Original measurement · 2026-08-20

We measured 604 Canadian small-business domains. Most of them can be spoofed.

Almost every article about DMARC quotes a global adoption statistic from a vendor report. We wanted a number for the specific population a Canadian small business actually belongs to, measured directly rather than cited, so we measured it ourselves and are publishing the method along with the result.

Two independent samples, measured from the outside using only information these domains publish to the entire internet. No site is named anywhere in this report.

69.7% and 80.7%

of domains in the two samples publish no enforcing DMARC policy - meaning a stranger can put that domain in the From: line of an email and no receiving mail server has been told to reject it.

What was measured

Four checks, all of them things any stranger can look up about your domain without your permission and without touching your server in any unusual way:

  1. Email spoofing exposure - the public SPF and DMARC records in DNS, and whether the DMARC policy actually enforces anything.
  2. HTTPS certificate - offered during an ordinary handshake: is the chain trusted, does it match the hostname, when does it expire.
  3. Domain registration - the public RDAP record: when does the registration lapse.
  4. Reachability - does the site answer over HTTPS, and does plain HTTP redirect to it.

Three of those four carry a date, which is the reason this is a recurring problem rather than a one-off audit: certificates now live ninety days or less, registrations lapse annually, and SPF records get rewritten during mail migrations and quietly revert. Nobody is told when any of it changes.

Sample A: 522 sites built by 141 web agencies

We started from Canadian web design and marketing agencies, took the client sites each one publishes in its own portfolio, and measured those. 78 of the 141 agencies had a readable portfolio. That produced 533 measurement events over 522 distinct domains - the gap is client sites claimed by two different agencies, and the rates below are per distinct domain, not per event. A further 73 listed sites could not be measured at all and are excluded rather than counted as clean.

FindingSitesShare of 522
DMARC present but set to p=none (monitor only, enforces nothing)18635.6%
No DMARC record at all17834.1%
No SPF record275.2%
Domain registration expires within 60 days224.2%
Site still answers on plain HTTP without redirecting132.5%
SPF ends in +all (permits the whole internet)122.3%
HTTPS certificate expires within 21 days61.1%
Site does not answer over HTTPS at all10.2%

The two email lines are the story. 364 of 522 domains (69.7%) have no enforcing DMARC policy, and it splits almost evenly: 178 never published a DMARC record, and 186 published one and left it at p=none, which reports and enforces nothing. The second group is the interesting one. Those domains did not miss the memo - they acted on it and stopped at the step that protects nobody, which is the shape of a job started and not finished.

The attribution problem, and what it does to the number

A portfolio page is a marketing claim, not a work record. When we required documentary evidence that the agency actually built the site before crediting it, the sample dropped from 522 to 267 attributed sites - roughly half - of which 210 had a finding, a rate of 78.7%. The stricter sample gives a higher rate than the loose one, so the headline is not an artifact of counting sites the agencies never touched.

0 clean sheets out of 29

Restricting to agencies where we could measure at least five client sites leaves 29 agencies. Not one of them had every client site clean. We expected a spread - some agencies careful about this, some not - and there wasn't one. The most defensible reading is that this simply is not on anybody's build checklist: DNS email policy sits outside what a website project is understood to cover, so it is nobody's job by default. We are not claiming these agencies were negligent, and we are not naming any of them.

Sample B: an independent 83-domain small-business sweep

Measured 2026-08-01 against a separate list of Ontario small businesses, with the same code. It is a different population reached a different way, which is the only reason it is worth reporting next to Sample A.

By industry - read the sample sizes first

Splitting 83 domains four ways leaves slices too small to carry a confident rate. We publish them with their sample sizes rather than either hiding them or dressing them up. Our in-house minimum for quoting a rate is 25; rows below it are marked.

IndustrySitesAny findingSpoofableConfidence
Dental3585.7%80.0%meets minimum
Medspa2181.0%81.0%directional only
Home Services1675.0%75.0%directional only
Law1190.9%90.9%directional only

Do not read an industry ranking into that table. With slices this size the differences between them are well inside the noise; the only thing it supports is that no industry in the sample was in good shape.

Check your own domain

You do not have to take any of this on faith, and you should not. The same code that produced these tables runs as a free page - type a domain, get the same four findings in plain English, no signup and no email address. It works on any domain, including ones you do not own, which is how you can sanity-check our numbers against businesses you know.

