Email authentication in Australian wineries

A scan of 124 independent wineries across five regions, June 2026

A wine club runs on a short list of emails a year and the trust behind them. Members hand over a card, agree to a release each season, and act on what the winery sends because they know the sender. If someone can send an email that appears to come from the winery, they reach that same list of members, each with a card on file and a habit of saying yes. A message in the winery's name asking a member to confirm their details, claim an allocation, or re-enter a declined payment would arrive looking entirely legitimate, because the domain it came from does nothing to reject it.

I scanned the public email authentication of 124 wineries across five Australian wine regions, in June 2026. 82 of them, two in three, publish nothing that would stop someone forging mail in their name.

Open to forgery means one of two things. The winery publishes no DMARC record at all, leaving the domain completely unprotected, or it publishes DMARC set to p=none, which monitors and reports but blocks nothing. Of the 82, 32 have no record and 50 sit at p=none, the more deceptive of the two, because it reads as protection on paper while a spoofed sender still arrives. Only the 42 wineries at p=quarantine or p=reject stop the forgery. A further 11 publish neither an SPF nor a DMARC record, open on both counts.

The gap runs across every region, and one stands apart.

Share of wineries open to forgery, by region, highest to lowest. The vertical marker is the 66% national rate. The regional samples are modest.

Margaret River is widest, with twenty of twenty-three wineries open, close to nine in ten. The other four regions sit together near three in five, from Barossa Valley at 60 percent up to Yarra Valley at 65, so outside Margaret River the problem is steady rather than regional. The regional samples are modest, so read the order as the shape of the thing rather than a precise ranking.

Email authentication of 124 wineries across five Australian wine regions, June 2026. "Open" is no enforcing DMARC (no record or p=none); "Wide open" is no SPF or DMARC at all.
Region Wineries Open No DMARC p=none Enforcing Wide open
Margaret River 23 20 7 13 3 3
Yarra Valley 20 13 6 7 7 2
Hunter Valley 33 20 9 11 13 5
McLaren Vale 23 14 5 9 9 0
Barossa Valley 25 15 5 10 10 1
National 124 82 32 50 42 11

Forgery is the exposure a winery cannot see. There is a second fault it often can. Thirteen of the 124 publish an SPF record grown past the ten-lookup limit, the point at which many receivers stop checking and fail the record outright. For a winery that runs a club, the email that fails is the one the season turns on, the release notice, the pack confirmation, the renewal. It does not bounce. It lands in spam for a share of members who never see it, the charge goes through anyway, and the first anyone hears of it is a confused member or a billing dispute.

The scan reads only public DNS, the same records any mail server checks and any attacker can read, for 124 wineries across five Australian wine regions, in June 2026. A winery counts as protected only at p=quarantine or p=reject. No winery is named, because the point is the shape of the problem, not a list of targets.

Email authentication is the control that fails silently. Nothing bounces, nobody is told, and a winery has no way of knowing its domain is the one carrying a forged email to its own members, or quietly dropping the release notice into spam. The records sit in public DNS the whole time. You can read your own winery's in about a minute, and if they need work, that is what the deliverability service is for.

This scan follows the same method as the others, read from public DNS, counted one organisation at a time. How the scans work.

These scans continue sector by sector. If you want the next one when it is published, ask by email. It will come from me when the report is out, and nothing else will follow it.