Can you trust email from the UK's charities?

A charity's domain is an asset anyone can impersonate. Three public DNS records decide whether a forged message gets delivered — and on most charity domains, nothing stops it.

88.3%
publish no enforcing DMARC policy
nothing rejects a forged address
57.3%
publish no DMARC record at all
29.8%
publish no SPF record
99,606
charity domains measured
MX, SPF and DMARC

01 · The DMARC ladder

Publishing a policy is not the same as enforcing one

DMARC is not a yes/no. A domain sits on one of four rungs, and the distance between the middle two is the whole point: p=none means the charity has published a policy and asked to be told about failures, while nothing is blocked. It is a real step — and it is not protection.

Reporting only the policy field would put 87,968 domains in one bucket labelled “none”. 30,921 of them have started.

Fig. 1Where charity domains sit on the DMARC ladderPNG
  • no DMARC record57,04757.3%
  • p=none (monitoring only)30,92131.0%
  • p=quarantine6,9517.0%
  • p=reject4,6874.7%
Query dmarc-absent · dmarc-unprotected · run 12 · 99,606 domains

02 · SPF

29.8% have not taken the first step

29.8% publish no SPF record. SPF alone stops nothing — a receiving server still needs a DMARC policy to act on the result — but its absence means no step has been taken at all.

Note: a further 814 domains publish more than one SPF record. That is a misconfiguration, not a stricter setting: evaluation must fail when a second record is found, so the intended policy is never applied. They are counted apart from both groups.

03 · Who runs the mail

Microsoft 365 and Google Workspace carry 42% of the sector between them

Fig. 2Mail providers by share of charity domainsPNG
Microsoft 36525.7%
None recorded18.9%
Google Workspace15.9%
Other providers14.7%
Their own server8.9%
IONOS4.7%
GoDaddy1.7%
Fasthosts1.4%
Query: MX lookup, run 12 · 99,606 domains

9.3% (9,241) publish no MX record at all: the domain does not receive mail. That is not automatically a problem — a charity may use a different address entirely — but a domain that sends no mail and receives none still needs a DMARC policy, because an unprotected domain is exactly what a forger wants.

04 · Ready to quote

Key takeaways

Method, reproducibility and licence

How these figures were produced

What we measured. For every crawled domain we resolved MX, SPF (TXT) and DMARC (_dmarc. TXT) records from public DNS. Each figure names the query behind it; re-running it against the same snapshot reproduces the number.

What we did not measure: DKIM. Locating a DKIM key requires guessing selector names, and a guess that misses is indistinguishable from an absence. No figure here is a complete picture of a charity’s email security, and none should be quoted as one.

Denominator. Every crawled domain that returned a DNS answer. Unlike this project’s crawl-derived figures these are not filtered to exclude domains whose robots.txt declined our crawler: robots.txt governs HTTP fetching, not DNS lookups, so those domains are fully measured here and belong in the denominator.

Aggregates only. No charity, domain or address appears on this page, and the generator refuses to write a file that contains one.

How to cite this page

Quote any figure freely with credit. For a formal reference:

Nebula Design (2026). Can you trust email from the UK's charities? Email security across 99,606 charity domains. Nebula Design Research, August 2026. Version 1.0, DNS measured 22 August 2026. https://nebula.design/research/uk-charity-email-security-2026/

The aggregate table behind every figure is data.csv - every number on this page can be recomputed from it. All aggregate figures are released under CC BY 4.0; register data is used under the Open Government Licence v3.0 (Crown Copyright). This page carries no information about any individual charity.