Also by us:LastSpamReporter

72% of Quebec Organizations Don't Block Email Impersonation

In August 2026 we checked the public DNS records of 296 Quebec organizations across nine sectors: health, universities, CEGEPs, school service centres, municipalities, police services, professional orders, law firms and accounting firms.

This was not a survey. Nobody was asked anything. We read the DMARC policy each organization has already published to the world — a public record anyone can look up in seconds.

We are not naming a single domain. The point isn't to embarrass anyone. It's that most of these organizations have never checked where they stand.

There are only three possible answers

DMARC is the rule a domain publishes telling every mail server on the internet what to do when someone forges a message in its name. There are three answers, and every organization has already chosen one — even if it chose by doing nothing.

PolicyWhat a receiving mail server does with the forgery
No record, or p=noneNothing. It lands in the inbox, looking genuine.
p=quarantineDelivers it, but files it to junk.
p=rejectRefuses it. It never arrives.

Only the third one stops the impersonation.

What 296 Quebec organizations chose

SectorNWide openJunk onlyBlocked
Health1759%23%18%
Universities1844%34%22%
Accounting firms1741%24%35%
Professional orders4738%60%2%
Law firms3735%27%38%
Municipalities (50 largest)5016%48%36%
Police services248%50%42%
School service centres388%66%26%
CEGEPs484%61%35%
All sectors29624%48%28%

24% are wide open — a forged message from those domains reaches the inbox indistinguishable from the real thing. 72% do not block impersonation at all, once you include the ones that only send it to junk.

The real story is the 48% in the middle

The organizations that surprised us aren't the negligent ones. They're the 142 of 296 sitting at p=quarantine.

Those organizations did the hard part. They published a DMARC record. They collected the reports. They worked out which of their own systems send mail on their behalf — the newsletter platform, the payroll tool, the ticketing system — which is genuinely the difficult, unglamorous part of a DMARC rollout.

Then they stopped one setting short and never flipped the last switch.

A forged message in the junk folder is still a forged message that was delivered. It can be found, opened and believed. Plenty of people go digging through junk for a message they were expecting — which is exactly the moment a convincing fake gets read.

The sector that stands out

Of the 47 professional orders that license Quebec's engineers, nurses, lawyers, accountants and doctors, exactly one fully blocks impersonation of its own domain.

That is 2% at full enforcement — the weakest result in the entire study.

These are organizations that hold membership rosters: names, professional addresses, licence numbers. A message reading "your licence status requires immediate attention", apparently from the body that actually issues that licence, is an unusually easy fake to build and an unusually effective one to receive.

The sector that already solved it

The most useful finding is the one that inverted our prediction: all 48 CEGEPs, 4% spoofable.

We double-checked that result against raw DNS precisely because it contradicted what we expected. It holds. The CEGEP network moved on DMARC together — the same reporting endpoints recur across many of them — and it worked.

That matters because it removes the two usual objections. An entire sector of 48 public institutions, none of them lavishly funded, did this. "Too hard" and "too expensive" are not the reason the rest haven't.

Worth adding: Quebec's own provincial government domain publishes p=reject, and because it sets no separate subdomain policy, every government body underneath it inherits that full enforcement. It is being done at scale, here, already.

How we measured it

Public DNS only — DMARC and MX records. No mail servers were probed, nothing was scanned. Every statement here is a verifiable fact about a public record as it stood in August 2026.

Two rules mattered enough to build into the tooling, because each one is a way the numbers could have come out wrong:

  • Subdomains inherit. No record at _dmarc.sub.example.org does not mean "no DMARC". Under RFC 7489 you resolve to the organizational domain and apply its subdomain policy. Skip this and you mislabel a large share of the public sector as unprotected when it is in fact fully covered.
  • A domain that receives no mail was excluded, not counted. Those are usually vanity or redirect domains, not the address an organization actually emails from. Counting them would inflate the result with domains nobody would bother to impersonate.

Some honest limits. Health is 17 distinct mail domains rather than 34 organizations, because the CISSS/CIUSSS network largely sends from one shared domain. Most municipal police forces have no mail domain of their own and use their city's, so those two sectors overlap and are not independent samples. Municipalities are the 50 largest by population rather than a census; every other sector is a complete census of its universe. Shares are rounded to whole percentages.

Check your own domain

The check takes about ten seconds and needs nothing but your domain name. It reads the same public record we read, and tells you which of the three answers you are currently giving.

If you find yourself at p=quarantine, you are closer than you think. The hard work is already behind you — what's left is the last switch.

Check your domain now →

Study conducted August 2026 on public DNS records. No organization is named. Method, per-sector results and limits are described in full above.

Want to read this later? Email it to yourself.

Stay ahead of email threats

Get our latest DMARC, SPF, and email-security guides in your inbox. No spam — unsubscribe anytime.

We only use your email to send blog updates. One click unsubscribes you.