Daily Website Report
Research · 2026

50.5% of small businesses can be impersonated by email

We checked the email authentication and HTTPS setup of 1,549 randomly sampled US small business domains. Most would let a scammer send email in their name, and many of their websites show visitors a security warning.

1,549 domains · 1,402 using email · 1,461 with a live website · Updated 2 Oct 2026
50.5%have no enforced DMARC policy, so spoofed email in their name gets delivered
27.8%have no DMARC record at all
7.9%have a missing or broken SPF record
20.3%of websites have no HTTPS, or a certificate browsers reject

Email: who can send as you?

DMARC tells receiving mail servers what to do with email that claims to be from your domain but isn't. Only quarantine and reject actually stop spoofed mail. Base: 1,402 domains that receive email (have MX records).

No DMARC record27.8%
DMARC record is broken0.1%
p=none (monitoring only, spoofed mail still delivered)22.6%
p=quarantine20.5%
p=reject29%
No SPF record4.8%
SPF broken (duplicate records, +all, or over 10 lookups)3.1%
Neither SPF nor DMARC3.9%
Fully protected (valid SPF and enforced DMARC)46.2%

17.2% of domains that do have DMARC collect no reports (no rua= address), so they can't see who is sending as them. DKIM was found at a common selector for 63.1% of domains; DKIM can't be listed from DNS, so treat that as a lower bound.

By email provider

Share of domains without an enforced DMARC policy, by who hosts their email. Paying for Google Workspace or Microsoft 365 doesn't set DMARC up for you.

Microsoft 365 · 43% of domains49.1%
Other / self-hosted · 40.7% of domains52.4%
Mimecast · 8.3% of domains36.2%
Google Workspace · 7.3% of domains64.1%

Websites: what visitors see

Base: 1,461 domains with a live website.

No HTTPS at all12.9%
Certificate not trusted (wrong name, self-signed or incomplete chain)4.9%
Certificate expired2.5%
Certificate expires within 30 days3.8%
http:// doesn't redirect to https:// (of sites with HTTPS)17.8%
Fully correct HTTPS (grade A)65%

By company size

Without enforced DMARC, by number of employees.

1-4 employees · HTTPS problem 22.7%50%
5-9 employees · HTTPS problem 21.9%50.2%
10-19 employees · HTTPS problem 20%54.5%
20-49 employees · HTTPS problem 18.4%50.6%
50-99 employees · HTTPS problem 21.1%50%

By industry

The most common industries in the sample, ranked by the share without enforced DMARC.

Attorneys · HTTPS problem 21.7%59%
Real Estate · HTTPS problem 11.8%58.3%
Insurance · HTTPS problem 15.6%16.7%

Is your business in the 50.5%?

Check your own domain in seconds. Both tools show the exact record or setting that fixes each problem.

Check my DMARC → Check my SSL

Why this matters

Since 2024, Gmail and Yahoo require DMARC from bulk senders, and missing authentication pushes everyone else's mail toward spam too. The bigger risk is fraud: a business without an enforced DMARC policy can't stop someone sending invoices, payment-change requests or password resets that look like they came from its own address. Those emails land with customers and suppliers, who trust them precisely because the address is real.

The website numbers matter for the same reason. An expired or untrusted certificate turns the homepage into a full-page "Your connection is not private" warning, and most visitors leave instead of clicking through.

Methodology

We drew a random sample of US business records that list a website, left out businesses with 100 or more employees, and kept one entry per domain. We excluded social media pages, website builders' shared domains and webmail providers, so every domain is one the business controls. 1,549 domains were checked successfully between their sampling and 2 October 2026.

Each domain was checked with the same code that runs our free DMARC checker and SSL checker: public DNS lookups for MX, SPF, DMARC and common DKIM selectors, then an HTTPS connection to the website to verify its certificate and the http-to-https redirect. Email figures use domains that receive email (have MX records) as the base; website figures use domains with a live website. Segments with fewer than 30 domains are not shown. No individual business is named.

You're welcome to cite these figures. Please link to this page as the source.

Frequently asked questions

What does "can be impersonated by email" mean?

The domain has no DMARC policy that tells receivers to reject or quarantine mail that fails authentication. Without one, a scammer can send email with the business's exact address in the From line and most mailboxes will still deliver it.

Where does the sample come from?

A random sample of US business records that list a website, de-duplicated by domain. Social media pages, free website builders and webmail domains were excluded so that every domain in the sample is one the business owns.

How was each domain checked?

With the same code that runs our free DMARC checker and SSL checker: public DNS lookups for MX, SPF, DMARC and common DKIM selectors, and an HTTPS connection to the website to verify its certificate and whether http:// redirects to https://. Nothing was sent to the businesses and no login or scan beyond these public lookups was made.

How can I check my own domain?

Use the free DMARC checker and SSL checker linked on this page. Both show the exact record or setting that fixes each problem.