Cyber Security
Scottish Charity Email Report 2026: Is Your Email Going Into Spam?
Written by Efem Toptas, Founder & Managing DirectorUpdated 25 September 2026
Of 9,471 Scottish charities that run email on their own domain, 84% have no enforcing DMARC policy and, by our estimate, more than half have no DKIM signature. Those two records now decide whether Google, Microsoft and Yahoo deliver a charity's own newsletters and appeals to the inbox or to spam, and whether an email sent by a stranger using the charity's address is refused. The fix is free and takes an afternoon.
We took the public list of every registered Scottish charity, found the 9,471 that run email on their own domain, and checked each one for the three records that decide two things: whether the charity's own emails reach the inbox, and whether a fake email using its address gets refused. They are called SPF, DKIM and DMARC, and they are explained below. The result: 84% have no enforcing DMARC policy, so a fake email using their address is not rejected on their instruction and, at most receivers, lands in the inbox. Nearly half have no DMARC record at all, and we estimate that only around 12% are fully protected.
Measured or estimated? The SPF and DMARC figures in this report are direct observations of public DNS records, and a sample was re-checked against a second, independent resolver with 100% agreement. The DKIM figure and anything built on it, including "fully protected", is an estimate and a floor: we can only detect DKIM keys published on common selector names, so some charities using custom selectors will be counted as unprotected when they are not. Email provider is inferred from MX records. Income and staff numbers are as each charity reported to OSCR. Estimates are marked as such throughout.
This cuts both ways. Since February 2024, Google and Yahoo have required SPF, DKIM and DMARC from anyone sending email in volume, and Microsoft applied the same rules to Outlook.com and Hotmail addresses in May 2025. A charity without them sends its newsletter or appeal and a growing share of it is filtered into spam, or refused outright, with no bounce to tell anyone. At the same time, the missing records mean an invoice with changed bank details, a fake donation appeal or a message from "the chief executive" can be sent in the charity's name and delivered. The records that fix both are free, take an afternoon, and most charities have not set them.
The three records, in plain English
Email was designed in the 1980s with no way to prove who sent a message. Anyone can type your charity's address into the From field, and the receiving server has to decide whether to believe it. Three DNS records, each a line of text published against your domain, give it something to check. Nobody needs to install anything; the records live with whoever manages your website domain.
- SPF (Sender Policy Framework) is a published list of the mail servers allowed to send email for your domain: your email provider, your newsletter tool, your accounts system. A receiving server compares the sender against the list. The record ends with an instruction for anyone not on it: -all means reject them, ~all means "treat with suspicion", which in practice means deliver anyway. The bouncer's guest list, and whether the bouncer is allowed to turn people away.
- DKIM (DomainKeys Identified Mail) adds an invisible cryptographic signature to every email you send. The receiving server checks the signature against a public key you publish in DNS. If the message was faked or altered on the way, the signature fails. A wax seal on the envelope that only your charity can make.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) ties the other two together. It tells receiving servers what to do when a message fails SPF and DKIM, and where to send reports about who is sending as you. The policy is one word: p=none means "just report it to me, deliver anyway", p=quarantine means "put it in the spam folder", and p=reject means "refuse it". A charity with DMARC at p=none has hired a security guard and told them to watch but never intervene.
Put together: SPF says who may send, DKIM proves the message is genuine, and DMARC says what to do when either check fails. Without all three, and without DMARC set to quarantine or reject, an email pretending to be from your charity is delivered like any other.
Your own emails suffer first
The security risk is the one that makes the news, but the deliverability problem is the one charities feel every month without knowing why.
- Google and Yahoo, from February 2024, require every sender to have SPF or DKIM, and anyone sending 5,000 or more messages a day to have all three, with DMARC at least at p=none. Mail that fails is filtered into spam or rejected.
- Microsoft, from May 2025, applies the same requirement to Outlook.com, Hotmail and Live addresses.
- Below those volumes the rules are softer, but every major provider now scores unauthenticated mail down. A message with no DKIM signature that has been forwarded, which breaks SPF, arrives with nothing to vouch for it.
For a charity that means the Christmas appeal to 8,000 supporters on Gmail, the volunteer rota, the trustee papers sent to a Hotmail address, and the invoice to a funder are all more likely to disappear into spam. Nobody sees a bounce. The open rate just drifts down and the fundraising team blames the subject line.
The headline numbers
Of 9,471 Scottish charity domains that receive email, September 2026. SPF and DMARC rows are measured; DKIM and fully protected are estimates.
The gap between "has a record" and "record does anything" is the story. Most charities have SPF, but 44% end it with a soft fail that only marks spoofed mail rather than rejecting it. More than half have DMARC, but seven in ten of those have left it at p=none, the monitoring setting that instructs receiving servers to deliver failing mail anyway. A DMARC record at p=none is a burglar alarm that has been installed but never switched on.
Bigger charities are better protected, but not by as much as you would hope
Estimated share of charities fully protected, by most recent annual income as reported to OSCR. A floor, because DKIM on custom selectors is not detected.
