Email authentication in Australian small business

Sector by sector, read from public DNS and published with the data.

Email authentication is the rare control that fails silently. A domain can be open to anyone forging mail in its name, or quietly landing its own mail in spam, with nothing bouncing and nobody told. It is also the one part of a business's posture that can be read from the outside, from the same public DNS an attacker checks, which makes it measurable across a whole sector at once.

So I read it, sector by sector. Each scan covers every organisation in a defined group, reports what their records actually do, and is published in full with the data. This page pools those scans into one picture. How the scans work sets out what is read, what each figure is counted against, and what the scan deliberately does not claim.

The pooled picture

60% 2,598 of 4,320 Australian business domains

publish nothing that would stop someone forging mail in their name

as found, 26 June to 4 August 2026

That is 4,336 businesses scanned, 4,320 of them with a domain that resolves, and the share has held near enough steady as the pool has grown.

Of the 4,320, 1,177 (27 percent) publish no DMARC record at all, and 1,421 (33 percent) publish DMARC set to monitor only, which reads as protection on paper while a forged sender still arrives. Only 1,722 (40 percent) reject or quarantine a forged message. Set apart from forgery, 446 (10 percent) publish no SPF record at all, and 245 more publish an SPF record grown past the ten-lookup limit, the point at which many receivers stop checking, so their own mail is at risk of failing whether or not anyone forges them.

Every figure on this page is as found, the state of the records on the day of each scan, counted one organisation at a time against the resolved base and reported with the sample floor described in the method. Segments below that floor are named and withheld, never folded in.

By sector

Eleven sectors are now large enough to publish, and they do not cluster. Independent schools and training providers are the tightest, with 53 of 174 (30 percent) open to forgery. Medical, dental and allied health are the widest, at 30 of 42 (71 percent), on the smallest sample that clears the floor. The spread between them is wide enough that industry norm looks like a better predictor of posture than business size, which is not what I expected when the first scan went out. Sectors below the sample floor are withheld rather than shown.

Email authentication by sector, first observation per domain (as found), to 4 August 2026. Each sector counts one domain once. "Open" is no enforcing DMARC, meaning no record or p=none.
Sector Businesses Open Open % No DMARC p=none Enforcing
Medical, dental and allied health423071%102012
Tourism, accommodation and bookings38122860%105123153
Real estate agencies27315958%8970114
Recruitment and staffing agencies*301653%41214
E-commerce and retail52927051%65205259
Member organisations and charities41621451%59155202
Multi-location or franchised businesses47823850%89149240
Accounting and financial advice1597447%264885
Clients of marketing and web agencies*301447%31116
Legal and conveyancing, general scan1807843%3246102
Independent schools and training providers1745330%1934121
Whole scanned pool4,3202,59860%1,1771,4211,722

Sectors below thirty businesses are withheld. The two marked * sit exactly at that floor, and medical, dental and allied health is the next smallest at 42 while carrying the widest figure in the table, so all three are worth reading as indicative rather than exact. The final row is the whole scanned pool, not a total of the rows above: the named sectors account for 2,692 of the 4,320 resolved domains, and the rest were read in scans that carry no sector label.

Some sectors have a full written deep-dive, where the sector is read on its own and the stakes are spelled out.

  1. Email authentication in Australian accounting and financial advice

    A national scan of 70 practices, June and July 2026

  2. Email authentication in Australian member organisations and charities

    A national scan of 412 organisations, June and July 2026

  3. Email authentication in Australian multi-location and franchised businesses

    A national scan of 475 businesses, June and July 2026

  4. Email authentication in Australian online retail

    A national scan of 433 retailers, June and July 2026

  5. Email authentication in Australian tourism and accommodation

    A national scan of 275 operators, June and July 2026

  6. Email authentication in Australian financial advisers

    A scan of 66 advisers, July 2026

  7. Email authentication in Australian real estate agencies

    A national scan of 234 agencies, June 2026

  8. Email authentication in Australian wineries

    A scan of 124 independent wineries across five regions, June 2026

  9. Email authentication in Australian law firms

    A national scan of 252 independent firms, June 2026

Movement over time

Where domains have been read more than once, the later record can be compared against the first. Of 1,470 domains re-checked, 9 had moved to an enforcing DMARC policy by the later read, 1 had added an SPF record, and 49 had added a discoverable DKIM signature. None had dropped an enforcing policy once they had one. The scan counts records gained and not records lost for SPF and DKIM, so those two figures can fall as well as rise between scans.

This is movement, not a sector rate. The re-scanned group is weighted toward domains that were contacted, so it is reported on its own and never mixed into the pooled figure above. It records that records changed and when, not why, because the background era of sender-requirement changes at the large mailbox providers moves records too, and that cannot be told apart from any other cause at the level of a DNS read.

Every figure here traces to a stored scan, counted one organisation at a time against the resolved base, with segments below the sample floor withheld. The full account of what is read and what it means is on the method page.