DEV Community

Probelane
Probelane

Posted on

3 in 10 major South African email domains can still be spoofed (October 2026 scan)

We checked the public DNS of 334 mail-receiving domains run by large South African organisations across 18 sectors: banks, insurers, retailers, telcos, universities, national and provincial government, and municipalities. We read each one's SPF and DMARC record.

Headline

  • 233 (70%) enforce DMARC at quarantine or reject.
  • 83 (25%) have no enforcing DMARC policy, so anyone can send mail that looks like it came from them.
  • 14 (4%) protect the main domain but leave subdomains open (sp=none).
  • 4 (1%) enforce only on part of their mail (pct below 100).

By sector (share fully protected)

  • Legal 100% · Insurance 90% · Professional services 88% · Fintech 85%
  • Corporate 80% · Property 80% · Banking 79%
  • Telco 73% · Logistics 64% · Retail 61%
  • Education 55% · National government 54% · Provincial 50% · Municipal 43% · Utilities 33%

Why it matters

Invoice and "bank details have changed" fraud starts with a believable sender. A municipality or utility without DMARC enforcement is the easiest name to borrow when asking a supplier or resident to pay into a new account.

What we did not do

We are not naming individual organisations. Every check reads public DNS only; nothing was sent to or probed on any mail server.

Check your own domains

Method: SPF and DMARC TXT lookups via public DNS-over-HTTPS, 9 October 2026. A domain counts as protected when p=quarantine or p=reject, pct is 100 or absent, and sp is not none.

Top comments (0)