Email authentication in Australian small business

Sector by sector, read from public DNS and published with the data.

Email authentication is the rare control that fails silently. A domain can be open to anyone forging mail in its name, or quietly landing its own mail in spam, with nothing bouncing and nobody told. It is also the one part of a business's posture that can be read from the outside, from the same public DNS an attacker checks, which makes it measurable across a whole sector at once.

So I read it, sector by sector. Each scan covers every organisation in a defined group, reports what their records actually do, and is published in full with the data. This page pools those scans into one picture. How the scans work sets out what is read, what each figure is counted against, and what the scan deliberately does not claim.

The pooled picture

Across 3,203 Australian businesses scanned between 26 June and 23 July 2026, 3,194 with a domain that resolves, 1,905 of them (60 percent) publish nothing that would stop someone forging mail in their name. That is the headline, and it holds across sectors that otherwise have nothing in common, from real estate to member associations to online retail.

Of the 3,194, 826 (26 percent) publish no DMARC record at all, and 1,079 (34 percent) publish DMARC set to monitor only, which reads as protection on paper while a forged sender still arrives. Only 1,289 (40 percent) reject or quarantine a forged message. Set apart from forgery, 307 (10 percent) publish no SPF record at all, and 182 more publish an SPF record grown past the ten-lookup limit, the point at which many receivers stop checking, so their own mail is at risk of failing whether or not anyone forges them.

Every figure on this page is as found, the state of the records on the day of each scan, counted one organisation at a time against the resolved base and reported with the sample floor described in the method. Segments below that floor are named and withheld, never folded in.

By sector

The picture barely moves from one sector to the next. Between half and three in five are open to forgery in every group large enough to publish, from online retail, where 215 of 433 (50 percent) are open, to tourism operators at 163 of 275 (59 percent). Sectors below the sample floor are withheld rather than shown.

Email authentication by sector, first observation per domain (as found), to 23 July 2026. Each sector counts one domain once. "Open" is no enforcing DMARC, meaning no record or p=none. Sectors below thirty businesses are withheld.
Sector Businesses Open Open % No DMARC p=none Enforcing
Tourism, hospitality and booking27516359%7588112
Real estate agencies23413357%7558101
Member organisations and charities41221151%58153201
Multi-location or franchised47523750%88149238
E-commerce and retail43321550%49166218
All scanned3,1941,90560%8261,0791,289

Some sectors have a full written deep-dive, where the sector is read on its own and the stakes are spelled out.

  1. Email authentication in Australian financial advisers

    A scan of 66 advisers, July 2026

  2. Email authentication in Australian real estate agencies

    A national scan of 234 agencies, June 2026

  3. Email authentication in Australian wineries

    A scan of 124 independent wineries across five regions, June 2026

  4. Email authentication in Australian law firms

    A national scan of 252 independent firms, June 2026

Movement over time

Where domains have been read more than once, the later record can be compared against the first. Of 1,058 domains re-checked, 5 had moved to an enforcing DMARC policy by the later read, 34 had added a discoverable DKIM signature, and none had moved the wrong way. Records move, slowly, and so far only in the safer direction.

This is movement, not a sector rate. The re-scanned group is weighted toward domains that were contacted, so it is reported on its own and never mixed into the pooled figure above. It records that records changed and when, not why, because the background era of sender-requirement changes at the large mailbox providers moves records too, and that cannot be told apart from any other cause at the level of a DNS read.

Every figure here traces to a stored scan, counted one organisation at a time against the resolved base, with segments below the sample floor withheld. The full account of what is read and what it means is on the method page.