How the scans work
What the sector scans read, what each figure means, and what the scan deliberately does not claim.
What the scan reads
Each scan reads the public email authentication records of every organisation in a sector, from public DNS and nothing else. SPF, whether a domain publishes a policy for who may send on its behalf. DMARC, whether it tells the world to reject or quarantine mail that fails. DKIM, whether a signature is discoverable. No mail is sent, nothing is logged against the domain, and no system is touched. These are the same records an attacker reads to decide whether a domain is worth forging, which is why they can be checked from the outside before any engagement begins.
What the figures are counted against
Every percentage is a share of the resolved base, the domains that actually resolve and are configured to carry mail. A domain that does not resolve is not a finding, it is excluded, because there is nothing to read. The count that sits beside each figure is that resolved base, not the raw list I started from, so the denominator is always the population the figure actually describes.
Each organisation counts once. Where a firm publishes several domains, they are reconciled to a single organisation so that one business with three domains does not weigh three times as much as one business with one. One domain, one vote.
The sample floor
Below a set number of organisations, a segment gets no published figure. A state with a handful of firms in it, or a region with only a few wineries, does not produce a percentage, because a percentage over a tiny base reads as precision that is not there. Those segments are named and withheld rather than quietly folded in, so a small number can never masquerade as a rate.
As found, and movement
A sector figure is always as found, the state of the records on the day of the scan. When a sector is re-scanned later, the change over time is reported separately and labelled as movement, never mixed into the headline sector figure. Movement is described by timing alone. Records that improved after a certain date are reported as having improved after that date, not as having improved because of anything I did, because the records do not carry that information and neither do I.
What the scan does not claim
A domain open to forgery is not a domain that has been breached, and it is not evidence that anyone has forged it. It means the records that would stop a forged message are absent or not enforcing. The risk is that the domain cannot defend itself, not that an incident has occurred.
A registered lookalike domain is not proof of an impersonator. It is a name that could be used to impersonate, which is a different and lesser claim, and the scan holds to the lesser one.
The scan reports what is wrong and why it matters. It does not publish the specific record to paste in to fix it. Knowing what correct looks like, and verifying it afterwards, is the work, and it is deliberately not given away as a recipe.
The scans
Each sector scan is published in full, with its figures inline and its sample size and date attached to every number.
-
Email authentication in Australian financial advisers
A scan of 66 advisers, July 2026
-
Email authentication in Australian real estate agencies
A national scan of 234 agencies, June 2026
-
Email authentication in Australian wineries
A scan of 124 independent wineries across five regions, June 2026
-
Email authentication in Australian law firms
A national scan of 252 independent firms, June 2026