Email authentication in Australian real estate agencies
A national scan of 234 agencies, June 2026
A real estate agency moves money it does not own. A deposit on a sale, the proceeds at settlement, a month of rent on its way to a landlord, a bond lodged and later returned. Most of it moves on the strength of an email carrying the agency's trust account details. If someone can send an email that appears to come from the agency, carrying different account details, the money goes to them instead, and by the time anyone notices, the funds are gone. Whether a given agency's domain can be used to send that email is not guesswork. It is a matter of public record, and it can be checked from the outside.
So I scanned the email authentication of 234 Australian real estate agencies in June 2026. 133 of them, 57 percent, publish nothing that would stop someone forging mail in their name. A forged "our trust account details have changed" email from any of those agencies would reach a buyer or a tenant looking entirely legitimate, because the agency's domain does nothing to reject it.
Open to forgery means one of two things. The agency publishes no DMARC record at all, leaving the domain completely unprotected, or it publishes DMARC set to p=none, which monitors and reports but blocks nothing. Of the 133, 75 have no record and 58 sit at p=none, the more deceptive of the two, because it reads as protection on paper while a spoofed sender still arrives. Only the 101 agencies at p=quarantine or p=reject actually stop the forgery.
| DMARC posture | Agencies | Share |
|---|---|---|
| Enforcing (reject or quarantine) | 101 | 43% |
| Monitor only (p=none) | 58 | 25% |
| No DMARC record | 75 | 32% |
| All agencies | 234 | 100% |
Forgery is the exposure an agency cannot see. There is a second fault it often can. 28 of the 234 publish no SPF record at all, and nine more publish an SPF record grown past the ten-lookup limit, the point at which many receivers stop checking and fail the record outright. For an agency, the email that quietly fails is the one a tenant or a buyer was waiting on, and it does not bounce. It lands in spam, unseen, while the deadline it carried passes.
Real estate sits close to the middle of the sectors I have scanned, where about 60 percent are open to forgery. That is not reassurance. It means the agency down the road is exposed in the same way, and so is the one holding a deposit right now.
Email authentication is the control that fails silently. Nothing bounces, nobody is told, and an agency has no way of knowing its domain is the one carrying the forged trust-account email. The records sit in public DNS the whole time. You can read your own agency's in about a minute, and if they need work, that is what the deliverability service is for.
This scan follows the same method as the others, read from public DNS, counted one organisation at a time. How the scans work.
These scans continue sector by sector. If you want the next one when it is published, ask by email. It will come from me when the report is out, and nothing else will follow it.