Defaults.Exposed

Money moves by email on domains that can be spoofed

When a business connects its domain to a payment processor, an e-signature service, a mailing platform or a collaboration suite, the vendor usually asks it to publish a TXT (Text) record at the apex holding a string only that vendor issued. The record is a receipt: someone who controls the zone proved it to that vendor at some point. The census can’t tell whether the account behind it is still open.

The September 2026 census read the apex TXT records of the 316,600,902 domains carrying a grade, so those receipts can be counted and set beside the one record that decides whether mail claiming to be from the domain can be forged: DMARC (Domain-based Message Authentication, Reporting and Conformance).

Take Stripe. 92,762 of those domains carry Stripe’s proof-of-ownership token, the record Stripe asks for before it will send receipts, invoices and failed-payment notices from a business’s own domain instead of stripe.com. 88.4% of them publish a DMARC record, against 24.8% of all domains carrying a grade.

Only 33.1% of the Stripe-verified domains enforce DMARC with p=quarantine or p=reject. 55.2% sit at p=none, which asks receiving mail servers to deliver mail that fails the check as normal and send the domain a report.

Contracts do better than payments. Of the 56,830 domains an organisation has claimed in DocuSign, 60.9% enforce DMARC. Marketing does worse: of the 295,854 domains verified with Klaviyo, 24.8% enforce and 69.2% sit at p=none.

Each commercial cohort with more than a thousand domains is ahead of the census as a whole on DMARC enforcement and on SPF (Sender Policy Framework) records ending -all, and has fewer domains with no DMARC record. Each is also ahead of the control cohort of domains that proved themselves to Google, where 17.8% enforce.

What a verification token proves

A token also says nothing about how much the account is used, or whether the vendor’s own mail authentication records were ever finished. Each cohort below is named by what its token proves, no more.

CohortWhat its token provesDomains
Stripestripe-verification=: the domain was verified in a Stripe account. Stripe’s documentation lists a proof-of-ownership TXT record as the first of three DNS (Domain Name System) records for a custom email domain, the setting that sends receipts, invoices and failed-payment notices from the business’s own domain.92,762
DocuSigndocusign=: an organisation claimed the domain in DocuSign Admin, which puts the DocuSign users with email addresses at that domain under the organisation’s management.56,830
HubSpot developer apphubspot-developer-verification=: the domain was verified for a HubSpot developer account. This is the token an app builder places; it doesn’t identify HubSpot CRM or Marketing Hub customers, whose sending domains are verified with CNAME (Canonical Name) records.12,268
Klaviyoklaviyo-site-verification=: the domain was verified in a Klaviyo account, the ownership step before a branded sending domain for marketing email.295,854
Mailchimpmailchimp-domain-verification=: the domain was verified in a Mailchimp account by its apex TXT method. Mailchimp verifies most sending domains by CNAME, so this cohort is tiny and isn’t the Mailchimp customer base.144
Atlassian organisationatlassian-domain-verification=: an Atlassian organisation verified the domain so it can manage the accounts of users with email addresses at it. Atlassian’s separate sending-domain token, for Jira and Confluence notification mail, is a different record and isn’t counted here.210,562
Zoomzoom-domain-verification=: the domain was verified in a Zoom account.4,105
Slackslack-domain-verification=: a Slack workspace or Enterprise Grid claimed the domain for its email addresses.29,094
Google Search Console (control)google-site-verification=: someone proved control of the domain to a Google product, most often Search Console. It says nothing about money or email, which is why it stands in as the control.29,008,806

The cohorts overlap. A domain that carries Stripe, DocuSign and Google tokens sits in three rows. The nine rows sum to 29,710,425 memberships, and 36,886,085 distinct domains carry at least one of the 22 tokens counted for this page, so the rows are not added together anywhere on this page.

Nine cohorts against DMARC and SPF

Each share in this table uses its own row’s domain count as the base. “Enforce” is a DMARC policy of p=quarantine or p=reject. “p=none” is a record with that policy. “No DMARC” is no record at all; the small remainder in each row is a record with no valid p= tag. “SPF -all” is an SPF record that ends in -all, which tells receivers to reject mail from any server the record doesn’t list.

The rows are ranked by the enforce share, and the last row is all domains carrying a grade, whatever their TXT records say.

