Published August 2026·last updated 24 August 2026·DNS measured 22 August 2026
A charity's domain is an asset anyone can impersonate. Three public DNS records decide whether a forged message gets delivered — and on most charity domains, nothing stops it.
DMARC is not a yes/no. A domain sits on one of four rungs, and the distance
between the middle two is the whole point: p=none means the charity
has published a policy and asked to be told about failures, while nothing is
blocked. It is a real step — and it is not protection.
Reporting only the policy field would put 87,968 domains in one bucket labelled “none”. 30,921 of them have started.
29.8% publish no SPF record. SPF alone stops nothing — a receiving server still needs a DMARC policy to act on the result — but its absence means no step has been taken at all.
Note: a further 814 domains publish more than one SPF record. That is a misconfiguration, not a stricter setting: evaluation must fail when a second record is found, so the intended policy is never applied. They are counted apart from both groups.
9.3% (9,241) publish no MX record at all: the domain does not receive mail. That is not automatically a problem — a charity may use a different address entirely — but a domain that sends no mail and receives none still needs a DMARC policy, because an unprotected domain is exactly what a forger wants.
88.3% of 99,606 UK charity domains publish no enforcing DMARC policy, so nothing instructs a receiving mail server to reject a message forging the charity’s address (August 2026).
57.3% of UK charity domains publish no DMARC record at all; a further 30,921 publish one in monitor-only mode, which reports forgery without stopping it.
29.8% of UK charity domains publish no SPF record.
814 UK charity domains publish more than one SPF record - a misconfiguration that disables SPF entirely.
Method, reproducibility and licence
What we measured. For every crawled domain we resolved MX,
SPF (TXT) and DMARC (_dmarc. TXT) records from public DNS. Each
figure names the query behind it; re-running it against the same snapshot
reproduces the number.
What we did not measure: DKIM. Locating a DKIM key requires guessing selector names, and a guess that misses is indistinguishable from an absence. No figure here is a complete picture of a charity’s email security, and none should be quoted as one.
Denominator. Every crawled domain that returned a DNS answer. Unlike this project’s crawl-derived figures these are not filtered to exclude domains whose robots.txt declined our crawler: robots.txt governs HTTP fetching, not DNS lookups, so those domains are fully measured here and belong in the denominator.
Aggregates only. No charity, domain or address appears on this page, and the generator refuses to write a file that contains one.
Quote any figure freely with credit. For a formal reference:
Nebula Design (2026). Can you trust email from the UK's charities? Email security across 99,606 charity domains. Nebula Design Research, August 2026. Version 1.0, DNS measured 22 August 2026. https://nebula.design/research/uk-charity-email-security-2026/
The aggregate table behind every figure is data.csv - every number on this page can be recomputed from it. All aggregate figures are released under CC BY 4.0; register data is used under the Open Government Licence v3.0 (Crown Copyright). This page carries no information about any individual charity.