain completely unprotected, or it publishes DMARC set to p=none, which monitors and reports but blocks nothing. Of the 211, 58 have no record and 153 sit at p=none, the more deceptive of the two, because it reads as protection on paper while a spoofed sender still arrives. Only the 201 organisations at p=quarantine or p=reject actually stop the forgery.

DMARC posture of 412 Australian member organisations and charities, June and July 2026. "Open" to forgery is no enforcing DMARC, meaning no record or p=none.
DMARC posture Organisations Share
Enforcing (reject or quarantine)20149%
Monitor only (p=none)15337%
No DMARC record5814%
All organisations412100%

Forgery is the exposure an organisation cannot see. There is a second fault this sector carries more than any other I have scanned. 37 of the 412 publish an SPF record grown past the ten-lookup limit, the point at which many receivers stop checking and fail the record outright, and 22 more publish no SPF record at all. The over-limit count is the highest of any sector in the pool, and it fits how these organisations run. A membership platform here, a newsletter tool there, an events system, a fundraising platform, each one added to the record over the years and none ever removed, until the record fails for every sender at once. The mail that quietly fails is the renewal notice and the appeal, and it does not bounce. It lands in spam while the organisation reads the silence as member fatigue.

Member organisations sit in the middle of the sectors I have scanned, where about six in ten of the pooled domains are open to forgery. The organisations in this pool are often run lean, with IT handled by a volunteer or a general provider, which is exactly why a control that fails silently stays failed.

Email authentication is the control that fails silently. Nothing bounces, nobody is told, and an organisation has no way of knowing its domain is the one carrying a forged appeal to its own members. The records sit in public DNS the whole time. You can read your own organisation's in about a minute, and if they need work, that is what the deliverability service is for.

This scan follows the same method as the others, read from public DNS, counted one organisation at a time. How the scans work.

These scans continue sector by sector. If you want the next one when it is published, ask by email. It will come from me when the report is out, and nothing else will follow it.