Back to all resources
whitepaper

Vaughan Business Email Security Study 2026: Only 17.9% Enforce DMARC

October 4, 2026
9 min read
IT Rapid Support Team
Vaughan Business Email Security Study 2026: Only 17.9% Enforce DMARC

If a criminal wanted to send an email that appears to come from a Vaughan business, how many local businesses have told the world's mail servers to refuse it? We measured it. On 4 October 2026 IT Rapid Support looked up the public email authentication records of 354 Vaughan business domains, 290 of which receive email. The short answer is fewer than one in five.

This is the Vaughan edition of the measurement we ran across the wider region in August, published as our GTA small-business cybersecurity report. That study drew a random sample of GTA business domains. This one starts from a different, fully public list of businesses physically located in the City of Vaughan, so the two are independent checks on the same question. They land within a few points of each other.

Nothing here names or ranks any business. We publish aggregates only, with the method and the limits, and the aggregate table is available as a downloadable CSV for anyone who wants to cite it.

Headline Findings

Of the 290 mail-enabled Vaughan business domains we checked on 4 October 2026:

MeasureDomainsShare of 290---------Publish an SPF record25889.0%Publish a DMARC record14951.4%DMARC set to p=none (monitor only)9633.1%DMARC set to p=quarantine3813.1%DMARC set to p=reject144.8%DMARC enforcing (quarantine or reject)5217.9%No DMARC record at all14148.6%Neither SPF nor DMARC289.7%
  • 82.1% of mail-enabled Vaughan business domains (238 of 290) do not enforce DMARC. For those domains, a receiving mail server has no instruction from the owner to refuse or quarantine a message that fails authentication.
  • Nearly half, 48.6%, publish no DMARC record at all. Another 33.1% publish one set to p=none, which asks receivers to take no action.
  • Of the 96 domains at p=none, 64 (66.7%) also have no reporting address (rua). Those records neither block spoofed mail nor tell the owner it is happening.
  • SPF is the part most businesses have: 89.0% publish an SPF record. But 10 domains (3.4%) publish two SPF records, which makes SPF invalid under the standard, and another 10 end their record with ?all, which tells receivers nothing.
  • Only 14 domains, 4.8%, have reached p=reject, the setting that tells receivers to refuse failing mail outright.

The Vaughan numbers sit close to the GTA baseline. Our August scan of 481 mail-enabled GTA business domains found 91.7% publishing SPF, 52.4% publishing DMARC and 20.6% enforcing it. Vaughan comes in at 89.0%, 51.4% and 17.9%. Two different samples, drawn two months apart from different sources, tell the same story: most businesses have started email authentication and stopped before the step that actually stops impersonation.

The Platform Split Shows Up Again

We also classified each domain's mail platform from its MX records. Microsoft 365 handled mail for 88 domains (30.3%), Google Workspace for 80 (27.6%), and 122 used other hosts, mostly web hosting companies and email security gateways.

Mail platform (by MX)DomainsPublish DMARCEnforce DMARC------------Microsoft 3658855.7%29.5%Google Workspace8050.0%7.5%Other hosts12249.2%16.4%

Microsoft 365 domains in Vaughan were roughly four times as likely as Google Workspace domains to enforce DMARC, 29.5% against 7.5%. The same direction appeared in our GTA business email platforms study, which found 27.2% against 10.8%. We do not read this as one platform being safer. It more likely reflects who set the domain up: Microsoft 365 tenants are more often configured by an IT provider, while Google Workspace is often set up by the owner from a web host's control panel. The DMARC record is a line of DNS either way.

By type of business, offices and professional services were the most likely to enforce DMARC (30.8% of 39 domains), and food and hospitality businesses the least (11.5% of 52). Health and dental practices, which handle patient information, published SPF at a high rate (96.4% of 55) but only 12.7% enforced DMARC. These subgroups are small, so treat the differences as direction rather than precise rates.

