We checked 51 small-business domains: 30 could be spoofed by email. Here's how to find these prospects automatically
If you sell IT, security or web services to small businesses, the hardest part of outreach is the first line. "We help businesses with cybersecurity" gets ignored. "Anyone can currently send email that looks like it's fr
If you sell IT, security or web services to small businesses, the hardest part of outreach is the first line. "We help businesses with cybersecurity" gets ignored. "Anyone can currently send email that looks like it's from @yourfirm.com, and here's the DNS record that proves it" gets read.
We wanted to know how common those verifiable, fixable problems really are, so we ran passive, public-only checks against 51 small professional firms: accountants, law firms and dental practices in South Africa and the US.
What we checked (and what we didn't)
Only things anyone can see from the outside:
- DNS: MX, SPF, DMARC, and DKIM on ~59 common selectors
- One homepage request: status code, redirects, generator tags, script versions, response headers
- One TLS handshake: certificate issuer and expiry
- RDAP/WHOIS: domain expiry date
No port scanning, no vulnerability probing, no logins. This matters both ethically and practically: everything you find is something the business owner can verify in 10 seconds.
The results
Of the 51 firms:
| Finding | Count |
|---|---|
Domain spoofable (no DMARC record, or p=none) among firms with mailboxes on their domain |
30 |
| ...of which had no DMARC record at all | 23 |
| No DKIM key found on any common selector | 19 |
| Running jQuery < 3.5, an outdated WordPress, or end-of-life PHP | 10 |
| Domain expiring within 30 days | 3 |
| Website served over plain HTTP only | 2 |
| Expired SSL certificate | 1 |
| Host "domain registered / coming soon" placeholder instead of a website | 1 |
Some observations:
1. DMARC is the big one. Well over half of these firms can be impersonated by email. For an accountant or a law firm, that's the exact setup behind "our banking details have changed" invoice fraud aimed at their clients. Gmail, Yahoo and Microsoft now require DMARC for bulk senders as well, so this is no longer a niche concern.
2. Most of them aren't on Microsoft 365 or Google Workspace. A large share use the mail service bundled with their web host. That's a second conversation in itself (deliverability, backups, MFA).
3. DKIM detection is inherently lossy. You can't list a domain's DKIM selectors from DNS; you can only guess common ones (google, selector1, default, k1 and so on). A "no DKIM found" result is a low-confidence signal, so we weight it accordingly and never lead with it.
4. "Slow website" is a trap in containers. Our first runs flagged half the sites as slow. It turned out CPU throttling in a small container was inflating TLS and parse timings. The fix was to re-time slow candidates in a second, idle pass. If you build your own checker, don't trust single-shot timings.
Turning findings into a prospect list
A raw list of failing checks isn't a prospect list. What a salesperson needs per company is:
- The single most commercially relevant problem (not 14 findings)
-
The exact evidence, e.g.
No DMARC TXT record at _dmarc.example.com. SPF: "v=spf1 mx a ?all" - Why it matters in plain English, e.g. "visitors get a full-page browser warning"
- A score, so you work the list top-down
- A one-line opener that is specific, checkable and offers value first
Here's an anonymised row from the run:
rank: 2
company: Example Law Firm 02 (law firm, Johannesburg)
opportunityScore: 81 (critical)
topProblem: Domain can be spoofed: no DMARC record
evidence: No DMARC TXT record at _dmarc.example-02.co.za.
SPF: "v=spf1 mx a include:spf.host-h.net ?all"
otherSignals: Outdated WordPress 6.0.17 | No DKIM signing key found |
Missing security headers (grade F)
coldOpenLine: "Quick heads-up: anyone can currently send email that looks
like it's from @example-02.co.za because there's no DMARC record. I can
send you the exact DNS fix, it takes about 15 minutes."
The scoring is simple and transparent: severity of the top problem, plus a smaller bump for each additional independent signal, with confidence penalties for lossy checks like DKIM.
Doing it yourself
You can do every check above with free tools: dig TXT _dmarc.example.com, openssl s_client -connect example.com:443, curl -sI, and an RDAP lookup at https://rdap.org/domain/example.com. For a handful of domains, that's all you need.
For hundreds of domains, we packaged the whole pipeline (checks, scoring, evidence, pitch and opener) as an Apify Actor. You paste domains, URLs, emails or a CSV/Google Sheet link and get back a ranked list you can export to CSV, Sheets, Make or Zapier:
👉 Security & Website Pain Prospect Finder
It's pay-per-result at $0.015 per company scored. Invalid inputs, non-existent domains and companies below your minimum score are free. The Store page documents the input format and output columns.
Please use this responsibly
These are real businesses with real gaps. Lead with help, not fear: give them the fix even if they don't hire you, include an opt-out, and follow your local anti-spam and privacy law (CAN-SPAM, GDPR, POPIA). Never publish a company's name next to its security gaps. That's why every example above is anonymised.
Questions about the methodology, especially DKIM false negatives or how you pitch DMARC to small clients? Ask in the comments.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.