State of Email Security in Polk County 2026: 63% of Businesses Can Be Impersonated
How many Polk County businesses can be impersonated by email?
About two in three. To measure email security in Polk County, in October 2026 we checked the public email records of 1,101 Polk County businesses listed in the Lakeland and Winter Haven chamber directories. 63% have no DMARC policy that tells receiving mail servers to block forged email, which means a criminal can send messages that appear to come from their exact address, and many of those messages will be delivered.
That matters because forged email is how most invoice and payment fraud starts. A customer receives an email that looks like it came from a business they trust, with new bank details for the next payment. The FBI’s Internet Crime Complaint Center consistently ranks business email compromise among the costliest crimes it tracks. The records that stop the forged part of it are free, and most businesses have never set them up.
What did the Polk County email security check find?
| Finding | Share of businesses |
|---|---|
| Can be impersonated (no enforcing DMARC policy) | 63% |
| No DMARC record at all | 31% |
DMARC set to “monitor only” (p=none), which still lets forged email through | 31% |
Protected: forged email sent to spam (p=quarantine) | 20% |
Protected: forged email rejected (p=reject) | 17% |
| No SPF record (the basic list of servers allowed to send their email) | 8% |
| No DKIM email signing found | 43% |
The “monitor only” group is worth a second look. These businesses started the job, published a DMARC record, and never finished it. A p=none policy collects reports but tells receiving servers to deliver forged email anyway. It is the right first step and the wrong place to stop.
Which industries in Polk County are most exposed?
Share of business domains in each group that can be impersonated by email:
Groups are based on chamber directory categories; a business can appear in more than one. Real estate & property: 76 domains. Legal: 42. Nonprofits & churches: 118. Construction & trades: 123. Medical, dental & health: 150. Banks, insurance & financial: 99.
Real estate is the most exposed group, at 74%, and it is also where forged email does the most damage: fake wiring instructions sent during a closing are a well-known fraud pattern. Medical and dental offices, at 61%, handle patient data and insurance payments and are frequent phishing targets. The financial group scores best, largely because banks and credit unions are regulated and usually have enforcement in place; the small firms around them are not always so well covered.
Does it depend on the email provider?
Yes, a lot. Of the businesses whose email runs on Microsoft 365, 48% can be impersonated. On Google Workspace it is 84%. On other providers, 65%. Neither platform publishes DMARC for a custom domain automatically, even though Google and Yahoo now require it from bulk senders; it has to be set up in the domain’s DNS by whoever manages it. Either platform can be fully protected; see our Microsoft 365 vs Google Workspace comparison for practices.
What should a business do about it?
- Check your own domain. Our free email spoofing check reads the same public records used in this report and tells you in seconds whether your business can be impersonated, and what to fix.
- Find everything that sends email as you, including invoicing and accounting software, website forms, newsletters and copier scan-to-email, and make sure your SPF record covers them.
- Turn on DKIM signing in Microsoft 365, Google Workspace or your provider.
- Publish DMARC at
p=nonewith reporting, read the reports for a few weeks, then move toquarantineand finallyreject. Doing it in that order is what keeps your own legitimate email out of customers’ spam folders. - Add a call-back rule: any change to payment details is confirmed by phone, on a number you already had. DMARC stops forged mail from your domain; it does not stop look-alike domains.
For the wider picture, see our pages on cybersecurity in Lakeland and cybersecurity in Winter Haven, where freight and invoice fraud through hijacked email is a growing problem for logistics firms.
How was this report put together?
- Sample: business website domains listed in the public online member directories of the Lakeland Chamber of Commerce and the Greater Winter Haven Chamber of Commerce, collected in October 2026. Large national companies and directory links that were not member businesses were removed. 1,243 domains were checked; the 1,101 that receive email are the basis of every percentage.
- What was checked: each domain’s public DNS records (MX, SPF, DKIM and DMARC), read through public resolvers on October 8–9, 2026. These are the same records every mail server reads when it receives a message. No business’s systems were accessed or tested.
- “Can be impersonated” means the domain has no DMARC record, or one with a policy of
none. A domain withquarantineorrejectcounts as protected. - Limits: chamber members tend to be established businesses, so the wider picture may be worse. DKIM was checked under the most common record names, so a small number of businesses using unusual names may be counted as missing DKIM when they have it. Industry groups are based on directory categories and overlap.
- Privacy: results are published in aggregate only. We do not name, list or contact any business based on this data.
We plan to repeat the check each quarter and report how the numbers change. Journalists and chambers are welcome to cite the figures with a link to this page.
Want Help Closing the Gap?
iTech Plus provides cybersecurity, email security and managed IT for businesses across Polk County, from our office in Haines City. Setting up SPF, DKIM and DMARC properly is usually an hour or two of work, followed by a few weeks of watching the reports. If you would like it done for you, or a broader look at your systems, we offer a free IT assessment with a written report. Call (321) 221-7117 or email info@itechplus.co.







