Original research · August 2026
81% of Ocala businesses can be impersonated by email
We checked the public email-authentication records of 31 independent businesses across Ocala and Marion County. 25 of them — 81% — have no working protection against someone sending email in their name.
81%
can be impersonated
7 of 7
law firms vulnerable
6%
fully protected
The finding
Every law firm we checked was vulnerable
All seven Ocala law firms in the sample can be impersonated in email. Not one had DMARC set to act on forged messages.
That matters more here than almost anywhere else. Law firms handle real estate closings and settlement funds, which makes them the standing target for payment-redirection fraud. The attack does not require breaching the firm — it requires sending a client an email that appears to come from the firm, with different wiring instructions, at the moment they are expecting exactly that message.
Veterinary clinics were equally exposed, seven of seven. Dental practices were slightly better at seven of nine.
Vulnerable by sector
- Law firms7/7 (100%)
- Veterinary clinics7/7 (100%)
- Dental practices7/9 (78%)
- Medical practices1/2 (50%)
- Contractors & HVAC3/6 (50%)
Sample sizes are small per sector and shown in full rather than converted into percentages alone.
The reason
Almost everyone has SPF. Almost nobody has DMARC.
87% of the businesses had an SPF record. Only 39% had DMARC at all, and only 19% had it set to actually do something.
This is the gap that leaves people confident and exposed simultaneously. SPF checks a hidden envelope address used during delivery. The From line your customer reads is a different field. Without DMARC tying them together, a forged message can pass SPF on the attacker's own domain and still display your business in the inbox.
Six businesses had published DMARC and left it at p=none — monitoring mode, which blocks nothing. That is the signature of a job started and never finished.
What we measured
- Have an SPF record87%
- Have any DMARC record39%
- DMARC actually enforcing (quarantine or reject)19%
- DMARC at full reject6%
- DKIM found on a common selector32%
- Collecting DMARC reports19%
- DNSSEC enabled0%
What it costs
This is the attack that does not need to hack you
Business email compromise costs American businesses more each year than ransomware. It needs no malware and no breach — only a domain that never told the internet who may send on its behalf.
The closing that goes to the wrong account
A buyer receives wiring instructions that appear to come from the firm handling their closing. The money moves once and does not come back.
The invoice your customer pays to someone else
Your branding, your name, different bank details. It reaches the inbox because nothing told the receiving server to reject it.
Your reputation, not the attacker's
The customer who was defrauded believes the message came from you. In every visible respect, it did.
Methodology
How this was done, and its limits
Published in full so anyone can reproduce or challenge it.
What we did
For each domain we read the public DNS records that govern email authentication: MX, SPF, DMARC at _dmarc., and DKIM across seven common selectors (selector1, selector2, google, k1, s1, default, mail). Queries went to a public resolver over DNS-over-HTTPS on 11 August 2026. A business was counted vulnerable if it had no DMARC policy of quarantine or reject — the only settings that cause a receiving server to act on a forged message.
What we did not do
We sent no email to anyone, accessed no system, attempted no login and read no private data. Every record examined is already visible to every mail server on the internet. We are not publishing which businesses were vulnerable, and we will not share that list — it would function as a target list for the fraud described above.
Limitations, stated plainly
- 31 businesses is a convenience sample drawn from public listings, not a random sample of Ocala. Treat the sector figures as indicative.
- DKIM cannot be fully enumerated from outside. A business using a custom selector would be recorded as “not found” despite having it. The DKIM figure is therefore a floor, not a ceiling.
- DNS changes. These are the records as of 11 August 2026 and some will have moved since.
- We sell services that fix this. The measurements are what they are, including the 87% SPF figure that cuts against a simpler sales story.
Check your own domain
Two seconds, no signup, no email address. It reads the same public records this study used and tells you exactly where you stand.
Questions
About this study
How was this measured?
By reading public DNS records — SPF, DKIM and DMARC — for each domain, using a public DNS resolver. That is exactly the information every mail server on the internet reads when it receives a message claiming to be from that business. Nothing was sent to any of these companies, no system was accessed, and no private data was involved.
Which businesses were vulnerable?
We are not publishing that, and we will not provide it on request. A named list of local businesses that can be impersonated is a ready-made target list for the exact fraud this study is about. Findings are aggregate only. Any business can check its own domain in two seconds using our free tool.
How were the businesses chosen?
31 independent businesses in Ocala and Marion County across five sectors, selected from public web listings. National chains, franchises and directory sites were excluded, because their email is usually managed centrally and would not reflect how local firms actually operate. It is a convenience sample, not a random one — see the limitations below.
Is 31 businesses enough to draw conclusions?
It is enough to establish that this is widespread rather than occasional, and the sector patterns are stark enough to be meaningful. It is not enough to state a precise percentage for Ocala as a whole. We have reported the sample size everywhere rather than rounding it into a headline that implies more precision than we have.
Our business was probably in this sample. What should we do?
Run the free check on your own domain, then fix it — the records cost nothing. If you would like help doing it without interrupting your legitimate email, get in touch. There is no obligation and we are not going to chase you.
Want yours fixed properly?
These are DNS records, not new software, and there is nothing to buy. The risk is sequencing — tighten the wrong record first and your real email stops being delivered.