What This Means for Vaughan Businesses

DMARC matters because of how payment fraud works. In business email compromise, which the Canadian Anti-Fraud Centre calls payment redirection fraud, a criminal sends an email that looks like it comes from a supplier, a director or a lawyer and asks for banking details to be changed or an urgent payment released. When the domain in the From line has no enforcing DMARC policy, the receiving server has nothing from the owner telling it to refuse a forged message, so the forgery is judged on the receiver's own filtering alone.

The losses are not abstract. Data from the Canadian Anti-Fraud Centre shows Canadians lost over $704 million to fraud in 2025, and the Competition Bureau's Fraud Prevention Month release notes that only 5% to 10% of frauds are reported. A Vaughan distributor whose customers pay invoices by email, a Woodbridge law office handling closing funds or a Concord contractor taking deposits is exactly the kind of business a forged email is designed to imitate.

There is also a deliverability reason, separate from fraud. The three largest consumer mailbox providers now require authentication:

  • Google requires every sender to Gmail accounts to set up SPF or DKIM, and senders of more than 5,000 messages a day to also publish DMARC, at a minimum of p=none, with the From domain aligned (Google email sender guidelines).
  • Yahoo requires SPF or DKIM from all senders, and from bulk senders both SPF and DKIM plus a valid DMARC policy of at least p=none (Yahoo Sender Hub).
  • Microsoft began enforcing SPF, DKIM and DMARC (at least p=none) on 5 May 2025 for domains sending more than 5,000 messages a day to Outlook.com, Hotmail and Live addresses, rejecting non-compliant mail (Microsoft Defender for Office 365 blog).

Most Vaughan small businesses do not send 5,000 emails a day, so the bulk rules do not bind them directly. Two things still follow. First, the providers' baseline expectation is now SPF, DKIM and DMARC together, and a domain that sends newsletters, invoices or appointment reminders through a third-party platform can cross into bulk territory without anyone noticing. Second, p=none satisfies those rules but does not protect you. The bulk-sender minimum is about proving who you are; enforcement is what protects your customers from someone pretending to be you.

How We Did It

Sources. We built the list from OpenStreetMap, the open map database, querying through the public Overpass API for every mapped feature inside the City of Vaughan administrative boundary with a website or email tag. That returned 936 map features on 4 October 2026. We reduced each website or email address to its domain and removed features tagged as a national brand or chain, schools, places of worship, government and other public bodies, social media and website-builder platforms, domains appearing at more than three Vaughan locations, and a short manual list of remaining chains, charities and out-of-area domains. That left 354 unique business domains, from restaurants, dental clinics and salons to manufacturers, distributors and professional offices.

DNS checks. For each domain we queried public DNS on 4 October 2026, starting 13:07 UTC (9:07 AM ET), using the dig tool against public resolvers (Cloudflare 1.1.1.1, with Google 8.8.8.8 as fallback). We read the MX records to decide whether the domain receives mail (a domain with no MX, or a null MX, was counted as not mail-enabled; 64 of 354), the TXT records at the domain for SPF (v=spf1), and the TXT records at _dmarc for DMARC. DMARC policy was read from the p= tag; SPF was classified by its final all mechanism. Nothing was sent to any business and no system was probed beyond public DNS. Anyone can repeat a single check with our free email spoofing check.

Limitations. OpenStreetMap is volunteer-mapped, so the sample over-represents shops, restaurants, clinics and businesses that have a website and that someone has mapped; it is not a random sample of all Vaughan businesses, and large industrial firms are under-represented. A business whose mail domain differs from its website domain was measured on the website domain. We did not check DKIM, because DKIM keys live at selector names that cannot be listed from outside, and a DMARC record says what the owner asked for, not what every receiver does. Platform and business-type subgroups are small. DNS changes daily, so these figures describe 4 October 2026 only.

A Five-Step Fix for Your Own Domain

If your domain is among the 82.1% that do not enforce DMARC, the fix is a few DNS records and some patience. Done in this order, legitimate mail keeps arriving the whole way through.