CohortDomainsEnforcep=noneNo DMARCSPF -all
DocuSign56,83060.9%26.9%12.2%56.2%
Slack29,09451.9%31.8%16.2%36.1%
Atlassian organisation210,56250.8%28.9%20.3%52.7%
HubSpot developer app12,26839.7%43.2%17.1%29.3%
Zoom4,10534.5%40.9%24.6%22.6%
Stripe92,76233.1%55.2%11.6%24.9%
Klaviyo295,85424.8%69.2%5.9%26.5%
Google Search Console (control)29,008,80617.8%24.6%57.5%15.4%
Mailchimp1440.0%91.0%9.0%93.8%
All domains carrying a grade316,600,90211.6%13.2%75.2%18.2%

Stacked bars splitting each cohort's domains by DMARC policy, in the order of the table. Share enforcing with p=quarantine or p=reject: DocuSign 60.9%, Slack 51.9%, Atlassian organisation 50.8%, HubSpot developer app 39.7%, Zoom 34.5%, Stripe 33.1%, Klaviyo 24.8%, Google control 17.8%, Mailchimp 0.0%, all domains carrying a grade 11.6%. Share with no DMARC record, same order: 12.2%, 16.2%, 20.3%, 17.1%, 24.6%, 11.6%, 5.9%, 57.5%, 9.0%, 75.2%.

Figure 1. Each bar is one cohort, split by the DMARC policy the census read, with the cohort’s own domain count on the right. The cohorts overlap, so the bars are not added together.

DocuSign, Slack and Atlassian, the cohorts where an administrator claims a domain for a whole organisation, lead the table, and in each of them half or more of the domains enforce DMARC. The Mailchimp row is 144 domains and too small to read.

Stripe sits in the lower half with a shape of its own. Its no-DMARC share, 11.6%, is among the lowest in the table, and its p=none share, 55.2%, is the second highest of the cohorts with more than a thousand domains, behind Klaviyo.

Stripe’s setup page for a custom email domain says a DMARC policy is required and suggests starting at p=none, then moving to quarantine or reject. Most Stripe-verified domains publish a record, and most of those records say p=none. The census can’t show whether that advice played any part. Klaviyo’s row has the same shape at a larger scale: 5.9% without a record, 69.2% at p=none.

The control cohort and the baseline read the other way round. Among the 29,008,806 domains that proved themselves to Google, 57.5% have no DMARC record at all, and among all domains carrying a grade the figure is 75.2%. Restricting the control to the 26,315,677 domains whose only verification-shaped TXT record is Google’s moves it little: 16.8% enforce and 59.3% have no record.

How the SPF record ends

Most domains in every commercial cohort publish SPF: 88.3% of Stripe-verified domains do, against 47.4% of all domains carrying a grade. The table splits each cohort by the mechanism that ends the record, on the same base as the table above.

CohortSPF record-all~all?all, +all or no recognised endingNo SPF
DocuSign97.6%56.2%38.7%2.7%2.4%
Slack93.6%36.1%55.2%2.3%6.4%
Atlassian organisation94.6%52.7%39.2%2.7%5.4%
HubSpot developer app88.7%29.3%57.3%2.1%11.3%
Zoom80.0%22.6%55.9%1.6%20.0%
Stripe88.3%24.9%60.2%3.2%11.7%
Klaviyo82.2%26.5%53.5%2.2%17.8%
Google Search Console (control)68.2%15.4%49.7%3.1%31.8%
Mailchimp98.6%93.8%4.9%0.0%1.4%
All domains carrying a grade47.4%18.2%26.6%2.6%52.6%

Stacked bars splitting each cohort's domains by how the SPF record ends, in the order of the first table. Share ending -all: DocuSign 56.2%, Slack 36.1%, Atlassian organisation 52.7%, HubSpot developer app 29.3%, Zoom 22.6%, Stripe 24.9%, Klaviyo 26.5%, Google control 15.4%, Mailchimp 93.8%, all domains carrying a grade 18.2%. Share ending ~all, same order: 38.7%, 55.2%, 39.2%, 57.3%, 55.9%, 60.2%, 53.5%, 49.7%, 4.9%, 26.6%.

Figure 2. Each bar is one cohort, split by the mechanism that ends its SPF record.

In the Stripe cohort ~all outnumbers -all by more than two to one (60.2% to 24.9%), and ~all leads in the Klaviyo, Zoom, HubSpot, Slack and Google rows as well. DocuSign and Atlassian, which lead on DMARC, also lead on -all at 56.2% and 52.7%. The SPF all qualifier page covers what a receiver does with each ending; ~all together with p=none leaves a forged message deliverable.

Where a DKIM key was found

The census can only judge DKIM (DomainKeys Identified Mail) where it knows where to look: the domain needs a mail exchanger at a provider whose DKIM selectors the census probes. Elsewhere the result is undetermined, and the site’s data page leaves those domains out of the DKIM base in the same way. So this table has its own base: the domains in each cohort where DKIM could be evaluated. The last two columns split that share by generic and country-code domains, each on its own evaluated base.

