Skip to content

Original research · August 2026

81% of Ocala businesses can be impersonated by email

We checked the public email-authentication records of 84 independent businesses across Ocala and Marion County. 68 of them — 81% — have no working protection against someone sending email in their name.

81%

can be impersonated

7 of 7

veterinary practices vulnerable

19%

fully protected

The finding

Every veterinary practice we checked was vulnerable

All 7 Ocala veterinary practices in the sample can be impersonated in email. Not one had DMARC set to act on forged messages. Law firms were barely better at 8 of 9.

That matters more here than almost anywhere else. Law firms handle real estate closings and settlement funds, which makes them the standing target for payment-redirection fraud. The attack does not require breaching the firm — it requires sending a client an email that appears to come from the firm, with different wiring instructions, at the moment they are expecting exactly that message.

Dental practices were slightly better at 7 of 9.

Vulnerable by sector

  • Veterinary7/7 (100%)
  • Legal8/9 (89%)
  • Accounting & tax8/9 (89%)
  • Garage doors5/6 (83%)
  • HVAC9/11 (82%)
  • Roofing4/5 (80%)
  • Dental7/9 (78%)
  • Auto repair6/8 (75%)
  • Landscaping4/6 (67%)
  • Medical & chiropractic3/5 (60%)

Sample sizes are small per sector and shown in full rather than converted into percentages alone.

The reason

Almost everyone has SPF. Almost nobody has DMARC.

75% of the businesses had an SPF record. Only 44% had DMARC at all, and only 19% had it set to actually do something.

This is the gap that leaves people confident and exposed simultaneously. SPF checks a hidden envelope address used during delivery. The From line your customer reads is a different field. Without DMARC tying them together, a forged message can pass SPF on the attacker’s own domain and still display your business in the inbox.

21 businesses had published DMARC and left it at p=none — monitoring mode, which blocks nothing. That is the signature of a job started and never finished.

What we measured

  • Have an SPF record75%
  • Have any DMARC record44%
  • DMARC actually enforcing (quarantine or reject)19%
  • DMARC published but only monitoring25%
  • DKIM found on a common selector26%
  • Running Microsoft 365 for mail31%

What it costs

This is the attack that does not need to hack you

Business email compromise costs American businesses more each year than ransomware. It needs no malware and no breach — only a domain that never told the internet who may send on its behalf.

  • The closing that goes to the wrong account

    A buyer receives wiring instructions that appear to come from the firm handling their closing. The money moves once and does not come back.

  • The invoice your customer pays to someone else

    Your branding, your name, different bank details. It reaches the inbox because nothing told the receiving server to reject it.

  • Your reputation, not the attacker's

    The customer who was defrauded believes the message came from you. In every visible respect, it did.

Methodology

How this was done, and its limits

Published in full so anyone can reproduce or challenge it.

What we did

For each domain we read the public DNS records that govern email authentication: MX, SPF, DMARC at _dmarc., and DKIM across seven common selectors (selector1, selector2, google, k1, s1, default, mail). Queries went to a public resolver over DNS-over-HTTPS on 18 August 2026. A business was counted vulnerable if it had no DMARC policy of quarantine or reject — the only settings that cause a receiving server to act on a forged message.

What we did not do

We sent no email to anyone, accessed no system, attempted no login and read no private data. Every record examined is already visible to every mail server on the internet. We are not publishing which businesses were vulnerable, and we will not share that list — it would function as a target list for the fraud described above.

Limitations, stated plainly

  • 84 businesses is a convenience sample drawn from public listings, not a random sample of Ocala. Treat the sector figures as indicative.
  • DKIM cannot be fully enumerated from outside. A business using a custom selector would be recorded as “not found” despite having it. The DKIM figure is therefore a floor, not a ceiling.
  • DNS changes. These are the records as of 18 August 2026 and some will have moved since.
  • We sell services that fix this. The measurements are what they are, including the75% SPF figure that cuts against a simpler sales story.

Check your own domain

Two seconds, no signup, no email address. It reads the same public records this study used and tells you exactly where you stand.

Questions

About this study

How was this measured?

By reading public DNS records — SPF, DKIM and DMARC — for each domain, using a public DNS resolver. That is exactly the information every mail server on the internet reads when it receives a message claiming to be from that business. Nothing was sent to any of these companies, no system was accessed, and no private data was involved.

Which businesses were vulnerable?

We are not publishing that, and we will not provide it on request. A named list of local businesses that can be impersonated is a ready-made target list for the exact fraud this study is about. Findings are aggregate only. Any business can check its own domain in two seconds using our free tool.

How were the businesses chosen?

84 independent businesses in Ocala and Marion County across 14 trades, selected from public web listings. National chains, franchises and directory sites were excluded, because their email is usually managed centrally and would not reflect how local firms actually operate. It is a convenience sample, not a random one — see the limitations below.

Is 84 businesses enough to draw conclusions?

It is enough to establish that this is widespread rather than occasional, and the sector patterns are stark enough to be meaningful. It is not enough to state a precise percentage for Ocala as a whole. Worth noting: the first version of this study covered 31 businesses and found 81% spoofable. Widening it to 84 across 14 trades produced the same figure, which is a better reason to trust it than the sample size alone. We report the sample size everywhere rather than rounding it into a headline that implies more precision than we have.

Our business was probably in this sample. What should we do?

Run the free check on your own domain, then fix it — the records cost nothing. If you would like help doing it without interrupting your legitimate email, get in touch. There is no obligation and we are not going to chase you.

Reuse

Citing this study

Free to quote, in full or in part, including commercially. We ask only that the sample size stays attached to the figure — 81% reported as though it described every business in Marion County would be our fault as much as anyone else’s. A link back is appreciated and not required.

Ocala Secure IT, Ocala Email Security Study 2026. Public email-authentication records checked across 84 independent Ocala and Marion County businesses across 14 trades; 81% could be impersonated. ocalasecureit.com/research/ocala-email-security-2026

Working on a story and need a cut of the data that is not on this page — a sector we did not publish, or the raw distribution? Ask. We will run it. We will not release the per-domain results, to anyone: a list of local businesses that can be impersonated is a target list for exactly the fraud this study is about.

Want yours fixed properly?

These are DNS records, not new software, and there is nothing to buy. The risk is sequencing — tighten the wrong record first and your real email stops being delivered.

Call nowBook a visit