Resources · Original research · September 27, 2026 · By Mike Parker
76% of Orange County firms we checked haven’t switched on a key fake-email protection
We read the public email settings of 319 Orange County law, accounting and escrow firms. 244 of them have not told the world’s email systems to block or quarantine messages that pretend to come from them. No firm is named, and nothing was scanned: these are public records any email system can read.
The numbers
Share of firms whose domain does not tell email systems to stop forged mail.
76%
All 319 firms (244 of 319)
84%
CPA and accounting firms (122 of 146)
79%
Law firms (97 of 123)
50%
Escrow and title companies (25 of 50)
About half (161 of 319) publish no setting at all. Public DNS records read the evening of September 27, 2026 (Pacific time).
By profession
| Firms | Block or quarantine | Watch only | No setting |
|---|---|---|---|
| CPA and accounting firms (146) | 16% | 32% | 52% |
| Law firms (123) | 21% | 20% | 59% |
| Escrow and title companies (50) | 50% | 26% | 24% |
| All firms (319) | 24% | 26% | 50% |
“Block or quarantine” means a DMARC setting of reject or quarantine. It includes 3 law firms that apply it to only part of their mail. One more law firm has a quarantine setting that applies to 0% of its mail; we count that as watch only. Percentages are rounded, so a row may not add to exactly 100.
What this means, in plain English
Anyone can put your firm’s address in the “From” line of an email. A short public setting called DMARC tells the receiving email system what to do when that message fails the checks: send it to spam, or refuse it. Without that setting, whether a fake message reaches your client is left to each recipient’s email provider.
Escrow, law and accounting firms send the kinds of messages criminals like to copy: wiring instructions, settlement payments, tax documents and payment requests. A fake one that looks like it came from the real firm’s address is harder for a client to spot.
Escrow and title companies did best in our sample, with half of them switched on. Accounting firms had the lowest share switched on (16%), close to law firms (21%). Law firms were the most likely to have no setting at all (59%).
Check your own firm
Our free domain check reads the same public records in a few seconds and tells you which setting your firm has. No signup, and we don’t keep the domain you check.
If the check says no DMARC record was found, or shows p=none (watch only), the fix is usually a few DNS changes over a few weeks: start by watching the reports, fix any service that sends email as you, then switch to quarantine and finally reject. If you’d like help, the free 30-minute assessment covers it. More for your profession: escrow and title, law firms, accounting firms.
How we did it
- Finding firms. On September 27, 2026 (Pacific time) we ran public web searches for each profession across Orange County cities and kept each firm’s own website address. We left out directories, national chains, and any firm we weren’t reasonably sure was based in Orange County.
- The sample. That gave 336 firm domains. 1 no longer exists and 16 publish no mail-server (MX) record, so they are left out. The results cover the other 319.
- What we read. Each domain’s public mail records and DMARC record, looked up through ordinary public DNS. These are the same lookups mail servers make every day to route and check email.
- What we did not do. We scanned nothing, logged into nothing, sent no email and contacted no firm. We do not publish or share the list of firms.
Limits. This is a sample, not every firm in the county, and it leans toward firms that show up in web search. It measures one setting on one day; settings change. It does not measure other protections a firm or its clients’ email providers may use, and it is not evidence that any firm has been impersonated or hacked. DMARC covers only forged use of a firm’s exact domain. It does not stop look-alike domains (one letter changed) or email sent from a real mailbox that has been broken into, so a firm with a reject setting can still be impersonated those ways. We checked each firm’s website domain; a firm that emails from a different domain was measured on its website domain.
Disclosure. CRC Cloud provides IT and security services, including this fix. Our own domain, crccloud.com, publishes a reject setting.
Questions
What is the setting this study looked at?
It is called DMARC. It is a short public record in a firm’s domain settings that tells email systems what to do with a message that claims to come from the firm but fails the checks. “none” means just watch. “quarantine” means send it to spam. “reject” means refuse it. With no record, or with “none”, each recipient’s email provider decides for itself.
Does a missing setting mean a firm was hacked or is careless?
No. It means the firm has not told other email systems to stop forged mail in its name. Often it is simply a setting nobody has turned on yet. It says nothing about whether a firm has been hacked, and it is one control among many.
Was my firm in the study?
We do not publish or share the list of firms. You can see your own firm’s setting in a few seconds with our free domain check, which reads the same public records.
How does a firm fix it?
Publish a DMARC record set to “none” with a reporting address first, so the reports show who sends email as you. Fix any service that fails, such as billing or marketing tools. Then move to “quarantine” and finally “reject”. For most small firms it is a few DNS changes over a few weeks.
Can reporters get the method and the numbers?
Yes. The method is on this page, and we can share the aggregate counts behind every figure. We do not share the list of firms. Call us or use the contact page.
Reporters: for the method and the aggregate counts, call (949) 916-6444 or use the contact page.