Benchmarks / UK charities
UK charities
Donation pages take card details and donation fraud is common, because a fake appeal from a real-looking charity address is unusually persuasive. Charities also run on small teams and donated time, which is exactly where certificate and DNS drift goes unnoticed.
can be impersonated by email.
21 of 95 charities have no enforced DMARC policy, so a criminal can send mail that appears to come from them. Across 95 domains scanned.
Overall95 domains scanned
Can this sector be spoofed?
DMARC is the record that lets the world reject forged mail. Only an enforced policy (quarantine or reject) actually stops impersonation; p=none only watches.
- Enforced (p=reject) 35.8%
- Enforced (p=quarantine) 38.9%
- Monitor only (p=none) 22.1%
- No DMARC at all 3.2%
What we found, most common first
- 44.2%have no domain transfer lock42 of 95
Without it, anyone into the registrar account can move the domain away.
- 24.2%do not enforce HTTPS (no HSTS)23 of 95
A visitor’s first request can be downgraded to plain HTTP and intercepted.
- 22.1%can be impersonated by email21 of 95
No enforced DMARC policy, so a criminal can send mail that appears to come from them. This is the root of invoice and payment-redirection fraud.
- 6.3%have a certificate expiring within 30 days6 of 95
An expired certificate shows every visitor a full-page browser warning.
- 1.1%have no SPF record1 of 95
Nothing tells receivers which servers may send mail for them, so more of their genuine mail is treated as spam.
- 1.1%set tracking cookies before consent1 of 95
Analytics or advertising cookies are set on the first page load, which is the most commonly enforced cookie-law breach.
Common across the internetcontext, not a sector failing
- 95.8%have DNSSEC switched off91 of 95
DNS answers are unsigned. DNSSEC remains rare across the whole web, so this is context rather than a sector-specific failing.
- 94.7%have no CAA record90 of 95
Any certificate authority may issue a certificate for the domain. CAA adoption is low across the internet generally, not just here.
- 68.4%run third-party scripts on the page65 of 95
Common everywhere. It only becomes a PCI DSS 4.0 obligation on pages that take card details, where each script must be inventoried and watched.
Weakest categories
- 25.3%Email authenticationgraded D or worse
- 3.2%Payment securitygraded D or worse
- 2.1%DNSgraded D or worse
- 2.1%Domain and registrationgraded D or worse
- 1.1%Content and SEOgraded D or worse
How we measure this
Registered charities from the Charity Commission register, which is public. We run the same public checks we run for customers, entirely from the public internet, with nothing installed anywhere. We publish sector averages only: no organisation is named, linked or individually reported, and we do not publish findings about any specific business. This sample leans towards larger and better-resourced organisations, so the real figure across the whole sector is likely to be worse, not better.
See how you compare.
Free, no signup, about a minute.