Colorado Springs Email Security Report 2026

Original research · Colorado Springs · 2026

84% of the Colorado Springs business email domains we checked can be impersonated.

We checked the public email-security records of 821 business email domains in El Paso and Teller County. 84% have nothing in place that tells the world’s mail servers to reject a message forged in their name — the exact gap behind fake-invoice and payroll-change scams. No business is named here; this is what the whole community looks like.

The numbers

What 821 local business domains look like from the outside

All of this is public DNS — the same records every mail server in the world reads before deciding whether to trust a message from your domain.

84% spoofable

No DMARC policy, or one set to “monitor only” (p=none). Mail servers are told nothing about rejecting forgeries.

60% have no DMARC at all

DMARC is the record that lets you tell Gmail, Outlook and everyone else to reject mail that pretends to be you. Most local businesses never published one.

17% have no SPF

SPF lists which servers may send for your domain. Without it, anyone can.

4% have a weak SPF

Published, but ending in a rule that means “allow everything anyway”.

58% show no DKIM signing

No cryptographic signature on outgoing mail at any of the common selector names we checked, which hurts deliverability and makes spoofing easier.

6% are fully protected

DMARC set to reject, with SPF and DKIM in place. This is the standard your bank, your insurer and Google now expect.

By email provider

Where a business hosts its email changes the picture more than anything else. Microsoft 365 and Google Workspace make DKIM and DMARC a few clicks — but they are not on by default, and it shows.

Domains Spoofable No DMARC No SPF No DKIM found Fully protected
Other/self-hosted 281 81% 58% 11% 50% 11%
Google Workspace 237 91% 65% 29% 62% 3%
Microsoft 365 207 83% 60% 1% 55% 2%
GoDaddy 34 94% 88% 88% 97% 0%
IONOS 24 100% 21% 8% 96% 0%
Email security gateway 18 44% 17% 0% 33% 33%

By industry

Ranked by share of spoofable domains. Industries with fewer than 15 checked domains are left out rather than over-read.

Domains Spoofable No DMARC No SPF No DKIM found Fully protected
CPAs and tax 17 94% 47% 6% 59% 0%
Property management 80 92% 61% 20% 65% 0%
Manufacturing 21 90% 57% 19% 48% 5%
Behavioral health 44 89% 70% 20% 50% 7%
Medical practices 67 88% 58% 21% 64% 6%
Construction and trades 235 88% 65% 16% 60% 3%
Hospitality 38 87% 66% 24% 74% 8%
Auto sales and repair 27 85% 67% 22% 59% 0%
Technology and IT 106 81% 59% 18% 52% 8%
Nonprofits 81 80% 46% 21% 48% 7%
Engineering 15 80% 60% 7% 47% 0%
Dental practices 18 78% 44% 11% 67% 17%
Law firms 29 72% 48% 0% 31% 7%
Insurance 24 46% 42% 0% 83% 54%

What this means for your business

If your domain is in the 84%, a criminal can send an email that looks exactly like it came from you — to your customers, your bookkeeper or your bank — and most receiving mail servers will deliver it. That is how “we changed our bank account, please update the wire details” scams work, and the losses land on the business whose name was used. It also means your own legitimate mail is more likely to be filtered as spam, because Google and Yahoo now expect these records from everyone.

Fix it in an afternoon

  1. Publish SPFA single DNS record listing who sends for you (for Microsoft 365: v=spf1 include:spf.protection.outlook.com -all).
  2. Turn on DKIMIn Microsoft 365 or Google Workspace it is a switch plus two DNS records. Every message is then signed.
  3. Publish DMARC, start at p=noneCollect reports for a couple of weeks so nothing legitimate breaks.
  4. Move to p=quarantine, then p=rejectNow forged mail is refused. This is the step almost nobody in the 821 finishes.

We do this for clients as a fixed piece of work, and it is included in the Secure Office plan. Check your own domain — the check is free and the report arrives by email.

How did you check 821 businesses?

We started from the Colorado Secretary of State’s public business registry for El Paso and Teller County (8,252 active businesses in good standing), matched businesses to their own websites by name — accepting a domain only when the site showed a local address or phone number and the business’s own name, which gave 1,010 verified domains — and read each domain’s public DNS records: MX (where mail goes), SPF, DMARC and the common DKIM selector names. Nothing was sent to anyone and nothing was probed beyond public DNS, the same records any mail server reads. 189 domains with no mail records were excluded, leaving 821. Businesses with no website, or one under a different name, are not represented.

Why don’t you name the businesses?

Because a list of who can be spoofed is a target list. We tell each business privately. If you want to know where your own domain stands, ask — it is free.

Is “spoofable” the same as “hacked”?

No. None of this requires breaking into anything. It means a forged message in your name is unlikely to be rejected by the receiving mail server. It is a gap in what you have published, not a breach.

How current is this?

Checked 2026-09-28. We refresh this report periodically; if you fix your records, the next run will show it.

Where does your domain stand?

Tell us your business name and we will check it the same way, free, and show you exactly what to change. Check my domain

.snet-table{width:100%;border-collapse:collapse;font-size:.95rem;margin:12px 0 4px;font-variant-numeric:tabular-nums}
.snet-table th,.snet-table td{text-align:left;padding:9px 12px;border-bottom:1px solid #e7dfd2;white-space:nowrap}
.snet-table th{font-size:.78rem;letter-spacing:.04em;text-transform:uppercase;color:#8a7a64;font-weight:600}
.snet-table td:first-child{font-weight:600;color:#2b221a}
.snet-table td:nth-child(3){color:#bf5b37;font-weight:600}
.snet-table td:last-child{color:#4d6b2f;font-weight:600}