CohortDKIM evaluatedKey foundKey found, gTLDKey found, ccTLD
DocuSign52,91866.3%64.3%71.9%
Slack28,01571.8%71.8%71.8%
Atlassian organisation190,17267.5%66.6%69.0%
HubSpot developer app10,75866.4%66.9%65.6%
Zoom3,05259.2%60.1%57.8%
Stripe75,83863.6%63.2%64.5%
Klaviyo238,19543.8%42.8%46.1%
Google Search Console (control)18,478,60742.0%39.3%48.4%
Mailchimp4697.8%85.7%100.0%
All graded domains where DKIM could be determined75,823,11950.1%45.2%61.6%

Horizontal bars of the share of each cohort's evaluated domains where a DKIM key was found, in the order of the first table: DocuSign 66.3%, Slack 71.8%, Atlassian organisation 67.5%, HubSpot developer app 66.4%, Zoom 59.2%, Stripe 63.6%, Klaviyo 43.8%, Google control 42.0%, Mailchimp 97.8%, all domains carrying a grade 50.1%.

Figure 3. The share of each cohort’s evaluated domains where a DKIM key answered, with the number of evaluated domains on the right.

A found key is a floor. The census probes the one to three selectors that the domain’s mail provider publishes, so a key under any other selector goes unseen, and a domain that signs through a marketing platform’s own selector can still show as not found.

The Klaviyo row, at 43.8%, sits below the other commercial cohorts and below the census as a whole, at 50.1% of the 75.8 million domains where DKIM could be determined. The other six large commercial cohorts are all ahead of the census on this measure. The census can’t separate how much of Klaviyo’s gap comes from keys it didn’t look for.

Generic and country-code domains

The shares above blend generic top-level domains such as .com with country-code domains such as .de and .uk, and the two groups differ across the census: 10.5% of generic domains carrying a grade enforce DMARC, against 14.3% of country-code domains, and 78.4% against 67.0% have no record. The table splits the DMARC and SPF columns by TLD type, following IANA’s root zone database, with each cell on its own row’s base.

CohortgTLD domainsEnforceNo DMARCSPF -allccTLD domainsEnforceNo DMARCSPF -all
DocuSign41,45760.3%12.3%53.1%15,37362.6%11.9%64.6%
Slack20,16553.2%16.2%36.0%8,92949.0%16.2%36.2%
Atlassian organisation127,41051.6%20.4%49.7%83,15249.5%20.2%57.2%
HubSpot developer app7,79140.7%17.6%29.3%4,47738.0%16.2%29.4%
Zoom2,57135.4%26.3%22.8%1,53432.9%21.6%22.2%
Stripe61,77433.0%12.0%23.1%30,98833.4%10.6%28.4%
Klaviyo203,17324.1%6.0%24.5%92,68126.2%5.7%30.8%
Google Search Console (control)19,728,54717.8%59.6%13.4%9,280,25917.8%53.1%19.5%
Mailchimp100.0%40.0%50.0%1340.0%6.7%97.0%
All domains carrying a grade229,046,22510.5%78.4%17.5%87,554,67714.3%67.0%20.0%

The vendor pattern holds on both sides. Stripe-verified domains enforce at 33.0% under generic TLDs and 33.4% under country codes, DocuSign at 60.3% and 62.6%. Across the census the country-code side is ahead on enforcement; within the commercial cohorts the two sides sit within a few points of each other.

Beside the Hidden SaaS Map

DomainsProject published The Hidden SaaS Map on 2 May 2026, a count of vendor verification tokens from a DNS crawl on 17 April 2026. Readers will set its per-vendor figures beside this page’s, so the difference in method comes first.

That crawl queried around 1.9 billion hostnames and folded each hit to its registrable apex with the Public Suffix List, so a token found on any subdomain counts for the apex, and it matched a catalogue of more than 50 vendor token formats. It reported 40,180,281 apexes with at least one tracked token, 25,988,287 for Google and 7,624,510 for Microsoft 365.

For the vendors on this page it reported 96,753 apexes for Stripe, 59,158 for DocuSign, 56,735 for HubSpot, 260,461 for Klaviyo, 230,746 for Atlassian, 61,135 for Zoom and 79,958 for Mailchimp and Mandrill together. It didn’t read DMARC, DKIM or SPF policy for any of them.

This page counts apex TXT records only, over the 316,600,902 domains the September 2026 census graded, and each cohort is one exact token string. The two sets differ in both directions: the census finds more Google and Klaviyo tokens and far fewer Zoom, HubSpot and Mailchimp ones. They differ in population, placement, token format and date, and this page doesn’t net one against the other.

What the census can and can’t see

The DMARC page explains what p=quarantine and p=reject do to forged mail, and the DKIM page covers selectors and where a key lives.

See your own

The free scan reads any domain live, on the same checks the census uses: DMARC policy, the SPF all mechanism, and a DKIM key at the selectors your mail provider publishes. If your business takes payments, signs contracts or sends customer mail from a domain, the result tells you whether that mail can be forged today.

Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. DomainsProject figures are from its Hidden SaaS Map of 2 May 2026 and are not census data. Census numbers move every month; the current values are on the data page.