Run the free perimeter check → Or use any third-party DMARC checker you like and compare - the underlying records are public, so every tool should agree.

How you fix it

For most small businesses this is two DNS records, not a project:

  1. SPF - one TXT record listing the services allowed to send as you, ending in ~all or -all. Ending in +all permits the entire internet and is worse than having none.
  2. DMARC - a TXT record at _dmarc.yourdomain.com. Start at p=none with a reporting address, read the reports until you recognise every legitimate sender, then move to p=quarantine and then p=reject.

Step two is where this data says people stop. Publishing p=none and never advancing it is the single most common state in both samples - the record exists, checkers report "DMARC found", and nothing is enforced.

If that is all you need, do it and you are done. It is a one-time fix and we would rather say so than pretend otherwise.

Method, and the controls that make it checkable

Everything here comes from public data: DNS TXT lookups over DoH, the certificate offered in a normal TLS handshake, a public RDAP registration lookup, and one ordinary page request. Nothing was scanned, probed, guessed or logged into. No site received anything it would not receive from a visitor.

The measuring code runs two controls on every sweep, and a failure on either side aborts the run and prints no rates at all:

Limitations, stated plainly

Neither sample is random. Sample A is drawn from agency portfolios, which over-represents businesses that hired a professional. Sample B is a regional small-business list. Both are populations we can reach and describe; neither licenses a claim about "Canadian business" in general.

Portfolio attribution is unreliable, which is why the strict subset is reported separately above.

Sample A contains 10 domains that are not client businesses at all - review widgets, accessibility plugins and social shorteners linked from the same portfolio pages. All of them measured clean, so leaving them in makes the published rate lower than it should be. We left them in and are telling you instead of removing them: without them the Sample A finding rate would read 73.0% rather than 72.0%.

These are point-in-time readings (2026-08-01 and 2026-08-20). Certificate and registration findings age fastest; any individual domain may have been fixed the next day.

Absence of a finding is not a clean bill of health. Four checks are four checks. A domain with no findings here can still have problems these four do not look at.

We sell a service that monitors exactly this. That is a real interest and you should weigh it. It is also why the free checker and the fix instructions are here in full, and why we would rather you fixed your DNS yourself than bought anything.

Or have it watched for you

Three of the four checks carry an expiry date and change without anyone telling you. A3E's perimeter monitor re-runs all four every month per site, and emails you only when something changes - CA$99/month per site, cancel any time. If your DNS is a one-line fix, fix it; what this buys is that it stays fixed.

Check a domain free See the monitor

Questions

What does "spoofable" mean here?

It means the domain publishes no DMARC policy, or publishes one set to p=none. In both cases a stranger can put that domain in the From: line of an email and receiving mail servers have been given no instruction to reject it. It does not mean the domain has been attacked, and it does not mean the website was hacked. It means one specific public defence is switched off.

Is p=none really no protection?

p=none asks receivers to report what they see and to enforce nothing. It is the correct first step when you are rolling DMARC out, and it is a common place to get stuck: the record exists, a checker says "DMARC found", and the policy never advances to quarantine or reject. In this data, DMARC-present-but-p=none was more common than having no DMARC record at all (35.6% versus 34.1% of measured domains).

Did you attack, scan or log in to any of these sites?

No. Every check is a read of information the domain publishes to the whole internet: DNS TXT records, the certificate offered during a normal HTTPS handshake, the public RDAP registration record, and one ordinary page request. Nothing was probed, guessed or bypassed, and no site is named in this report.

Why won't you publish the list of domains?

Because a named list of domains that can be spoofed is a target list. The aggregate is the useful part, and you can check any single domain yourself in about ten seconds with the free tool linked above, including domains you do not own.

How would I fix this on my own domain?

Publish an SPF record listing the services allowed to send as you, then add a DMARC record and move it from p=none to p=quarantine and eventually p=reject once your reports are clean. For most small businesses this is two DNS records and an afternoon. If that is all you need, do it and you never need to hear from us again.

How current are these numbers?

The agency sample was measured on 2026-08-20 and the small-business sample on 2026-08-01. Certificate and registration expiry are moving targets by definition, so those two lines age fastest. The DMARC picture moves slowly.

Figures on this page are generated directly from the stored raw measurement files and re-verified by an automated control on every operating cycle; if the underlying data changed and this page did not, the control fails. Generated 2026-08-25T23:35:11Z.

← Back to all articles