Australian Accounting Firms Email Security Benchmark 2026
We scanned 316 Australian accounting-firm domains for email security, web security and AI-search readiness. 75.3% lack enforced DMARC; 70.1% of sites fail security headers.
Accounting firms are a high-value target for invoice fraud and business email compromise. They instruct payments on behalf of clients, hold trust-account and banking details, and their clients are trained to act on their emails without question — an attacker who can convincingly spoof a firm’s domain has a direct line to a payment. Whether that spoofing is even possible comes down to one DNS record: DMARC. We measured how many Australian accounting firms have it enforced.
This benchmark aggregates 316 Australian accounting-firm domains scanned with the same free diagnostic tools we publish at edos.com.au/tools. It covers email security, web security, and AI-search readiness (GEO/AEO).
The one-line summary
- 75.3% have no enforced DMARC policy. Their domain can be spoofed in invoice-fraud and phishing emails with nothing instructing receivers to reject the fakes.
- 70.1% of accounting-firm websites score D or F on security headers.
- 52.9% are unready for AI search — invisible to the answer engines a growing share of prospective clients now use to find an accountant.
Methodology & sample (read this first)
Honesty about the sample matters more than a big number, so here it is upfront:
- What: 316 Australian accounting-firm domains, scanned between June and July 2026. Where a domain was checked more than once, its most recent scan is the one counted; the dataset was frozen for publication on 21 July 2026.
- How: DNS-based checks (DMARC/SPF/DKIM, MX, blacklist, MTA-STS/DNSSEC/BIMI/CAA/TLS-RPT) ran on all 316 domains. Website checks (security headers, GEO/AEO AI-search readiness) ran on the 291 domains with a reachable website.
- Not a random sample. These domains are sourced from a prospect list, not drawn randomly from the full population of Australian accounting firms. Read the figures as indicative of the segment, not as a statistically representative cross-section.
- Privacy: every figure below is an aggregate across the dataset. No individual firm, domain, IP or person is named or identifiable.
An earlier cut of this dataset covering 275 firms was published in Accountants Daily on 8 July 2026. The cohort has since grown to 316 firms; the figures here supersede it.
If you want to run the same checks on your own domain, every tool used here is free and linked throughout.
↓ Download the aggregate dataset (CSV). The figures below are free to cite with attribution to Edos Solutions.
Pillar 1: Email security
A domain without an enforced DMARC policy can be impersonated in phishing and invoice-fraud emails, with nothing instructing receivers to reject the fakes — the exact scenario behind “our bank details have changed” emails that look like they came from the firm.
DMARC policy (n = 316)
| Policy | Share | What it means |
|---|---|---|
| Missing entirely | 42.1% | No DMARC record at all |
p=none (monitor only) | 33.2% | Record exists but enforces nothing |
p=quarantine | 16.5% | Spoofed mail sent to junk |
p=reject | 8.2% | Spoofed mail blocked outright |
75.3% have no enforcement (missing + none); only 8.2% reach the recommended reject.
Supporting records (n = 316)
| SPF valid | DKIM valid | Valid MX | On a blacklist |
|---|---|---|---|
| 91.5% | 66.8% | 93.4% | 2.5% |
Modern controls are almost entirely absent (n = 316)
| MTA-STS | DNSSEC | BIMI | CAA | TLS-RPT |
|---|---|---|---|---|
| 0.9% | 0.0% | 0.6% | 1.6% | 0.6% |
Mail provider (n = 316)
| Microsoft 365 | Google Workspace | Other | Self-hosted (Postfix/Exim) | Unknown |
|---|---|---|---|---|
| 56.6% | 14.6% | 16.1% | 6.0% | 6.6% |
Microsoft 365 and Google Workspace together host 71.2% of the cohort’s mail, and both support full DMARC enforcement at no extra cost. The 75.3% enforcement gap above is a configuration gap, not a capability gap.
→ Check your own domain free: SPF/DKIM/DMARC checker · blacklist check. Fix it properly: Mail Shield.
Pillar 2: Web security
Security headers are the cheapest defence a website has, and the most neglected.
Security-headers grade (n = 291 sites)
| Grade | A | B | C | D | F |
|---|---|---|---|---|---|
| Share | 2.7% | 5.2% | 22.0% | 65.3% | 4.8% |
70.1% score D or F.
→ Check your own: security headers tool · full website security scan. Build secure: Websites.
Pillar 3: AI-search readiness (GEO/AEO)
As buyers shift to AI answer-engines (ChatGPT, Perplexity, Google AI overviews) to find and vet an accountant, sites need structure those engines can parse and cite. Most can’t.
GEO/AEO grade (n = 291 sites)
| Grade | A+ | A | B | C | F |
|---|---|---|---|---|---|
| Share | 1.0% | 7.9% | 17.2% | 21.0% | 52.9% |
52.9% are graded F. Note the GEO scale produced no D grades in this cohort at all — the D-or-F figure above is entirely F, not a mix of the two.
→ Check your own: GEO/AEO AI-search scanner.
What to do about it
DMARC enforcement is a sequence, not a single change, and most firms can audit where they stand in an afternoon:
- Confirm SPF and DKIM are valid for every domain that sends mail — the primary domain and any secondary or parked domains.
- Publish DMARC at
p=noneand read the aggregate reports for a few weeks. This surfaces legitimate senders (marketing platforms, practice-management software, forwarders) before you start blocking anything. - Move to
p=quarantineonce the reports show no legitimate mail failing, then move top=reject. - Repeat the same check for secondary and parked domains — a common blind spot is a firm’s old trading name or a defensively-registered lookalike domain with no DMARC record at all, which is exactly what an attacker would spoof instead.
Limitations
- Not a random sample: these domains are prospect-list sourced and cover the accounting vertical only. Treat the figures as indicative of this segment, not a statistically representative cross-section of all Australian accounting firms.
- Point in time: snapshot taken 21 July 2026.
- Coverage: DNS/email checks cover all 316 domains; website checks (security headers, GEO/AEO) cover the 291 domains with a reachable website.
- GEO scale: the AI-search readiness grading produced no D grades in this cohort — the 52.9% D-or-F figure is entirely F.
Methodology questions or media enquiries: info@edos.com.au.
Need help implementing this?
Talk to an engineer