Level finding. Across three frames, 44 of 60 independent insurance agencies (73.3%, 95% Wilson CI [61.0, 82.9]) publish no enforcing DMARC policy and can therefore be impersonated by email to their own clients.
We measured the published email-authentication posture of 60 US independent insurance agencies across three frames, using only public DNS and contacting no one. About 3 in 4, 44 of 60 (73.3%, 95% Wilson CI [61.0, 82.9]), publish no enforcing DMARC policy, which means a message that did not originate with the agency can still reach a client's inbox appearing to. We report the level per frame with 95% intervals, alongside SPF publication (93.3%) and DNSSEC signing (5.0%). The corrective step is a single DNS policy change. A pre-registered expectation that affiliated agencies would be better protected did not hold: the three frames were not distinguishable at this sample size.
Insurance agencies hold client PII, carry errors-and-omissions exposure, and depend on clients trusting that an emailed policy document or payment request came from the agency. Email authentication is the public, checkable control that supports that trust. An agency either publishes an enforcing DMARC policy, in which case mailbox providers can reject mail that fails authentication, or it does not, in which case impersonating mail can pass. This study measures which.
Passive public DNS only. No mail was sent and no agency was contacted. For each domain we resolved DMARC at _dmarc (presence, policy, parseability; RFC 7489), SPF (presence, tri-state with indeterminate reads excluded rather than counted absent; RFC 7208), DNSSEC by the DNSKEY-at-apex definition (RFC 4033 et seq.), and MX as a mail-active context check.
Operational definitions. Spoofable: no enforcing DMARC (record absent, p=none, or unparseable). Protected: p=quarantine or p=reject. Strictly protected: p=reject. Shares carry 95% Wilson score intervals. No significance test and no model are used.
Frames, all public and search-compiled. A, agencies presenting Trusted Choice / Big “I” affiliation, multi-metro. B, general independent agencies, multi-metro, no affiliation screen. C, North Carolina independent agencies. Each row is one independently operated agency's own mail domain; carriers, MGAs, wholesalers, rollup and aggregator domains were excluded. Of 62 agencies supplied, 60 were measured; 2 were excluded for having no MX (not mail-active) and are not counted in any denominator.
Across all frames, 44 of 60 agencies (73.3%, 95% CI [61.0, 82.9]) publish no enforcing DMARC policy. Strict protection (p=reject) is present at 8 of 60 (13.3%); any enforcing policy (quarantine or reject) at 16 of 60 (26.7%). SPF is published at 56 of 60 (93.3%). DNSSEC is signed at 3 of 60 (5.0%).
| Frame | N | Spoofable | 95% CI |
|---|---|---|---|
| A affiliated | 33 | 78.8% (26/33) | [62.2, 89.3] |
| B general | 14 | 64.3% (9/14) | [38.8, 83.7] |
| C North Carolina | 13 | 69.2% (9/13) | [42.4, 87.3] |
| Aggregate | 60 | 73.3% (44/60) | [61.0, 82.9] |
The pre-registered directional read was that affiliated agencies (A) would show a lower spoofable share than the general frames. The data run the other way: the affiliated frame is directionally higher (78.8%) than general (64.3%) and North Carolina (69.2%), and all pairwise intervals overlap, so no frame is distinguishable at this sample size. We report the level and make no causal claim; affiliation is shown neither to protect nor to harm.
The central pattern is the gap between publishing a sender record and enforcing it: SPF is nearly universal (93.3%) while any enforcing DMARC policy is the exception (26.7%, and only 13.3% at reject). Agencies broadly declare who may send for them, but most do not tell receiving servers to act when a message fails that check, which is what stops impersonation.
Two layers agreed. A from-scratch classifier over the same findings produced 0 disagreements, and a second resolution pass via reordered resolvers and Quad9 agreed domain-for-domain on all 60.
The frames are search-compiled convenience samples, so results are directional, not definitive, and the frame comparison is underpowered at this N; the publishable result is the aggregate level. Published DNS is a proxy for deployed behavior. DKIM is outside passive scope. Two domains were excluded for having no MX. Per-frame companion measures are included in the released data.
The companion veterinary study (VEI-001) found 83% of practices spoofable. Insurance here is somewhat lower at 73%, with overlapping intervals, so the two are not clearly distinguishable. Both show a clear majority of businesses exposed to impersonation.
Publishing an enforcing DMARC policy is a single DNS change, available in Microsoft 365 and Google Workspace without new software, after a short monitoring period at p=none to confirm legitimate mail aligns. The measurement above is exactly what any client, or any attacker, can read from the outside.