Also by us:LastSpamReporter

59 of 100 Canadian News Media Domains Can Be Impersonated by Email

In September 2026 we read the public DNS records of 105 Canadian news outlets and media groups: the national newsrooms, the leading dailies and TV newsrooms of every province and territory, radio and web-only outlets, and the parent companies that own most of them.

This was not a survey. Nobody was asked anything. We read the DMARC policy each organization has already published to the world.

We are not naming a single domain. A newsroom whose address can be forged is a newsroom whose readers and sources can be fooled, and the point is to get that fixed, not to embarrass anyone.

Three possible answers

DMARC is the rule a domain publishes telling every mail server what to do when someone forges a message in its name.

PolicyWhat a receiving mail server does with the forgery
No record, or p=noneNothing. It lands in the inbox, looking genuine.
p=quarantineDelivers it, but files it to junk.
p=rejectRefuses it. It never arrives.

What Canada's news media chose

Of the 100 domains that receive mail:

  • 59 (59%) are wide open: 9 publish no DMARC record at all, 50 publish one set to none.
  • 25 (25%) send forgeries to junk.
  • 16 (16%) refuse them.

In other words, only 16 of 100 refuse a forged message outright. For 59, a forgery reaches anyone's inbox (readers, sources, advertisers, even the newsroom's own staff) looking exactly like the real thing.

Kind of outletNWide openJunk onlyBlocked
Daily newspapers4271%24%5%
Radio367%0%33%
Web-only outlets1457%21%21%
Television1650%19%31%
Weeklies, magazines, agency1250%42%8%
Parent companies1338%31%31%
RegionNWide openJunk onlyBlocked
Atlantic provinces1385%0%15%
Ontario1573%7%20%
The three territories667%33%0%
Saskatchewan and Manitoba757%14%29%
National outlets2454%17%29%
British Columbia and Alberta1850%50%0%
Québec1741%47%12%

Why it matters for a newsroom

A newsroom lives on two kinds of trust: readers who believe what arrives under its name, and sources who answer when a journalist writes. A forged message from a newsroom's own domain can ask a source for documents, send readers to a fake subscription page, or put words in a reporter's mouth. With a wide-open policy, nothing in the mail system stops it.

It works inside the building too: a fake note "from" the editor-in-chief to the newsroom, asking for a password or an urgent payment, arrives looking as real as the genuine one.

Most of them are one step away

37 of the 50 outlets at none already collect DMARC reports. They did the hard part: they know which systems send mail in their name. What is left is the switch that tells the rest of the internet to refuse the fakes.

And 20 of the 59 wide-open domains sit behind a paid email-security gateway (Proofpoint or Mimecast). The expensive part is bought. The free part, publishing the policy, is not done.

How we measured it

Public DNS only: DMARC and MX records, read on September 30, 2026. No mail server was probed, nothing was scanned. Every statement here is a verifiable fact about a public record as it stood that day.

  • A domain that receives no mail was excluded, not counted. 5 of the 105 publish no mail server.
  • Parent companies are counted once, for their own domain. Where a group owns several outlets, each outlet's own domain is also counted, because each one can be forged separately.
  • This is a selection, not a census: the outlets a reader in each province would name first, plus the groups that own them. Shares are rounded to whole percentages.

Check your own domain

The check takes about ten seconds and needs nothing but your domain name. It reads the same public record we read.

Check your domain now →

Study conducted September 2026 on public DNS records. No organization is named.

Want to read this later? Email it to yourself.

Stay ahead of email threats

Get our latest DMARC, SPF, and email-security guides in your inbox. No spam — unsubscribe anytime.

We only use your email to send blog updates. One click unsubscribes you.