We checked 51 small-business domains: 30 could be spoofed by email. Here's how to find these prospects automatically
If you sell IT, security or web services to small businesses, the hardest part of outreach is the first line. "We help businesses with cybersecurity" gets ignored. "Anyone can currently send email that looks like it's from @yourfirm.com, and here's the DNS record that proves it" gets read. We wanted to know how common those verifiable, fixable problems really are, so we ran passive, public-only…
The study checked the DNS records, email setup and security of 51 small businesses across South Africa and the United States. Roughly 60% of these firms could have their email accounts spoofed, as many lacked DMARC records. Over a third of the firms didn't implement DKIM keys, and outdated software like jQuery 3.5 or PHP 10 were in use by some.
Additionally, 3 out of the 51 domains were about to expire. The research found that DMARC was the most critical issue, as it can prevent email spoofing attempts that often lead to invoice fraud. A scoring system was developed to rank businesses based on the severity of their security issues, enabling salespeople to focus on the most critical cases first.
The findings emphasize the importance of implementing DMARC and other security measures to protect businesses from email-based threats.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.