domains are spoofable — they either publish no DMARC record at all, or publish one set to p=none, which asks receiving mail servers to take no action. An attacker can send invoice-redirect or wire-fraud email that passes as coming from these companies.
Sender authentication is three linked public records. SPF lists who may send for a domain. DKIM signs outbound mail cryptographically. DMARC tells receiving servers what to do when the first two fail — and is the only one of the three that can actually reject a forgery.
All three are published in DNS, which means anyone can read them, including whoever is deciding whether your accounts-payable department is worth targeting. That is why we can measure this from outside, and why attackers can too.
Ag-tech is markedly worse than the processors
Splitting the sample by its two source lists produces the sharpest finding in the data. Established food processors are far from uniformly protected, but the venture-backed ag-tech cohort — the companies most likely to be handling customer data and selling into enterprise supply chains — is substantially more exposed.
Food processors
Ag-tech companies
Only 5.0% of the ag-tech cohort enforces a DMARC reject policy, against 32.3% of processors. 45.0% of ag-tech domains publish no DMARC record whatsoever, and 30.0% publish neither DMARC nor SPF — no sender authentication of any kind.
Where the sample sits
DMARC has four practical states. Only the last two do anything to a forged message.
The full sample
Every domain measured, one square each, coloured by the strongest policy it publishes. Companies are not identified — see the disclosure note below.
Food processors
Ag-tech
Why we don’t name the companies. Every record in this study is world-readable and takes seconds to query — nothing here is a secret. But publishing a list of named organisations alongside the specific gap in their defences serves attackers more efficiently than it serves defenders, and we are not willing to make that trade for a marketing asset. This follows the same disclosure rule we apply to client work.
If you are responsible for one of these domains and want to know whether you are in the sample and what we found, ask us. We will tell you, at no cost and with no obligation.
Who runs the mail
Provider mix matters because the remediation differs by platform — and because every major host on this list supports DMARC enforcement at no additional cost. Nothing here is a licensing problem.
What this costs, concretely
The attack this enables is neither theoretical nor sophisticated. It is business email compromise: an attacker sends a grower, a broker, or a co-packer an email that genuinely appears to come from a company they already do business with, attaching a real-looking invoice with changed bank details. Agriculture is a high-value target because payments are large, seasonal, and time-pressured — a redirected payment on a harvest contract clears long before anyone reconciles.
A domain at p=reject makes that message fail authentication at the recipient’s mail server, before a human ever evaluates it. A domain with no DMARC record gives the recipient nothing to check against.
The remediation sequence
- Publish DMARC at
p=nonewith arua=reporting address. Changes nothing about delivery; starts producing data on who sends as you. - Read the reports for 30–60 days. This is where you find the marketing platform, the ERP, and the freight broker that all send on your behalf.
- Authorise those senders in SPF and DKIM, then move to
p=quarantine, thenp=reject.
21 domains in this sample already enforce quarantine or reject. Of those, 4 publish no rua= reporting address — enforcing a policy while collecting no data on what it blocks, so a legitimate sender failing authentication would go unnoticed.
Methodology
Sample
51 domains drawn from two public California industry lists: a food-processor trade association membership roster (31 domains) and the portfolio of a Central Valley agricultural technology incubator (20 domains). This is a convenience sample of two membership lists, not a random sample of California agriculture.
Collection
Public DNS record lookups only — TXT records at the domain apex and at _dmarc. and <selector>._domainkey., plus MX. No connection was made to any company’s mail servers, web servers, or other infrastructure. Every record cited is world-readable by design and returns the same answer to any resolver on the internet. No system was accessed, scanned, or tested.
Verification
Each lookup was issued against two independent resolvers with three retries and exponential backoff. A record is reported missing only when both resolvers returned a definitive negative answer; a lookup that failed to resolve cleanly was flagged as an error and excluded rather than counted as missing. The final run completed with zero unresolved lookups.
Each domain was additionally probed with a randomly generated nonexistent DKIM selector. Domains whose DNS answers any subdomain cannot have DKIM presence inferred and are marked untestable rather than counted as absent.
Limitations
DKIM absence is not proven. DKIM selectors are arbitrary strings and cannot be enumerated from DNS. We tested 13 selectors common to major mail platforms. A domain recorded as having no DKIM may use a custom selector we did not guess.
Geography is inferred, not verified. Both source lists are California organisations whose membership skews heavily to the Central Valley, but we did not independently verify the headquarters county of each company. This describes California food processing and ag-tech; it is not a certified Central Valley census.
Some domains do not carry mail. 13 domains publish no MX record, meaning they are brand or redirect domains and corporate mail runs elsewhere. Absent DMARC on a non-mail domain is a weaker finding, though such domains remain usable for outbound forgery. Restricting the analysis to the 38 domains that do receive mail yields a spoofable rate of 55.3% — the conservative figure, and the one to cite if only one number is quoted.
Point-in-time. All records were resolved on 9 August 2026. DNS changes; some of these domains may have been remediated since.
Check your own domain. Everything in this study is measurable from outside with no access to your systems. If you want to know where your organisation sits, get in touch and we will run it and send you the result.