Skip to main content

Local research, August 2026

Southwest Michigan Email Security Report: 2026 Edition

We audited 698 Southwest Michigan business domains. Of the 567 that actually send and receive email, 84.7% have no DMARC enforcement. In plain English, that means anyone can send an email that looks like it comes from those businesses, and nothing stops it from landing in a customer's inbox.

84.7%

No DMARC enforcement

480 of 567 mail-capable domains. Anyone can send email as them.

53.4%

No DMARC record at all

303 of 567 domains publish nothing.

31.2%

Monitoring only (p=none)

177 of 567 domains watch but block nothing.

15.2%

Actually enforcing

86 of 567 domains: 58 quarantine, 28 reject.

To cite: Parallax Intelligence audit, August 2026. 84.7% of 567 mail-capable businesses (698 audited) have no DMARC enforcement.

What does "no enforcement" mean?

A DMARC record is a small DNS setting that tells a receiving mail server what to do with a message that fails authentication. Set it to enforce, and a forged email claiming to be from your business gets rejected or sent to spam. Leave it missing, or set to "monitor only," and that forged email sails through to your customer's inbox looking exactly like you sent it. Of the 567 Southwest Michigan business domains in this audit that actually send and receive mail, 303 publish no DMARC record at all and 177 have one that enforces nothing.

The numbers by city

City Mail-capable domains No enforcement
Battle Creek 144 81.3% (117)
Kalamazoo 62 77.4% (48)
Marshall 48 85.4% (41)
Holland 24 83.3% (20)

City rows cover 278 of the 567 mail-capable domains; the rest are in smaller towns or have no city on record.

Every city in the table comes in above three out of four domains unprotected. Marshall is the least protected of the four; Kalamazoo, while still exposed, has the strongest numbers.

Who runs the email, by provider

Provider Mail-capable domains
Microsoft 365 150
Google Workspace 139
Self-hosted 54
GoDaddy 32
Proofpoint 18
Rackspace 7
Other or unknown 153

Microsoft 365 and Google Workspace together run more than half of the 567 mail-capable domains we checked. Neither platform turns on DMARC enforcement by default; a business has to set it up, which is exactly the gap this report measures.

Why this matters for a small business

Email impersonation is the front door for invoice fraud and payment scams. The FBI's Internet Crime Complaint Center calls business email compromise one of the most financially damaging online crimes, and it usually starts with a message that looks like it came from a real, trusted business. On top of that, Google now requires senders to authenticate their email or risk landing in spam, even when the message is genuine. Both problems share one fix: turn on enforcement.

How we measured this

Every figure here comes from a live DNS lookup of each business domain's published DMARC policy and mail server (MX) records, taken at the latest audit in our dataset and verified against live DNS in July 2026. "Mail-capable" means the domain has a working MX record today, so we only count domains that actually receive email; every percentage on this page is out of those 567. "No enforcement" means either no DMARC record, or a record set to p=none, which monitors but blocks nothing. One mail-capable domain's audit did not read its DMARC policy, so it counts in the 567 but in none of the four policy figures. This is a point-in-time snapshot of public DNS records, not a claim that any business was breached, and we never name an individual business. This edition covers Q3 2026.

Questions about this report

What is DMARC?
DMARC is a DNS record that tells email servers what to do with a message that claims to be from your domain but fails authentication. It's free to set up and most business email platforms support it, but it isn't turned on by default.
What does "no enforcement" mean?
It means a business either has no DMARC record at all, or has one set to "monitor only" (p=none), which watches for forged email but does not block any of it. Both leave the door open for spoofing.
Is my business named in this report?
No. This report only publishes city and provider level figures. We never name, list, or identify an individual business.
How was this data collected?
We ran a live DNS lookup against each domain's published DMARC policy and mail server records. Every number on this page comes from that audit, not a survey or a third-party estimate.
Which email providers had the least protection?
The audit scores domains, not providers. But Microsoft 365 and Google Workspace, the two most common platforms among the businesses we checked, both leave DMARC for the domain owner to set up. Neither turns on enforcement out of the box.
What should I do if my domain has no enforcement?
Run a free check to see where your domain stands, then set your DMARC record to p=quarantine or p=reject once you've confirmed your legitimate mail sources. A one-minute check tells you which state you're in.

Is your domain one of them?

Run our free one-minute check and find out whether someone can send email as your business, in plain English, with no signup.

Get my free email check Try the savings calculator