59 of 100 Canadian News Media Domains Can Be Impersonated by Email

In September 2026 we read the public DNS records of 105 Canadian news outlets and media groups: the national newsrooms, the leading dailies and TV newsrooms of every province and territory, radio and web-only outlets, and the parent companies that own most of them.
This was not a survey. Nobody was asked anything. We read the DMARC policy each organization has already published to the world.
We are not naming a single domain. A newsroom whose address can be forged is a newsroom whose readers and sources can be fooled, and the point is to get that fixed, not to embarrass anyone.
Three possible answers
DMARC is the rule a domain publishes telling every mail server what to do when someone forges a message in its name.
| Policy | What a receiving mail server does with the forgery |
|---|---|
No record, or p=none | Nothing. It lands in the inbox, looking genuine. |
p=quarantine | Delivers it, but files it to junk. |
p=reject | Refuses it. It never arrives. |
What Canada's news media chose
Of the 100 domains that receive mail:
- 59 (59%) are wide open: 9 publish no DMARC record at all, 50 publish one set to
none. - 25 (25%) send forgeries to junk.
- 16 (16%) refuse them.
In other words, only 16 of 100 refuse a forged message outright. For 59, a forgery reaches anyone's inbox (readers, sources, advertisers, even the newsroom's own staff) looking exactly like the real thing.
| Kind of outlet | N | Wide open | Junk only | Blocked |
|---|---|---|---|---|
| Daily newspapers | 42 | 71% | 24% | 5% |
| Radio | 3 | 67% | 0% | 33% |
| Web-only outlets | 14 | 57% | 21% | 21% |
| Television | 16 | 50% | 19% | 31% |
| Weeklies, magazines, agency | 12 | 50% | 42% | 8% |
| Parent companies | 13 | 38% | 31% | 31% |
| Region | N | Wide open | Junk only | Blocked |
|---|---|---|---|---|
| Atlantic provinces | 13 | 85% | 0% | 15% |
| Ontario | 15 | 73% | 7% | 20% |
| The three territories | 6 | 67% | 33% | 0% |
| Saskatchewan and Manitoba | 7 | 57% | 14% | 29% |
| National outlets | 24 | 54% | 17% | 29% |
| British Columbia and Alberta | 18 | 50% | 50% | 0% |
| Québec | 17 | 41% | 47% | 12% |
Why it matters for a newsroom
A newsroom lives on two kinds of trust: readers who believe what arrives under its name, and sources who answer when a journalist writes. A forged message from a newsroom's own domain can ask a source for documents, send readers to a fake subscription page, or put words in a reporter's mouth. With a wide-open policy, nothing in the mail system stops it.
It works inside the building too: a fake note "from" the editor-in-chief to the newsroom, asking for a password or an urgent payment, arrives looking as real as the genuine one.
Most of them are one step away
37 of the 50 outlets at none already collect DMARC reports. They did the hard
part: they know which systems send mail in their name. What is left is the switch that tells the rest of
the internet to refuse the fakes.
And 20 of the 59 wide-open domains sit behind a paid email-security gateway (Proofpoint or Mimecast). The expensive part is bought. The free part, publishing the policy, is not done.
How we measured it
Public DNS only: DMARC and MX records, read on September 30, 2026. No mail server was probed, nothing was scanned. Every statement here is a verifiable fact about a public record as it stood that day.
- A domain that receives no mail was excluded, not counted. 5 of the 105 publish no mail server.
- Parent companies are counted once, for their own domain. Where a group owns several outlets, each outlet's own domain is also counted, because each one can be forged separately.
- This is a selection, not a census: the outlets a reader in each province would name first, plus the groups that own them. Shares are rounded to whole percentages.
Check your own domain
The check takes about ten seconds and needs nothing but your domain name. It reads the same public record we read.
Study conducted September 2026 on public DNS records. No organization is named.
Want to read this later? Email it to yourself.
Stay ahead of email threats
Get our latest DMARC, SPF, and email-security guides in your inbox. No spam — unsubscribe anytime.
We only use your email to send blog updates. One click unsubscribes you.