Email authentication in Australian tourism and accommodation

A national scan of 275 operators, June and July 2026

A booking runs on email between strangers. A guest who has never met the operator pays a deposit on the strength of a confirmation, then a balance on the strength of a follow-up, often to an account number the email itself supplies. The guest has no other relationship to check against, no voice they would recognise, no counter to walk up to. If someone can send an email that appears to come from the venue, carrying different account details or a new payment link, the guest has almost no way to tell, and the money goes to the attacker instead. Whether a given operator's domain can be used to send that email is not guesswork. It is a matter of public record, and it can be checked from the outside.

So I scanned the email authentication of 275 Australian tourism, accommodation and booking businesses across June and July 2026. 163 of them, 59 percent, publish nothing that would stop someone forging mail in their name. That is the widest exposure of the six sector pools large enough to publish, in the one industry where the customer is a stranger acting on email alone.

Open to forgery means one of two things. The operator publishes no DMARC record at all, leaving the domain completely unprotected, or it publishes DMARC set to p=none, which monitors and reports but blocks nothing. Of the 163, 75 have no record and 88 sit at p=none, the more deceptive of the two, because it reads as protection on paper while a spoofed sender still arrives. Only the 112 operators at p=quarantine or p=reject actually stop the forgery.

DMARC posture of 275 Australian tourism, accommodation and booking businesses, June and July 2026. "Open" to forgery is no enforcing DMARC, meaning no record or p=none.
DMARC posture Businesses Share
Enforcing (reject or quarantine)11241%
Monitor only (p=none)8832%
No DMARC record7527%
All businesses275100%

Forgery is the exposure an operator cannot see. There is a second fault it often can. 35 of the 275 publish no SPF record at all, and 14 more publish an SPF record grown past the ten-lookup limit, the point at which many receivers stop checking and fail the record outright. For an operator, the email that quietly fails is the confirmation a guest was waiting on, and it does not bounce. It lands in spam, the guest assumes the booking never went through, and the room sells twice or not at all.

Tourism sits at the wide end of the sector pools I have scanned. Most of the other sectors cluster around the halfway mark, so this is not one industry's oversight, it is what the records of Australian small business look like when nobody has ever read them, only more so here.

Email authentication is the control that fails silently. Nothing bounces, nobody is told, and an operator has no way of knowing its domain is the one carrying the forged deposit email. The records sit in public DNS the whole time. You can read your own business's in about a minute, and if they need work, that is what the deliverability service is for.

This scan follows the same method as the others, read from public DNS, counted one organisation at a time. How the scans work.

These scans continue sector by sector. If you want the next one when it is published, ask by email. It will come from me when the report is out, and nothing else will follow it.