Perspective2026-09-10·9 min read

Nothing Moves in a Quarter

My September posture numbers rose in every cohort. Of the 104 domains measured in both editions, seven changed anything. The rise is not real.

The September capture finished this week, and the first column I looked at was DMARC enforcement. Small business 49% (Red Bridge Cyber SMB Posture Baseline, September 2026). Medium business 79% (Red Bridge Cyber Medium Business Posture Baseline, September 2026). Multinationals 91% (Red Bridge Cyber Multinational Posture Baseline, September 2026). In June those three numbers were 43, 68 and 83. Every cohort up. None down.

The September capture finished this week, and the first column I looked at was DMARC enforcement. Small business 49%. Medium business 79%. Multinationals 91%*. In June those three numbers were 43, 68 and 83. Every cohort up. None down.

I had the good-news paragraph half-written in my head before I stopped. Australian email authentication improved this quarter. It reads beautifully. It is also almost certainly not true, and the reason sits inside my own methodology.

The sample is re-drawn every edition

Each quarter the Posture Research draws a fresh sample from the pool of Australian domains: 150 small businesses, and 75 each of medium business, enterprise and government, education, and the multinationals Australians deal with daily (Red Bridge Cyber Posture Research, September 2026). Fresh is the point. A fixed panel goes stale, drifts away from the population, and slowly turns into a study of 450 specific organisations rather than a read on the country.

The cost of that choice is that most of the domains change between editions. Of the 450 measured in September, 104 were also in the June sample. Twenty-three per cent. In the small-business cohort it is 32 of 150; among the multinationals, 14 of 75.

So when the small-business DMARC figure moves from 43% to 49%, roughly four fifths of the organisations behind the second number were not behind the first. That is not a quarter of progress. That is a different set of businesses.

What the same domains actually did

The interesting question is what happened on the 104 domains I measured twice. Same domain, same checks, twelve weeks apart. Each of the four controls below could be read on 102 of them; on the other two, the June scan returned no per-check verdicts to compare against. Here is every change:

Control Gained Lost Unchanged Read on
DMARC enforcement 4 0 98 102
DNSSEC 1 0 101 102
SPF 1 0 101 102
MTA-STS 0 0 102 102

Four domains moved DMARC to an enforcing policy. One turned on DNSSEC. One added an SPF record. Not one of the 102 changed anything about MTA-STS. Spread across the cohorts it is one DMARC change among the small businesses, one among medium business, one in education, one multinational, and one DNSSEC signing in enterprise and government - and the SPF gain is a sixth domain again, in medium business.

Six of the 104 changed one of those four controls. Widen it to every email-authentication check I capture - adding DKIM, TLS-RPT and reverse DNS - and it is seven. Ninety-seven domains changed nothing at all.

The other half of that result matters as much and gets quoted less. Nothing regressed. Zero losses, on every control, in every cohort. Nobody unsigned a zone, dropped an SPF record or walked DMARC back to p=none. Posture is sticky in both directions: hard to improve, and once it is in place, it stays.

So the cohort-level movement I nearly wrote up as national improvement is resample variation. The most likely explanation is that my September sample happened to contain slightly better-configured domains than my June one. I cannot prove that from the paired set alone - it covers 104 domains, and says nothing directly about the other 346 - but a national shift that somehow skipped 97 of the 104 organisations I watched throughout is not the way to bet. The same caution applies to the visibility numbers in the small-business cohort, where llms.txt files read 19% in June and 27% in September*. Same artefact. I am not going to present it as growth.

An independent programme hit the same wall

I would rather this were a quirk of my sampling than a real property of the field, so I went looking for someone doing the same measurement properly.

The Dutch government runs a half-yearly measurement of information-security standards across its own domains. In the edition published in May 2026, covering the position at 31 December 2025, the programme reported that its results were not comparable between periods because the set of domains being measured had grown. Their fix was to report a separate comparison over only the domains present in both measurements. They also found that newly-added domains score worse than the ones already being tracked.

An independent national measurement programme, run by a government with a mandate rather than by me with a sampler, ran into the identical problem and solved it the identical way. That is about as good a corroboration as this kind of methodological point ever gets.

