A trust account and a DNS record fail the same way.

A criminal law advocate I follow posted about a Sydney case last month, a real estate agent sentenced in the Parramatta Local Court after misusing $539,000 in client deposits. The NSW Government's own account of the case is worth reading in full, but the shape of it is simple. Between October and December 2023, the agent drew on the business trust account to repay loans on her own home and to buy an office, including one occasion where she misused a $190,000 house deposit.

A trust account exists for exactly one reason, so a deposit can sit somewhere neither party controls until settlement. The buyer doesn't hold it, the vendor doesn't hold it, the agent doesn't hold it either, not really, they only administer it. That's the whole design, remove any one party's ability to touch the money unilaterally, and the arrangement only works if that separation is actually enforced day to day, not just written into the agency's obligations.

I read that case and thought about DMARC.

A DMARC record does the same job for a domain, it exists so a business's name can't be attached to mail nobody there sent. But the design only works at enforcement, and most DMARC records sit at p=none, the monitoring policy, published because someone was told to have one and never moved past that point. A trust account and a DNS record are both safeguards that exist on paper long before anyone checks whether they're actually stopping the thing they're meant to stop.

The consumer in the Zhou case eventually got their money back. It just took one buyer 15 months to see the full $123,000 returned, and only after they engaged a lawyer and lodged a complaint with NSW Fair Trading. Nobody in that chain benefited from the trust account existing until someone outside the arrangement forced the question of whether it was working.

None of this means agents or DMARC records are the problem. The professionals doing this correctly vastly outnumber the ones who don't, and most domains at p=none aren't hiding anything, they're mid-way through a rollout nobody finished. The honest failure here isn't malice, it's a safeguard set up once and never checked again.

The standard advice for both is the same, and it's where the trap sits. Have a trust account, have a DMARC record. Nobody's advice says check whether either is doing what it claims, because checking is ongoing work with no obvious deadline, while installing the safeguard has a deadline built in, a form to lodge, a record to publish.

The pattern generalises past both of these. Any arrangement that shifts risk away from an individual only works if somebody is actually watching it, and watching is the part every checklist skips because it can't be finished and ticked off.

I scan for the DNS version of this every week. The trust account version just got a name and a court date attached, but it's the same finding.

Back to Writing