Email authentication in Australian online retail
A national scan of 433 retailers, June and July 2026
An online retailer's relationship with its customers is almost entirely email. The order confirmation, the shipping notice, the tracking link, the refund, every one of them arrives in the retailer's name and every one of them trains the customer to click what the retailer sends. Parcel phishing works because of that training. A forged "there is a problem with your delivery" email in a retailer's name, sent to people who really are waiting on a parcel, is one of the most reliable lures in use, and whether a given retailer's domain can be used to send it is not guesswork. It is a matter of public record, and it can be checked from the outside.
So I scanned the email authentication of 433 Australian e-commerce and retail businesses across June and July 2026. 215 of them, 50 percent, publish nothing that would stop someone forging mail in their name.
Open to forgery means one of two things. The retailer publishes no DMARC record at all, leaving the domain completely unprotected, or it publishes DMARC set to p=none, which monitors and reports but blocks nothing. Retail is the sector where the second kind dominates. Of the 215, only 49 have no record while 166 sit at p=none, which suggests plenty of retailers started the job, turned monitoring on, and never took the step that makes it protection. A p=none record reads as done on a checklist while a spoofed sender still arrives. Only the 218 retailers at p=quarantine or p=reject actually stop the forgery.
| DMARC posture | Retailers | Share |
|---|---|---|
| Enforcing (reject or quarantine) | 218 | 50% |
| Monitor only (p=none) | 166 | 38% |
| No DMARC record | 49 | 11% |
| All retailers | 433 | 100% |
Forgery is the exposure a retailer cannot see. There is a second fault that costs it money directly. 30 of the 433 publish no SPF record at all, and 21 more publish an SPF record grown past the ten-lookup limit, the point at which many receivers stop checking and fail the record outright. A retailer's SPF record grows one platform at a time, the store, the mailer, the helpdesk, the reviews tool, until one addition tips it over the limit and nobody notices. The mail that quietly fails is the order confirmation and the campaign the quarter was planned around, and it does not bounce. It lands in spam, and the retailer reads the silence as a soft month. The large mailbox providers now require aligned authentication from bulk senders, so a retailer sending any volume is being graded on these records already.
Retail sits at the better end of the sectors I have scanned, and it is still a coin flip. Across the pooled 3,375 domains, 2,007 (59 percent) are open, so retail's even split is an improvement on the field. The difference is that a retailer's name is a lure with a mailing list attached.
Email authentication is the control that fails silently. Nothing bounces, nobody is told, and a retailer has no way of knowing its domain is the one carrying the forged parcel email to its own customers. The records sit in public DNS the whole time. You can read your own store's in about a minute, and if they need work, that is what the deliverability service is for.
This scan follows the same method as the others, read from public DNS, counted one organisation at a time. How the scans work.
These scans continue sector by sector. If you want the next one when it is published, ask by email. It will come from me when the report is out, and nothing else will follow it.