Skip to main content
ShieldMarc
Research

Original research on UK email security

Independent audits of UK MSPs, public sector organisations and other categories of UK domain. Methodology is published with every piece. For what to do about the findings, see the guides and our DMARC services for UK organisations.

Our methodology

Every piece of research here is built from publicly published DNS records. We query the same data any resolver can see: DMARC, SPF and DKIM records, MX configuration, DNSSEC status and, where relevant, MTA-STS policy. No message content is examined, nothing is sent to the domains studied, and no intrusive testing of any kind is performed.

Samples are defined before collection rather than assembled to produce a result, and both the sampling frame and the collection date are published with each study. This matters because DMARC adoption figures vary enormously depending on whether you count the presence of a record or the presence of an enforcing policy, and headline numbers are often quietly measuring the former.

We state the distinction explicitly in every study: a domain with p=none has a DMARC record but no protection against spoofing, and counting it as protected overstates real-world coverage substantially. Where a finding is uncertain or the sample is too small to generalise, that is said in the text rather than left for the reader to infer.