1. Check where you stand. Run your domain through our email spoofing check or ask whoever manages your DNS to show you the SPF and _dmarc records. Note whether DMARC is missing, at p=none or enforcing.

2. List every service that sends email as your domain. Microsoft 365 or Google Workspace, plus the ones people forget: the accounting package that emails invoices, the newsletter tool, the booking system, the website contact form, the scanner that emails PDFs.

3. Publish one correct SPF record and turn on DKIM. One SPF record only, including each legitimate sender, ending in ~all or -all. Enable DKIM signing in Microsoft 365 or Google Workspace and in each third-party sender that supports it.

4. Publish DMARC at p=none with a reporting address, then read the reports. The rua address is the part two thirds of Vaughan's p=none domains are missing. A few weeks of reports show which legitimate senders still fail, so you can fix them before enforcing.

5. Move to quarantine, then reject. Once the reports show your own mail passing, step up to p=quarantine and then p=reject. Recheck whenever you add a new email tool.

This is routine work for us and part of the cybersecurity services we run for Vaughan businesses, alongside multi-factor authentication, Microsoft 365 hardening and tested backups. For the wider picture of how we support local companies, see our IT support in Vaughan page, or call (289) 582-9930. IT Rapid Support is at 7810 Keele St, Vaughan, ON L4K 0B7.

Frequently Asked Questions

What percentage of Vaughan businesses enforce DMARC?

In our scan of 290 mail-enabled Vaughan business domains on 4 October 2026, 52 (17.9%) had DMARC set to quarantine or reject. 96 (33.1%) had DMARC at p=none, which takes no action, and 141 (48.6%) had no DMARC record at all.

Is a DMARC policy of p=none enough?

It is enough to meet the Google, Yahoo and Microsoft minimum for bulk senders, but it does not stop anyone spoofing your domain, because p=none asks receivers to take no action on failing mail. It is meant as a monitoring stage with a reporting address, followed by quarantine and then reject.

Do small Vaughan businesses have to follow the Gmail, Yahoo and Outlook sender rules?

The DMARC requirement applies to senders of more than 5,000 messages a day to those providers. Every sender to Gmail and Yahoo still needs SPF or DKIM, and a business that sends newsletters or automated invoices through another platform can reach bulk volume without realising it. Setting up SPF, DKIM and DMARC protects deliverability either way.

Did you check or contact any individual business?

No. We only read public DNS records, the same lookups any mail server performs when it receives an email, and we publish aggregates only. No business is named, ranked or contacted, and nothing was sent to any of the domains.

Can I reuse these figures?

Yes. Journalists, business associations and other researchers are welcome to cite the figures with attribution to IT Rapid Support and a link to this page. The aggregate table is available as a CSV file.

Share this resource

IT Rapid Support Team

IT Rapid Support Team

Managed IT & Cybersecurity, GTA

IT Rapid Support Team is a security expert with extensive experience in security research and analysis.

More from this author

Related Resources

All Resources
IT Support for Mississauga Logistics and Warehousing
guide
•
September 5, 2026

IT Support for Mississauga Logistics and Warehousing

IT support for Mississauga logistics and warehousing firms: WMS uptime, warehouse Wi-Fi and scanners, EDI and carrier portals, 24/7 shifts, ransomware.

Read more: IT Support for Mississauga Logistics and Warehousing
IT for Medical and Dental Offices in Mississauga
guide
•
September 5, 2026

IT for Medical and Dental Offices in Mississauga

What PHIPA expects of a Mississauga medical or dental office's IT: breach reporting, EMR vendors, backups, MFA, phishing and patient Wi-Fi separation.

Read more: IT for Medical and Dental Offices in Mississauga
LSO Technology Competence: What Ontario Law Firms Need
guide
•
September 23, 2026

LSO Technology Competence: What Ontario Law Firms Need

What LSO rule 3.1-2 technology competence requires of Ontario law firms, with a checklist by firm size, common gaps and how to document compliance.

Read more: LSO Technology Competence: What Ontario Law Firms Need

Need Expert Security Advice?

Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.

Get in Touch