Benchmarks
What the UK’s websites actually look like from the outside.
We ran the same 34 public checks we run on any domain across five UK sectors, 445 organisations so far, and published the averages. Email authentication is the weakest point in every one of them, but it is not the only one.
Sectors, worst first
Ranked by how many can be impersonated by email, the root of invoice and payment-redirection fraud.
- UK online retailers113 scanned31.9% spoofableUK estate agents76 scanned26.3% spoofableUK charities95 scanned22.1% spoofableUK accountants69 scanned21.7% spoofableUK solicitors92 scanned15.2% spoofable
How the average UK domain scores
Across all 445 domains we have scanned, pooled across every sector.
What actually fails, and how often
Every check we run, ranked by how many domains fail it. The clean column matters as much as the failing one: a check almost nobody passes is telling you something different from one most people manage.
The specific weaknesses
Named problems rather than grades, so each one is a fact you can check on your own domain in a minute.
- 40.9%have no domain transfer lock
Without it, anyone into the registrar account can move the domain away.
Worst sector: UK accountants at 53.6%
- 35.1%do not enforce HTTPS (no HSTS)
A visitor’s first request can be downgraded to plain HTTP and intercepted.
Worst sector: UK accountants at 43.5%
- 23.8%can be impersonated by email
No enforced DMARC policy, so a criminal can send mail that appears to come from them. This is the root of invoice and payment-redirection fraud.
Worst sector: UK online retailers at 31.9%
- 3.8%expose a sensitive file or tool
A .env file, .git directory, database tool or status page is reachable from the internet.
Worst sector: UK online retailers at 12.4%
- 3.1%have a certificate expiring within 30 days
An expired certificate shows every visitor a full-page browser warning.
Worst sector: UK charities at 6.3%
- 2%have no SPF record
Nothing tells receivers which servers may send mail for them, so more of their genuine mail is treated as spam.
Worst sector: UK accountants at 4.3%
- 0.7%load insecure content on a secure page
Mixed content quietly breaks the padlock visitors are told to trust.
Worst sector: UK accountants at 1.4%
- 0.4%set tracking cookies before consent
Analytics or advertising cookies are set on the first page load, which is the most commonly enforced cookie-law breach.
Worst sector: UK estate agents at 1.3%
Three more that are common across the whole internet, not just here
True of these sectors, and true almost everywhere else too. Listing them alongside the findings above would overstate how unusual they are.
- 95.3%have DNSSEC switched off
DNS answers are unsigned. DNSSEC remains rare across the whole web, so this is context rather than a sector-specific failing.
- 92.6%have no CAA record
Any certificate authority may issue a certificate for the domain. CAA adoption is low across the internet generally, not just here.
- 56.2%run third-party scripts on the page
Common everywhere. It only becomes a PCI DSS 4.0 obligation on pages that take card details, where each script must be inventoried and watched.
Who can be impersonated by email
DMARC is what tells the world to reject mail forged in your name. Published but unenforced (p=none) is the trap: it looks configured, and it stops nothing.
- Enforced (p=reject) 47.9%
- Enforced (p=quarantine) 25.2%
- Published but not enforced 22%
- No DMARC record at all 4.9%
We publish sector averages only. Individual results are never shown, named or linked, and we do not publish findings about any specific organisation. Samples lean towards larger organisations, so real sector figures are likely worse.
Where do you sit against your sector?
Free, no signup, about a minute.