Their headline is worth reading carefully, though. Dutch government domains reach 86% DMARC at quarantine or reject. That is far above anything in my data, and the denominators are not the same thing: a curated list of mandated government domains is not a random sample of the web, and it should not be compared to one.

For a population closer to the open web, Berezin, writing on RIPE Labs and using OpenINTEL data, took a snapshot of the Tranco top one million on 18 July 2026. He found 458,467 domains publishing a DMARC record, of which only 46.9% enforce anything at all. Over the preceding 30 days that enforced share fell by 0.44 percentage points. The single most common DMARC record in the entire dataset, published by 58,064 domains, is v=DMARC1; p=none;.

A plateau at roughly the halfway mark, drifting very slightly backwards. Not a quarter of improvement anywhere.

Why nothing moves

Thirty years of putting infrastructure into stadiums, airports, mine sites and data centres has taught me that the controls which get finished are the ones with an owner and a deadline. DMARC has an owner problem, and the deadline it did get asked for the wrong thing.

The Australian Signals Directorate is clear about the destination. Its guidance on combating fake emails says to "implement DMARC immediately, even if only in a monitoring mode ('p=none') configuration", and describes the target state as a record that "either quarantines or rejects 100 percent of email that fails SPF and DKIM checks". It then says, plainly: "Following testing using a quarantine policy, implement a reject policy." Monitoring is a waypoint in that document, not an outcome.

Then look at what actually created the wave of DMARC records. From 1 February 2024, Google has required bulk senders, anyone sending 5,000 or more messages a day to Gmail addresses, to publish a DMARC record. The sender guidelines state that the enforcement policy "can be set to none". The commercial rule that drove mass adoption asked for a record, and explicitly did not ask anyone to enforce it. Millions of organisations complied exactly, and stopped.

That is the whole shape of the plateau. Publishing clears the gate. Enforcing takes an audit of every system that sends mail in your name, which nobody schedules.

The other controls are quieter versions of the same story. Ashiq, Fiebig and Chung, in their paper at ACM IMC 2025, found MTA-STS published by 0.07% of .com domains with mail servers, 0.09% of .net and 0.13% of .org, and 29.6% of the 68,030 domains that did publish one were misconfigured. DNSSEC validation and secure delegation rates reached 36% and 7% in 2025, and the APNIC Blog describes adoption as "still low after 20 years". My zero-change row for MTA-STS is not an anomaly. It is what a control with almost no deployment base looks like over twelve weeks.

One more thing worth saying out loud. I cannot cite you an Australian DMARC or DNSSEC adoption rate from an authoritative source, because there isn't one. auDA's flagship security report, "A secure .au", published May 2025 on 2024 data, contains no second-level DNSSEC signing rate, no DMARC data and no email-security data at all. It mentions DNSSEC once, to note that the .au zone itself is signed. That gap is a large part of why I run this research.

What you do with this

If you run a small business, the honest read is not "the country is improving". It is closer to "almost nobody moves, and nobody moves backwards".

Which is useful, because it means a change you make holds. That is not true of most security work. Patching is a treadmill, staff training decays, phishing filters get worked around. Moving DMARC to p=quarantine on your own domain is a one-afternoon change that was still in place twelve weeks later on every domain in my paired set that had it.

It also means the bar sits lower than you would assume. Just over half of the Australian small-business domains I measured in September do not enforce DMARC at all, and among medium businesses it is about one in five. Most published the record and stopped at the easy half, as I described last quarter.

Check your own domain, and check the policy value rather than whether a record exists. If it says p=none, you have the smoke alarm installed with the battery out.

I will run this again in December, on another re-drawn sample, and publish the paired comparison alongside it whether it flatters the numbers or not. I would rather report four changes honestly than six points of movement that were never there.

The question I keep turning over is a simpler one. If a control this cheap, this durable, and this clearly recommended by our own national authority still sits unfinished on half the country's small-business domains, what exactly is stopping people? I genuinely do not know, and I would like to.


Sources

#perspective#australian-business#small-business