Red Rook

Research

What we found when we went looking.

We publish what we measure. Every study here is built from data anyone can collect without touching a single system, anonymised before it goes out, and shipped with the method and its limits stated in full — including the parts that weaken the conclusion.

Report 01 · 9 August 2026

Sender Authentication in California Agriculture

We measured the public SPF, DKIM and DMARC records of 51 California food processors and agricultural technology companies. Nearly three in five publish no enforceable policy against someone sending email in their name — and the venture-backed ag-tech cohort is markedly worse than the established processors.

Read the report →

How we work

Public data only. Every study on this page is built from records that are world-readable by design — DNS, certificate transparency logs, published disclosures. No system is accessed, scanned, or tested. Where we assess a client’s infrastructure directly, that is an engagement under contract, and it does not become research.

Anonymised before publication. Names, sector detail, and anything reconstructible come out first. Publishing a list of named organisations next to the specific gap in their defences serves attackers more efficiently than defenders, and we will not make that trade for a marketing asset.

Limitations stated, not buried. Each report carries a section describing what the method cannot show and where the sample is weak. If a finding is softer than the headline suggests, the report says so.

Point-in-time, and dated. Infrastructure changes. Every figure carries the date it was measured.

If you want to know where your own organisation sits on any of this, ask us. We will run it and send you the result.