What we found on 95 company websites
We ran the same four checks on 95 companies in one industry, on one morning. The results were worse than we expected, and the reason they stay broken is more interesting than the faults themselves.
We were preparing outreach for event companies and wanted to understand the businesses before writing to any of them. That meant reading each website properly. Having read a few dozen, the same faults kept appearing, so we stopped reading and started measuring.
The sample is 100 event companies across 13 countries, from France and Germany to Singapore, South Africa, India, Australia and the United States. 95 of them had a website that answered when we asked. Everything below was measured on the morning of 18 September 2026, against the live sites and live DNS.
Anyone can send email as most of these companies
DMARC is the record that tells the receiving mail server what to do with a message that claims to come from your domain but cannot prove it. Without one, nothing stops a stranger writing to your clients in your name.
31 of the 95 have no DMARC record at all. Another 42 have one set to monitor only, which watches every forged message go past and does nothing about it. That leaves 22 companies actually enforcing it.
For an events business this is not an abstract risk. Delegates and sponsors are already used to receiving registration details and payment instructions from you, and they have no way of telling a forged message from a real one.
Most of them cannot tell you where a client came from
22 of the 95 carry no measurement code of any kind. No Google tag, no tag manager, no Matomo, no Plausible, nothing. When an enquiry arrives, nobody in the building can say whether that person came from a search, a referral, an event or a campaign somebody paid for.
The most telling case was not an absence. One company had an analytics plugin installed and never connected, and its own page source politely announces this to anyone who looks: no tracking code set. Somebody started the job. Nobody finished it, and nobody noticed for long enough that it is still there.
Eleven of them have two names
Eleven companies send email from one domain and run their website on another. The address on the business card and the address in the browser are different names for one company.
That is legitimate and often historical. The problem is that the protection is rarely applied to both. Usually one domain is locked down properly and the other, the one printed on every page of the website, is left open.
None of this is hard to fix
Every fault above is minutes of work for whoever already administers the domain. A DMARC record is one line of DNS. A measurement tag is an afternoon. No budget, no project, no vendor.
They persist because nobody is looking. And nobody is looking because it is not anybody's job. The founder assumes the web developer handles it, the web developer assumes the IT provider handles it, and the IT provider was never asked. That is a different problem from not knowing how, and a much harder one to solve with a checklist.
It is also the reason we build systems and hand them over with the governance attached, rather than delivering a document. A recommendation nobody owns produces exactly the situation above.
How this was measured, and what we deliberately left out
DMARC and domain records were read directly from DNS. Certificates were read from a live TLS handshake. Analytics was determined by fetching each homepage and searching the source for 20 known measurement scripts, including Google, Matomo, Plausible, Clarity, Hotjar, Meta and LinkedIn.
Two checks were dropped rather than published, because a raw fetch cannot measure them honestly:
- Homepage word count. Sites that render in JavaScript return an almost empty document to a crawler. One site measured 22 words and is a normal, complete page in a browser.
- Whether a site offers a way to make contact. Same reason. Our own first pass concluded one company had no contact route at all; it has a perfectly good contact page that is built in JavaScript.
One further caution on certificates. Several sites had a certificate expiring within a month, which sounds alarming and usually is not: a 90-day certificate renews itself. Only certificates with a lifetime beyond 180 days need a human to remember, and those are the only ones worth counting.
No company is named here. They are real businesses, several of them are people we have since written to, and the faults are theirs to fix privately.
If you want to know which of these applies to you
The first check takes about 30 seconds on your own domain and you do not need us to do it. If you would rather see the whole picture, the diagnostic asks twelve questions and tells you which stage of your revenue system is not defined yet.