In July 2026, I scanned the email security of 38 well-known Québec businesses and organizations — retailers, media, insurers, manufacturers. The finding is worrying: nearly one in three has no protection against spoofing. And since these are the biggest and best-resourced, the reality for small businesses is likely worse.
By default, email doesn't verify who is writing. Anyone can put yourcompany.com in the "From:" field and email your customers. Three protections stop this — SPF, DKIM and above all DMARC, which acts like a bouncer at the door of mail servers worldwide:
Concretely: for nearly one business in three in this sample, a fraudster could, this afternoon, send a fake invoice to their customers in their name — and it would land in the inbox, not spam. That is exactly the entry point for CEO fraud and fake invoices.
The picture isn't better for websites: 34% don't serve the HSTS security header, and 42% get a weak web security score (missing headers, incomplete HTTPS redirect). These are free settings that protect against interception and hijacking — yet almost nobody turns them on.
Remember: this sample is well-known businesses with budgets and often an IT team. If a third of them have no DMARC, picture the 8-person bakery, accounting firm or construction contractor with no IT staff. In our experience, these small businesses almost always start from zero protection. The share of spoofable small businesses in Québec is therefore very likely well above 31%.
Protecting yourself costs nothing and doesn't take weeks: DMARC, SPF and DKIM are simple DNS records. The first step is knowing where you stand — and that takes 15 seconds.
Enter your domain: in 15 seconds we test your SPF, DKIM, DMARC and website — free, no signup, public data only.
Run the free check →Method: each domain was analyzed with Cyberbilan's public scanner, which reads public information only (DNS records and site headers). No private data, no inbox access. Businesses are not named: only aggregate proportions are published. Results reproducible by anyone.