Benchmarks / UK accountants
UK accountants
Invoice fraud and client-data duty in one place. A practice sends payment instructions and holds financial records for dozens of businesses, so a spoofable domain is not a theoretical risk to them, it is a risk to every client on their books.
can be impersonated by email.
15 of 69 accountants have no enforced DMARC policy, so a criminal can send mail that appears to come from them. Across 69 domains scanned.
Overall69 domains scanned
Can this sector be spoofed?
DMARC is the record that lets the world reject forged mail. Only an enforced policy (quarantine or reject) actually stops impersonation; p=none only watches.
- Enforced (p=reject) 40.6%
- Enforced (p=quarantine) 29%
- Monitor only (p=none) 20.3%
- No DMARC at all 10.1%
What we found, most common first
- 53.6%have no domain transfer lock37 of 69
Without it, anyone into the registrar account can move the domain away.
- 43.5%do not enforce HTTPS (no HSTS)30 of 69
A visitor’s first request can be downgraded to plain HTTP and intercepted.
- 21.7%can be impersonated by email15 of 69
No enforced DMARC policy, so a criminal can send mail that appears to come from them. This is the root of invoice and payment-redirection fraud.
- 4.3%have no SPF record3 of 69
Nothing tells receivers which servers may send mail for them, so more of their genuine mail is treated as spam.
- 1.4%load insecure content on a secure page1 of 69
Mixed content quietly breaks the padlock visitors are told to trust.
- 1.4%expose a sensitive file or tool1 of 69
A .env file, .git directory, database tool or status page is reachable from the internet.
Common across the internetcontext, not a sector failing
- 95.7%have no CAA record66 of 69
Any certificate authority may issue a certificate for the domain. CAA adoption is low across the internet generally, not just here.
- 94.2%have DNSSEC switched off65 of 69
DNS answers are unsigned. DNSSEC remains rare across the whole web, so this is context rather than a sector-specific failing.
- 60.9%run third-party scripts on the page42 of 69
Common everywhere. It only becomes a PCI DSS 4.0 obligation on pages that take card details, where each script must be inventoried and watched.
Weakest categories
- 29%Email authenticationgraded D or worse
- 4.3%Content and SEOgraded D or worse
- 2.9%DNSgraded D or worse
How we measure this
Practices listed on UK professional body registers. We run the same public checks we run for customers, entirely from the public internet, with nothing installed anywhere. We publish sector averages only: no organisation is named, linked or individually reported, and we do not publish findings about any specific business. This sample leans towards larger and better-resourced organisations, so the real figure across the whole sector is likely to be worse, not better.
See how you compare.
Free, no signup, about a minute.