Below £500,000 of income, we estimate fewer than one charity in twelve is fully protected. Even among the 698 charities with income over £5 million, which have IT budgets and often IT staff, more than half are not. A third of the largest charities have DMARC at p=none.
The staff picture is the same. Of charities with no paid staff, an estimated 6.1% are fully protected. With 50 or more staff, an estimated 44%. The 4,322 volunteer-run charities in the data are the ones with the least capacity to fix this and the most to lose from a fraudulent appeal in their name.
The email provider makes a big difference
Estimated share fully protected, by where the domain's email is delivered. Provider inferred from MX records; the DKIM component is a floor.
Microsoft 365 hosts email for 3,355 Scottish charities, more than a third of the total, which is no surprise given the free Business Basic grant. Those charities do better than average: 98% have SPF and 78% enforce it (both measured), and an estimated 21% are fully protected. But an estimated 45% of them have not switched on DKIM, or use a selector we could not detect, which in Microsoft 365 is two clicks and two DNS records, and 39% have DMARC sitting at p=none.
Google Workspace charities fare worse on every measure, with only 7% enforcing SPF and 8% enforcing DMARC. Two providers stand out for the wrong reasons. IONOS publishes a DMARC record automatically for 90% of its customers, but sets it to p=none and almost none of those charities have DKIM, so the record protects nothing. GoDaddy is the opposite: it auto-publishes an enforcing DMARC policy for 43% of domains, but with DKIM on 2%, so legitimate mail from those charities is at real risk of being filtered into spam.
Two smaller findings
Dead websites. 762 charities on the register list a website whose domain no longer exists. Some will be lapsed registrations, which a fraudster can buy and use to send email in the charity's name to anyone who still has the old address. If your charity has changed domain, keep paying for the old one.
Domains that do not send email are wide open. 1,015 live charity domains have no mail service at all, typically a website on one domain with email elsewhere. Only 2.6% of those have published the two records that tell the world the domain never sends mail. The other 97% can be spoofed freely, and nobody is watching the reports.
What this means for your charity
Fixing the records does two jobs at once: your own emails start reaching inboxes reliably, and fake ones stop being delivered.
If you run a Scottish charity, the odds are that your domain is in the measured 84% without an enforcing DMARC policy, and that some of your genuine email is already being filtered into spam. The fix costs nothing but an afternoon, and it comes in three steps:
- Check your domain now with our free SPF, DKIM and DMARC checker. It gives a pass, warn or fail verdict on each record with the exact change to make.
- Turn on DKIM in your email provider. In Microsoft 365 it is under Defender, Email authentication settings. In Google Workspace it is under Apps, Gmail, Authenticate email. Both give you DNS records to publish.
- Move DMARC from p=none to p=quarantine, then to p=reject once a few weeks of reports show your real mail passing. If you have no DMARC record, publish one at p=quarantine with a reporting address today.
Trustees can ask one question at the next meeting: "Can someone send email pretending to be us?" If nobody can answer with a screenshot of a passing check, that is the action.
For charities on Microsoft 365, our charity licensing guide covers what is included free, and our Microsoft 365 management and monitoring service checks these records continuously as part of the monthly report.
Methodology and limits
- Source. The Scottish Charity Register, downloaded from OSCR on 25 September 2026 under the Open Government Licence. 24,971 active charities.
- Domains. We took the website field, stripped it to the registrable domain, and excluded social media pages, site builders and fundraising platforms. That left 11,248 unique domains, of which 762 did not resolve and 1,015 had no mail records. The analysis covers the 9,471 domains that receive email. Where several charities share a domain, it is counted once.
- Checks. Public DNS queries only, over DNS over HTTPS: MX, TXT for SPF, TXT at _dmarc for DMARC, and DKIM on the common selectors used by Microsoft 365, Google Workspace and others. We did not send email, connect to any server, or contact any charity.
- Fully protected means one valid SPF record, a DKIM key found, and DMARC at quarantine or reject. Because the DKIM component is a floor, this figure is an estimate and the true share is likely somewhat higher.
- Verification. All 1,015 no-mail domains, and random samples of 300 no-DMARC, 200 enforcing-DMARC and 200 dead domains, were re-checked against Google's public resolver: 100% agreement on DMARC and dead domains, 99.8% on mail records.
- "Not protected against fake emails in their name" means no DMARC policy of quarantine or reject. Some receiving servers apply their own judgement to SPF failures, so a small share of fake mail to those domains may still be filtered; without DMARC the charity has not instructed anyone to reject it.
- Limits. DKIM selectors are set by each provider and can be custom, so the DKIM figures are a floor, not a ceiling. Income and staff figures are as reported to OSCR in the latest annual return. Provider is inferred from the MX record.
- No charity is identified. We hold the per-domain results and will share a charity's own result with that charity on request.
We will repeat the scan in 2027 and report what changed. If you represent a charity umbrella body and would like the breakdown for your members, get in touch.
