News
Seven in ten Dutch accounting firms do not ask receivers to stop fake mail
A count of every active NOAB office from 1 to 7 October 2026 shows that 68.6% of their domains have no DMARC policy that blocks or quarantines fake mail. SPF, the record that names senders, is published at most offices.
NOAB, the Dutch association of administration and tax advisory firms, speaks of about 1,100 members. The public office directory listed 919 active offices in that period. After setting aside offices without an own website domain, 854 domains remain. NovaMX counted those domains itself, not on a commission from the association, and without naming offices. The full report, with method, tables and charts, is in the links above.
What the figures do and do not say
DMARC is the rule that tells a receiving mail server what to do when someone sends mail that claims to come from the office but fails the sender check. p=none asks the receiver to deliver the message anyway. p=quarantine asks the receiver to treat it as suspicious. p=reject asks the receiver to refuse it. If the rule is missing, the receiver decides.
On 216 domains (25.3%) the rule is missing. On 369 (43.2%) the rule is p=none: deliver, do not intervene. Together that is 586 domains, 68.6%, once the single invalid record is included. Enforcing policy, quarantine or reject, is on 268 domains (31.4%).
- No record 25.3%
- p=none 43.2%
- quarantine 17.4%
- reject 13.9%
"Vulnerable" is too coarse a word here. An office with SPF and a none policy has published a sender list. It simply does not ask others to stop a message that misses that list. For invoice fraud, that is the distinction that matters: the receiver has no instruction from the domain to be suspicious.
A none policy that measures nothing
Of the 369 domains with p=none, 65.0% also request no aggregate report and no failure report. The record exists, and nothing comes back. Under quarantine, 48.3% request an aggregate report. Under reject, that share is 33.6%. Failure reports (ruf) appear in the whole count only together with an aggregate address.
An office that has already set reject and publishes no report address asks the outside world to refuse, and does not see which streams keep failing. An office on none without an address is not measuring either.
SPF is the smaller story
SPF is the list of systems allowed to send mail for the domain. -all excludes everyone not on that list. ~all marks them as suspicious, but many receivers still deliver the message. 62.4% of domains close SPF with -all. 32.8% use ~all. Only 24 domains have no SPF. Three domains publish two SPF records, which makes the check invalid before the contents are read.
A separate question is whether the SPF record is too deep to be read reliably. Receivers may stop at 10 DNS lookups in the include chain. Of the 827 domains with one record, 61 (7.4%) are at or above that line. Another 91 are at 8 or 9, close enough that an extra sending service can break the record. The median is 4 lookups. Flattening is required for a minority, not for the profession as a whole.
The country looks more alike than the headlines suggest
By province, counted per office, the picture stays in the same band. Among provinces with at least fifty offices, Overijssel has the lowest share of p=reject (5.9%) and at the same time the highest DNSSEC delegation (72.5%). Utrecht is higher on reject (19.2%). Small provinces, Flevoland first with 15 offices, do not belong on a league table.
Nationally, 57.8% have a DS record, the sign that DNSSEC is switched on at the parent. 94.3% of websites had a valid certificate. HSTS, the header that binds browsers to HTTPS, was present on 26.3% of those valid sites. MTA-STS, for encrypted delivery to the domain, was present on 3 domains.
What an office risks
Without DMARC, or with p=none, the domain does not ask receivers to stop a message that fails the sender check. An invoice or payment request that looks like the office can then land in the inbox. Without rua, the office does not see that happening either. An SPF list on ~all, or two SPF records, does not give that receiver a strict boundary. A list on -all does, but without quarantine or reject the receiver may still deliver a failing message.
Too many SPF lookups are a different risk. At 10 or more, a receiver may treat the check as failed, including for real mail from the office. An invalid website certificate, or the absence of HSTS, affects the site, not that invoice mail. Missing MTA-STS is about encryption of mail coming in, and it was almost absent in this count.
What an office can do with this
The count names no offices. Anyone who wants to know how their own domain stands can look it up. The practical order that follows from the figures is plain: one SPF record, a DMARC record that requests reports while mail streams are not yet fully known, and only then quarantine or reject. If the lookup count is 8 or higher, shortening or flattening that chain belongs in the same round, not as a substitute for the policy.
DKIM was not part of this count. An office can have sound signatures and still publish a none policy. A valid padlock on the website says nothing about invoice mail.
Read the research report Download the report (PDF) Check your own domain