SMX Email Security Report 2026
Five Eyes Benchmarking shows NZ punching well above its weight
For five years, SMX has tracked email protocol adoption across Australasia. This year the scope was expanded to evaluate nearly 2,000 central government mail domains across all Five Eyes nations: New Zealand, Australia, the United Kingdom, Canada, and the United States.
That broadened scope uncovered hidden security gaps, from unmonitored reporting loops to exposed peripheral domains. It also highlights the progress New Zealand has made just in the last year.

Key findings
Protecting email requires an end-to-end approach – attackers are constantly searching for gaps. And as our 2026 findings reveal, that’s exactly what they’ll find across both commercial sectors and global government allies.
DMARC stragglers under increasing threat
The good news is that overall DMARC deployment across Five Eyes governments has reached 85–97%. But as agencies move to active enforcement, attackers shift focus to the remaining gaps. Any stragglers will be left behind in an ever-shrinking pond of attack targets.
Percent of central government domains actively enforcing DMARC (p=quarantine or p=reject)
90.3% Australia
84.5% UK
83.3% USA
66.7% NZ
20.5% Canada
Security by halves
Securing modern email needs a two-pronged approach: protect against domain forgery (spoofing) and stop emails from being intercepted while in transit. DMARC does the first by controlling who can send as your domain. MTA-STS does the second by encrypting emails in transit.
While allies like the US and Australia have locked down the sending side, New Zealand is the only Five Eyes nation that is also making progress on transport security. Those weak links call into question the strength of those security chains.
Percent of central government domains deploying inbound MTA-STS transport encryption:
72.5% NZ
54.6% UK
25.7% Australia
1.3% USA
0% Canada
Explore the Five Eyes data – See the dedicated dashboard
Compliant, but not protected
Deploying DMARC is an email security home run, but only if you actively enforce it and monitor feedback. The report exposes widespread "security theatre", where organisations are publishing DNS records, while leaving their domains wide open.
75% Canada gc.ca domains DMARC unenforced
37.7% Australia reports sent to unmonitored mailboxes
134 USA domains completely unprotected
Corporates continue to lag
While DMARC deployment figures look healthy for the top-100 listed corporates in Australasia, when it comes to actual protection, they’re lagging behind government agencies.
Percent of all domains actively enforcing DMARC:
88.9% Australian Federal Government
68.4% New Zealand Government
64.6% NZX-listed Companies
44.9% ASX-listed Companies