Benchmarks / UK estate agents
UK estate agents
Deposit diversion is the same attack wearing a different hat: an email that looks like it came from the agent, sending a tenant or buyer to the wrong account. High transaction values and a lot of email between strangers make this sector a standing target.
can be impersonated by email.
20 of 76 estate agents have no enforced DMARC policy, so a criminal can send mail that appears to come from them. Across 76 domains scanned.
Overall76 domains scanned
Can this sector be spoofed?
DMARC is the record that lets the world reject forged mail. Only an enforced policy (quarantine or reject) actually stops impersonation; p=none only watches.
- Enforced (p=reject) 53.9%
- Enforced (p=quarantine) 15.8%
- Monitor only (p=none) 19.7%
- No DMARC at all 10.5%
What we found, most common first
- 46.1%have no domain transfer lock35 of 76
Without it, anyone into the registrar account can move the domain away.
- 40.8%do not enforce HTTPS (no HSTS)31 of 76
A visitor’s first request can be downgraded to plain HTTP and intercepted.
- 26.3%can be impersonated by email20 of 76
No enforced DMARC policy, so a criminal can send mail that appears to come from them. This is the root of invoice and payment-redirection fraud.
- 3.9%have no SPF record3 of 76
Nothing tells receivers which servers may send mail for them, so more of their genuine mail is treated as spam.
- 2.6%expose a sensitive file or tool2 of 76
A .env file, .git directory, database tool or status page is reachable from the internet.
- 1.3%set tracking cookies before consent1 of 76
Analytics or advertising cookies are set on the first page load, which is the most commonly enforced cookie-law breach.
- 1.3%load insecure content on a secure page1 of 76
Mixed content quietly breaks the padlock visitors are told to trust.
- 1.3%have a certificate expiring within 30 days1 of 76
An expired certificate shows every visitor a full-page browser warning.
Common across the internetcontext, not a sector failing
- 98.7%have no CAA record75 of 76
Any certificate authority may issue a certificate for the domain. CAA adoption is low across the internet generally, not just here.
- 97.4%have DNSSEC switched off74 of 76
DNS answers are unsigned. DNSSEC remains rare across the whole web, so this is context rather than a sector-specific failing.
- 51.3%run third-party scripts on the page39 of 76
Common everywhere. It only becomes a PCI DSS 4.0 obligation on pages that take card details, where each script must be inventoried and watched.
Weakest categories
- 30.3%Email authenticationgraded D or worse
- 2.6%Web securitygraded D or worse
- 1.3%DNSgraded D or worse
- 1.3%Domain and registrationgraded D or worse
- 1.3%Content and SEOgraded D or worse
How we measure this
Agencies listed on major UK property portals and trade bodies. We run the same public checks we run for customers, entirely from the public internet, with nothing installed anywhere. We publish sector averages only: no organisation is named, linked or individually reported, and we do not publish findings about any specific business. This sample leans towards larger and better-resourced organisations, so the real figure across the whole sector is likely to be worse, not better.
See how you compare.
Free, no signup, about a minute.