Nearly eight in ten of the professional firms we assess cannot stop an email sent in their name from being delivered.

That is not a forecast. It is what those firms publish about their own domains today, in public records that every receiving mail server reads before it decides whether to deliver a message. We read the same records, from outside, with no access to anyone's systems.

What we measured

One public record, DMARC, tells the world's mail servers what to do with a message that claims to come from your domain and fails the checks. It has three settings. No record at all means receivers are given no instruction. Monitor mode produces reports and blocks nothing. Quarantine or reject means forged mail is acted on.

A firm in either of the first two positions cannot stop a stranger sending email in its name. Across every professional sector we assess, measured on 19 September 2026:

  • 48.0% publish no DMARC record at all.
  • 31.6% publish one in monitor mode, which reports and blocks nothing.
  • 79.6% therefore cannot stop a forged invoice, a fake payment instruction or a request for records sent in their name.
  • 7.5% have it set so forged mail is rejected outright.

By sector

The share of firms that cannot stop a forged email, by sector:

  • 88.8% of dental practices. Only 2.1% reject forged mail. Clinics are the most exposed to a message that appears to come from the practice itself: an appointment change, a payment request, a request for records.
  • 71.3% of accounting firms.
  • 70.3% of law firms.
  • 65.1% of insurance brokerages, the best-protected sector we assess. The firms advising clients on cyber cover are the most likely to have done the work themselves, and two thirds of them still have not finished it.

Law and accounting are examined in detail in Seven in ten professional firms cannot stop an email sent in their name.

Monitor mode is the number to watch

Roughly three in ten firms have started and stopped. Somebody turned DMARC on in monitor mode, meaning to tighten it later, and then nobody wanted to be the person who blocked the partners' email. So the record sits there for years producing a report nobody reads, and the firm believes the box is ticked.

If your record says p=none, the work is half done. The second half is the part that protects you.

How this compares

Our figure is in line with independent measurement. EasyDMARC's 2026 adoption report, covering 1.8 million domains, found that just over half (52.1%) publish a DMARC record at all, and fewer than one in four enforce one. Among the Fortune 500 the picture is reversed: 95% publish a record and more than 80% enforce it.

Large enterprises closed this gap years ago. Professional firms, which move client money and privileged material by email every day, mostly have not.

Why it matters more this year

None of this is new, and none of it is sophisticated. What has changed is who does the looking. Reading a firm's public records used to take a person an afternoon, and most firms were never worth a person's afternoon. Automated tooling does not make that calculation. It checks everyone.

How to check your own, in two minutes

You do not need a vendor for this. From any terminal:

dig TXT _dmarc.yourfirm.com +short

If it returns nothing, you are in the 48.0%. If it returns p=none, you are in the 31.6%. If it returns p=quarantine or p=reject, forged mail in your name is being acted on.

Method

Findings are read from public sources only, principally DNS. No systems were accessed, no logins were used, and no firm is named here or anywhere else. Figures use the most recent assessment of each firm and include only firms where the email-authentication check returned data. Percentages describe the firms in our visibility across Canada and the United States, not a national census. A soft-fail SPF record is not counted as a finding.