Skip to content
All resources
Guide research Published 29 June 2026

Australian SMB Security & Digital Readiness Benchmark 2026

We scanned 364 Australian business domains for email security, web security, SEO and AI-search readiness. 76% lack enforced DMARC; most fail security headers.

Most Australian small and medium businesses run on email they don’t control the security of, websites missing baseline hardening, and pages that neither Google nor the new AI answer-engines can read well. We know because we measured it.

This benchmark aggregates 364 Australian business domains scanned in June 2026 with the same free diagnostic tools we publish at edos.com.au/tools. It covers four pillars: email security, web security, SEO, and AI-search readiness (GEO/AEO).

The one-line summary

  • 76% have no enforced DMARC. Their domain can be spoofed with no policy to stop it.
  • 77% of websites score D or F on security headers.
  • Only 10% pass a basic SEO check, and nearly half (48%) are unready for AI search.

Methodology & sample (read this first)

Honesty about the sample matters more than a big number, so here it is upfront:

  • What: 364 Australian business domains, each scanned once in June 2026.
  • Composition (not a random sample). Roughly 75% are accounting firms, with a smaller spread across other professional services (allied health, law, real estate, dental, medical, mortgage and finance broking). Read this as “Australian professional-services SMBs, accounting-weighted,” not a statistically representative cross-section of all Australian business.
  • How: DNS-based checks (DMARC/SPF/DKIM, MX, blacklist, MTA-STS/DNSSEC/BIMI/CAA/TLS-RPT) ran on all 364; website checks (security headers, SEO, GEO/AEO) ran on the 330 domains with a reachable website (22 had no resolving site; 12 were not page-audited).
  • Privacy: every figure below is an aggregate across the dataset. No individual domain, business, IP or person is named or identifiable.

If you want to run the same checks on your own domain, every tool used here is free and linked throughout.

↓ Download the aggregate dataset (CSV). The headline figures behind this report are free to cite with attribution to Edos Solutions.


Pillar 1: Email security

A domain without an enforced DMARC policy can be impersonated in phishing and invoice-fraud emails, with nothing instructing receivers to reject the fakes.

DMARC policy (n = 364)

PolicyShareWhat it means
Missing entirely40.4%No DMARC record at all
p=none (monitor only)36.0%Record exists but enforces nothing
p=quarantine14.6%Spoofed mail sent to junk
p=reject9.1%Spoofed mail blocked outright
Missing40.4% p=none36.0% Quarantine14.6% Reject9.1%

76.4% have no enforcement (missing + none); only 9.1% reach the recommended reject.

Supporting records (n = 364)

SPF validDKIM validValid MXOn a blacklist
89.3%64.3%92.3%21.4%

More than 1 in 5 domains is on an email blacklist, a direct hit to deliverability.

Modern controls are almost entirely absent (n = 364)

MTA-STSDNSSECBIMICAATLS-RPT
1.1%0.0%0.8%1.6%1.1%

Mail is hosted predominantly on Microsoft 365 (54%) and Google Workspace (15%). Both support full DMARC enforcement out of the box, so most of the gap above is configuration, not capability.

Accounting firms are a large share of this dataset and carry a sharper version of this risk — clients act on their emails without question, making a spoofed domain a direct line to invoice fraud. See the accounting-firm email security benchmark for the vertical-specific breakdown.

Check your own domain free: SPF/DKIM/DMARC checker · blacklist check. Fix it properly: Mail Shield.


Pillar 2: Web security

Security headers are the cheapest defence a website has, and the most neglected.

Security-headers grade (n = 330 sites)

GradeABCDF
Share1.5%3.9%17.9%52.4%24.2%
Grade A1.5% Grade B3.9% Grade C17.9% Grade D52.4% Grade F24.2%

76.7% score D or F. The specific gaps:

Missing HSTSMissing CSPMissing X-Frame-Options
76.7%91.2%89.7%

Check your own: security headers tool · full website security scan. Build secure: Websites.


Pillar 3: SEO

Of the 330 sites with a reachable website, only 10% pass a basic technical-SEO check. The most common and easily fixed failures:

IssueSites affected
No H1 heading99
No title tag37
Heading-hierarchy gaps33
Missing meta description19
Two H1s (should be one)9

These are fundamentals. They quietly cap a site’s ranking before content or backlinks even enter the picture.

Check your own: SEO scanner.


Pillar 4: AI-search readiness (GEO/AEO)

The newest and widest gap. As buyers shift to AI answer-engines (ChatGPT, Perplexity, Google AI overviews), sites need structure those engines can parse and cite. Most can’t.

GEO/AEO grade (n = 330 sites)

GradeA+ABCF
Share1.2%10.0%21.2%19.4%48.2%
Grade A+1.2% Grade A10.0% Grade B21.2% Grade C19.4% Grade F48.2%

Only 17% pass. The dominant failures:

IssueSites affected
No structured data at all140 (42%)
No author or date signals71
Date present but no author50
Thin / near-zero content12

Nearly half of the sites are effectively invisible to AI search, and almost none of the sample has addressed it.

Check your own: GEO/AEO AI-search scanner.


What it means

Across all four pillars the pattern is the same: the platforms these businesses already pay for support the right configuration, but the configuration isn’t done. Most fixes are quick and cheap: enforce DMARC, add a few security headers, correct the on-page SEO basics, and add structured data for AI search.

Edos provides all four as services, and the diagnostic tools above are free to run on any domain.

Limitations

  • Sample bias: accounting-weighted professional-services SMBs, not a random cross-section of Australian business. Treat the figures as indicative of this segment.
  • Coverage: email and DNS checks cover all 364 domains; website checks (security headers, SEO, GEO/AEO) cover the 330 with a reachable website, and all grade distributions are reported over that base.
  • Point in time: June 2026 snapshot. We intend to re-scan the same cohort to publish year-on-year movement.
  • Provenance: the aggregate CSV published with this report is the frozen artifact of record for every figure above, committed on the publication date. The per-domain scan data behind it is a point-in-time snapshot and is not re-derivable from our live dataset, which is re-scanned on a rolling basis.

Methodology questions or media enquiries: info@edos.com.au.

Need help implementing this?

Talk to an engineer