Vigil Research Library · Series 1 · VEI-002 Vigil Exposure Index

Insurance Agency Email Spoofability Across Agency Frames

Bridgham Technology Institute, Bridgham Cyber, LLC · 2026
Reissued September 2026 under the Bridgham name.

Level finding. Across three frames, 44 of 60 independent insurance agencies (73.3%, 95% Wilson CI [61.0, 82.9]) publish no enforcing DMARC policy and can therefore be impersonated by email to their own clients.

Abstract

We measured the published email-authentication posture of 60 US independent insurance agencies across three frames, using only public DNS and contacting no one. About 3 in 4, 44 of 60 (73.3%, 95% Wilson CI [61.0, 82.9]), publish no enforcing DMARC policy, which means a message that did not originate with the agency can still reach a client's inbox appearing to. We report the level per frame with 95% intervals, alongside SPF publication (93.3%) and DNSSEC signing (5.0%). The corrective step is a single DNS policy change. A pre-registered expectation that affiliated agencies would be better protected did not hold: the three frames were not distinguishable at this sample size.

1. Why Insurance

Insurance agencies hold client PII, carry errors-and-omissions exposure, and depend on clients trusting that an emailed policy document or payment request came from the agency. Email authentication is the public, checkable control that supports that trust. An agency either publishes an enforcing DMARC policy, in which case mailbox providers can reject mail that fails authentication, or it does not, in which case impersonating mail can pass. This study measures which.

2. Method

Passive public DNS only. No mail was sent and no agency was contacted. For each domain we resolved DMARC at _dmarc (presence, policy, parseability; RFC 7489), SPF (presence, tri-state with indeterminate reads excluded rather than counted absent; RFC 7208), DNSSEC by the DNSKEY-at-apex definition (RFC 4033 et seq.), and MX as a mail-active context check.

Operational definitions. Spoofable: no enforcing DMARC (record absent, p=none, or unparseable). Protected: p=quarantine or p=reject. Strictly protected: p=reject. Shares carry 95% Wilson score intervals. No significance test and no model are used.

Frames, all public and search-compiled. A, agencies presenting Trusted Choice / Big “I” affiliation, multi-metro. B, general independent agencies, multi-metro, no affiliation screen. C, North Carolina independent agencies. Each row is one independently operated agency's own mail domain; carriers, MGAs, wholesalers, rollup and aggregator domains were excluded. Of 62 agencies supplied, 60 were measured; 2 were excluded for having no MX (not mail-active) and are not counted in any denominator.

3. Results

Across all frames, 44 of 60 agencies (73.3%, 95% CI [61.0, 82.9]) publish no enforcing DMARC policy. Strict protection (p=reject) is present at 8 of 60 (13.3%); any enforcing policy (quarantine or reject) at 16 of 60 (26.7%). SPF is published at 56 of 60 (93.3%). DNSSEC is signed at 3 of 60 (5.0%).

A · 26/33 78.8% B · 9/14 64.3% C · 9/13 69.2% Aggregate · 44/60 73.3% 0% 50% 100%
Figure 1. Spoofable share by frame and aggregate, with 95 percent Wilson intervals. Bars are the point estimate; whiskers the interval (A 62.2–89.3, B 38.8–83.7, C 42.4–87.3, aggregate 61.0–82.9). Denominators are labeled at left. Every pairwise interval overlaps, so the frames are not distinguishable at this sample size.
FrameNSpoofable95% CI
A affiliated3378.8% (26/33)[62.2, 89.3]
B general1464.3% (9/14)[38.8, 83.7]
C North Carolina1369.2% (9/13)[42.4, 87.3]
Aggregate6073.3% (44/60)[61.0, 82.9]

The pre-registered directional read was that affiliated agencies (A) would show a lower spoofable share than the general frames. The data run the other way: the affiliated frame is directionally higher (78.8%) than general (64.3%) and North Carolina (69.2%), and all pairwise intervals overlap, so no frame is distinguishable at this sample size. We report the level and make no causal claim; affiliation is shown neither to protect nor to harm.

The central pattern is the gap between publishing a sender record and enforcing it: SPF is nearly universal (93.3%) while any enforcing DMARC policy is the exception (26.7%, and only 13.3% at reject). Agencies broadly declare who may send for them, but most do not tell receiving servers to act when a message fails that check, which is what stops impersonation.

enforcing (p=quarantine) p=reject declare · 56/60 SPF 93.3% enforce · 16/60 26.7% any · 13.3% reject 0% 50% 100%
Figure 2. Declare versus enforce. SPF published (declare) at 93.3% (56/60) against any enforcing DMARC policy (enforce) at 26.7% (16/60), of which p=reject is 13.3% (8/60), shown as the darker segment. Agencies declare who may send for them far more often than they instruct receivers to act on failures.

3.1 Independent Reproduction

Two layers agreed. A from-scratch classifier over the same findings produced 0 disagreements, and a second resolution pass via reordered resolvers and Quad9 agreed domain-for-domain on all 60.

4. Limitations

The frames are search-compiled convenience samples, so results are directional, not definitive, and the frame comparison is underpowered at this N; the publishable result is the aggregate level. Published DNS is a proxy for deployed behavior. DKIM is outside passive scope. Two domains were excluded for having no MX. Per-frame companion measures are included in the released data.

5. Context

The companion veterinary study (VEI-001) found 83% of practices spoofable. Insurance here is somewhat lower at 73%, with overlapping intervals, so the two are not clearly distinguishable. Both show a clear majority of businesses exposed to impersonation.

6. What an Agency Does About It

Publishing an enforcing DMARC policy is a single DNS change, available in Microsoft 365 and Google Workspace without new software, after a short monitoring period at p=none to confirm legitimate mail aligns. The measurement above is exactly what any client, or any attacker, can read from the outside.

References

  1. Kucherawy, M. and Zwicky, E. Domain-based Message Authentication, Reporting, and Conformance (DMARC). RFC 7489, IETF, 2015.
  2. Kitterman, S. Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1. RFC 7208, IETF, 2014.
  3. Arends, R. et al. DNS Security Introduction and Requirements. RFC 4033, IETF, 2005. (With RFC 4034 and RFC 4035.)
Bridgham Technology Institute, Bridgham Cyber, LLC · VEI-002 · passive · aggregate · transparent · method and aggregate data open; no per-agency result published