Australian SMB Security & Digital Readiness Benchmark 2026
We scanned 364 Australian business domains for email security, web security, SEO and AI-search readiness. 76% lack enforced DMARC; most fail security headers.
Most Australian small and medium businesses run on email they don’t control the security of, websites missing baseline hardening, and pages that neither Google nor the new AI answer-engines can read well. We know because we measured it.
This benchmark aggregates 364 Australian business domains scanned in June 2026 with the same free diagnostic tools we publish at edos.com.au/tools. It covers four pillars: email security, web security, SEO, and AI-search readiness (GEO/AEO).
The one-line summary
- 76% have no enforced DMARC. Their domain can be spoofed with no policy to stop it.
- 77% of websites score D or F on security headers.
- Only 10% pass a basic SEO check, and nearly half (48%) are unready for AI search.
Methodology & sample (read this first)
Honesty about the sample matters more than a big number, so here it is upfront:
- What: 364 Australian business domains, each scanned once in June 2026.
- Composition (not a random sample). Roughly 75% are accounting firms, with a smaller spread across other professional services (allied health, law, real estate, dental, medical, mortgage and finance broking). Read this as “Australian professional-services SMBs, accounting-weighted,” not a statistically representative cross-section of all Australian business.
- How: DNS-based checks (DMARC/SPF/DKIM, MX, blacklist, MTA-STS/DNSSEC/BIMI/CAA/TLS-RPT) ran on all 364; website checks (security headers, SEO, GEO/AEO) ran on the 330 domains with a reachable website (22 had no resolving site; 12 were not page-audited).
- Privacy: every figure below is an aggregate across the dataset. No individual domain, business, IP or person is named or identifiable.
If you want to run the same checks on your own domain, every tool used here is free and linked throughout.
↓ Download the aggregate dataset (CSV). The headline figures behind this report are free to cite with attribution to Edos Solutions.
Pillar 1: Email security
A domain without an enforced DMARC policy can be impersonated in phishing and invoice-fraud emails, with nothing instructing receivers to reject the fakes.
DMARC policy (n = 364)
| Policy | Share | What it means |
|---|---|---|
| Missing entirely | 40.4% | No DMARC record at all |
p=none (monitor only) | 36.0% | Record exists but enforces nothing |
p=quarantine | 14.6% | Spoofed mail sent to junk |
p=reject | 9.1% | Spoofed mail blocked outright |
76.4% have no enforcement (missing + none); only 9.1% reach the recommended reject.
Supporting records (n = 364)
| SPF valid | DKIM valid | Valid MX | On a blacklist |
|---|---|---|---|
| 89.3% | 64.3% | 92.3% | 21.4% |
More than 1 in 5 domains is on an email blacklist, a direct hit to deliverability.
Modern controls are almost entirely absent (n = 364)
| MTA-STS | DNSSEC | BIMI | CAA | TLS-RPT |
|---|---|---|---|---|
| 1.1% | 0.0% | 0.8% | 1.6% | 1.1% |
Mail is hosted predominantly on Microsoft 365 (54%) and Google Workspace (15%). Both support full DMARC enforcement out of the box, so most of the gap above is configuration, not capability.
Accounting firms are a large share of this dataset and carry a sharper version of this risk — clients act on their emails without question, making a spoofed domain a direct line to invoice fraud. See the accounting-firm email security benchmark for the vertical-specific breakdown.
→ Check your own domain free: SPF/DKIM/DMARC checker · blacklist check. Fix it properly: Mail Shield.
Pillar 2: Web security
Security headers are the cheapest defence a website has, and the most neglected.
Security-headers grade (n = 330 sites)
| Grade | A | B | C | D | F |
|---|---|---|---|---|---|
| Share | 1.5% | 3.9% | 17.9% | 52.4% | 24.2% |
76.7% score D or F. The specific gaps:
| Missing HSTS | Missing CSP | Missing X-Frame-Options |
|---|---|---|
| 76.7% | 91.2% | 89.7% |
→ Check your own: security headers tool · full website security scan. Build secure: Websites.
Pillar 3: SEO
Of the 330 sites with a reachable website, only 10% pass a basic technical-SEO check. The most common and easily fixed failures:
| Issue | Sites affected |
|---|---|
| No H1 heading | 99 |
| No title tag | 37 |
| Heading-hierarchy gaps | 33 |
| Missing meta description | 19 |
| Two H1s (should be one) | 9 |
These are fundamentals. They quietly cap a site’s ranking before content or backlinks even enter the picture.
→ Check your own: SEO scanner.
Pillar 4: AI-search readiness (GEO/AEO)
The newest and widest gap. As buyers shift to AI answer-engines (ChatGPT, Perplexity, Google AI overviews), sites need structure those engines can parse and cite. Most can’t.
GEO/AEO grade (n = 330 sites)
| Grade | A+ | A | B | C | F |
|---|---|---|---|---|---|
| Share | 1.2% | 10.0% | 21.2% | 19.4% | 48.2% |
Only 17% pass. The dominant failures:
| Issue | Sites affected |
|---|---|
| No structured data at all | 140 (42%) |
| No author or date signals | 71 |
| Date present but no author | 50 |
| Thin / near-zero content | 12 |
Nearly half of the sites are effectively invisible to AI search, and almost none of the sample has addressed it.
→ Check your own: GEO/AEO AI-search scanner.
What it means
Across all four pillars the pattern is the same: the platforms these businesses already pay for support the right configuration, but the configuration isn’t done. Most fixes are quick and cheap: enforce DMARC, add a few security headers, correct the on-page SEO basics, and add structured data for AI search.
Edos provides all four as services, and the diagnostic tools above are free to run on any domain.
Limitations
- Sample bias: accounting-weighted professional-services SMBs, not a random cross-section of Australian business. Treat the figures as indicative of this segment.
- Coverage: email and DNS checks cover all 364 domains; website checks (security headers, SEO, GEO/AEO) cover the 330 with a reachable website, and all grade distributions are reported over that base.
- Point in time: June 2026 snapshot. We intend to re-scan the same cohort to publish year-on-year movement.
- Provenance: the aggregate CSV published with this report is the frozen artifact of record for every figure above, committed on the publication date. The per-domain scan data behind it is a point-in-time snapshot and is not re-derivable from our live dataset, which is re-scanned on a rolling basis.
Methodology questions or media enquiries: info@edos.com.au.
Need help implementing this?
Talk to an engineer