Original research · Colorado Springs · 2026
84% of the Colorado Springs business email domains we checked can be impersonated.
We checked the public email-security records of 821 business email domains in El Paso and Teller County. 84% have nothing in place that tells the world’s mail servers to reject a message forged in their name — the exact gap behind fake-invoice and payroll-change scams. No business is named here; this is what the whole community looks like.
The numbers
What 821 local business domains look like from the outside
All of this is public DNS — the same records every mail server in the world reads before deciding whether to trust a message from your domain.
84% spoofable
No DMARC policy, or one set to “monitor only” (p=none). Mail servers are told nothing about rejecting forgeries.
60% have no DMARC at all
DMARC is the record that lets you tell Gmail, Outlook and everyone else to reject mail that pretends to be you. Most local businesses never published one.
17% have no SPF
SPF lists which servers may send for your domain. Without it, anyone can.
4% have a weak SPF
Published, but ending in a rule that means “allow everything anyway”.
58% show no DKIM signing
No cryptographic signature on outgoing mail at any of the common selector names we checked, which hurts deliverability and makes spoofing easier.
6% are fully protected
DMARC set to reject, with SPF and DKIM in place. This is the standard your bank, your insurer and Google now expect.
By email provider
Where a business hosts its email changes the picture more than anything else. Microsoft 365 and Google Workspace make DKIM and DMARC a few clicks — but they are not on by default, and it shows.
| Domains | Spoofable | No DMARC | No SPF | No DKIM found | Fully protected | |
|---|---|---|---|---|---|---|
| Other/self-hosted | 281 | 81% | 58% | 11% | 50% | 11% |
| Google Workspace | 237 | 91% | 65% | 29% | 62% | 3% |
| Microsoft 365 | 207 | 83% | 60% | 1% | 55% | 2% |
| GoDaddy | 34 | 94% | 88% | 88% | 97% | 0% |
| IONOS | 24 | 100% | 21% | 8% | 96% | 0% |
| Email security gateway | 18 | 44% | 17% | 0% | 33% | 33% |
By industry
Ranked by share of spoofable domains. Industries with fewer than 15 checked domains are left out rather than over-read.
| Domains | Spoofable | No DMARC | No SPF | No DKIM found | Fully protected | |
|---|---|---|---|---|---|---|
| CPAs and tax | 17 | 94% | 47% | 6% | 59% | 0% |
| Property management | 80 | 92% | 61% | 20% | 65% | 0% |
| Manufacturing | 21 | 90% | 57% | 19% | 48% | 5% |
| Behavioral health | 44 | 89% | 70% | 20% | 50% | 7% |
| Medical practices | 67 | 88% | 58% | 21% | 64% | 6% |
| Construction and trades | 235 | 88% | 65% | 16% | 60% | 3% |
| Hospitality | 38 | 87% | 66% | 24% | 74% | 8% |
| Auto sales and repair | 27 | 85% | 67% | 22% | 59% | 0% |
| Technology and IT | 106 | 81% | 59% | 18% | 52% | 8% |
| Nonprofits | 81 | 80% | 46% | 21% | 48% | 7% |
| Engineering | 15 | 80% | 60% | 7% | 47% | 0% |
| Dental practices | 18 | 78% | 44% | 11% | 67% | 17% |
| Law firms | 29 | 72% | 48% | 0% | 31% | 7% |
| Insurance | 24 | 46% | 42% | 0% | 83% | 54% |
What this means for your business
If your domain is in the 84%, a criminal can send an email that looks exactly like it came from you — to your customers, your bookkeeper or your bank — and most receiving mail servers will deliver it. That is how “we changed our bank account, please update the wire details” scams work, and the losses land on the business whose name was used. It also means your own legitimate mail is more likely to be filtered as spam, because Google and Yahoo now expect these records from everyone.
Fix it in an afternoon
- Publish SPFA single DNS record listing who sends for you (for Microsoft 365:
v=spf1 include:spf.protection.outlook.com -all). - Turn on DKIMIn Microsoft 365 or Google Workspace it is a switch plus two DNS records. Every message is then signed.
- Publish DMARC, start at p=noneCollect reports for a couple of weeks so nothing legitimate breaks.
- Move to p=quarantine, then p=rejectNow forged mail is refused. This is the step almost nobody in the 821 finishes.
We do this for clients as a fixed piece of work, and it is included in the Secure Office plan. Check your own domain — the check is free and the report arrives by email.
How did you check 821 businesses?
We started from the Colorado Secretary of State’s public business registry for El Paso and Teller County (8,252 active businesses in good standing), matched businesses to their own websites by name — accepting a domain only when the site showed a local address or phone number and the business’s own name, which gave 1,010 verified domains — and read each domain’s public DNS records: MX (where mail goes), SPF, DMARC and the common DKIM selector names. Nothing was sent to anyone and nothing was probed beyond public DNS, the same records any mail server reads. 189 domains with no mail records were excluded, leaving 821. Businesses with no website, or one under a different name, are not represented.
Why don’t you name the businesses?
Because a list of who can be spoofed is a target list. We tell each business privately. If you want to know where your own domain stands, ask — it is free.
Is “spoofable” the same as “hacked”?
No. None of this requires breaking into anything. It means a forged message in your name is unlikely to be rejected by the receiving mail server. It is a gap in what you have published, not a breach.
How current is this?
Checked 2026-09-28. We refresh this report periodically; if you fix your records, the next run will show it.
Where does your domain stand?
Tell us your business name and we will check it the same way, free, and show you exactly what to change. Check my domain
.snet-table{width:100%;border-collapse:collapse;font-size:.95rem;margin:12px 0 4px;font-variant-numeric:tabular-nums}
.snet-table th,.snet-table td{text-align:left;padding:9px 12px;border-bottom:1px solid #e7dfd2;white-space:nowrap}
.snet-table th{font-size:.78rem;letter-spacing:.04em;text-transform:uppercase;color:#8a7a64;font-weight:600}
.snet-table td:first-child{font-weight:600;color:#2b221a}
.snet-table td:nth-child(3){color:#bf5b37;font-weight:600}
.snet-table td:last-child{color:#4d6b2f;font-weight:600}