We checked the public DNS of 334 mail-receiving domains run by large South African organisations across 18 sectors: banks, insurers, retailers, telcos, universities, national and provincial government, and municipalities. We read each one's SPF and DMARC record.
Headline
- 233 (70%) enforce DMARC at quarantine or reject.
- 83 (25%) have no enforcing DMARC policy, so anyone can send mail that looks like it came from them.
- 14 (4%) protect the main domain but leave subdomains open (sp=none).
- 4 (1%) enforce only on part of their mail (pct below 100).
By sector (share fully protected)
- Legal 100% · Insurance 90% · Professional services 88% · Fintech 85%
- Corporate 80% · Property 80% · Banking 79%
- Telco 73% · Logistics 64% · Retail 61%
- Education 55% · National government 54% · Provincial 50% · Municipal 43% · Utilities 33%
Why it matters
Invoice and "bank details have changed" fraud starts with a believable sender. A municipality or utility without DMARC enforcement is the easiest name to borrow when asking a supplier or resident to pay into a new account.
What we did not do
We are not naming individual organisations. Every check reads public DNS only; nothing was sent to or probed on any mail server.
Check your own domains
- One domain, a verdict and what to fix: Email Domain Security Auditor
- Before paying a new supplier or a changed bank account: Counterparty Trust Check
- Many domains at once, with expiry dates: Bulk Domain WHOIS/RDAP
Method: SPF and DMARC TXT lookups via public DNS-over-HTTPS, 9 October 2026. A domain counts as protected when p=quarantine or p=reject, pct is 100 or absent, and sp is not none.
Top comments (0)