Defaults.Exposed

Defaults.ExposedResearch › Domain Exposure by Industry

Domain Exposure by Industry

Data as of 2026-07-28 · 12 industries · "spoofable" = lacks an enforcing DMARC policy (`quarantine`/`reject`). Aggregate only.

Across the whole census, 88.2% of domains can be impersonated in email, 10% accept mail with no authentication at all, and 8.5% have none of the five core protections. Here's how industry domain endings compare — lower is better.

#IndustryDomainsSpoofableMail, no authFully exposed
1AI / Technology892,69470.2%4.7%4.1%
2Healthcare52,35577.5%4.5%7.3%
3Legal21,47480.7%9.1%10.5%
4Creative171,57981.8%10.2%8.1%
5Agencies107,11083.3%8.7%7.4%
6Retail4,791,82384.9%3.1%9.6%
7Technology1,308,34385.7%7.6%6.5%
8Software1,794,89986.5%4.2%6.8%
9Finance28,03086.6%7%8.5%
10Media87,45487.8%8.5%7.2%
11Design100,03288.1%9.9%8.3%
12Gaming57,21888.2%5.8%7.1%

"Spoofable" = share of domains with no enforcing DMARC policy, so the visible "From" address can be forged. "Mail, no auth" = has MX records but no working SPF/DMARC. "Fully exposed" = zero of five core protections (SPF, enforced DMARC, DNSSEC, HTTPS, HSTS). The domain ending is a proxy for the country/sector, not company registration.

Averages don't tell you about your domain. Check yours free → — owner-only, with exactly what to fix.

By country · By industry · By TLD · The exposure score → · Can someone spoof your domain? →