CYBERSECURITY

We Checked 237 Serbian Domains. 69% Can Be Spoofed.

We surveyed DMARC enforcement across 237 Serbian domains and every licensed bank: 85% publish SPF, only 31% block spoofing. The numbers and the fix.

Kage System·06 Aug 2026

Eighty-five percent of the Serbian domains we checked publish an SPF record. Only 31% are actually protected against email spoofing. Most have done part of the setup and stopped before the part that does the protecting. This isn’t specific to Serbia; a national TLD is just cheap to measure end to end, so we measured one.

A dark server rack with patch cables and glowing status lights
Photo by Kevin Ache on Unsplash.

We tell clients to put SPF and DMARC on every domain they own, including the ones that never send mail. So it was a little awkward that the first domain this survey looked at — our own — had neither. We fixed that before publishing: v=spf1 -all and p=reject, about five minutes at the registrar. With that out of the way, the other 237.

What we checked, and what “spoofable” means

We took the top 250 .rs domains from the Tranco list (a research ranking built to resist manipulation), dropped 13 that are foreign projects just parked on the .rs TLD — docs.rs and the rest of the Rust ecosystem — and kept the 237 Serbian organisations that were left. Banks we handled separately: all 19 licensed in Serbia, as a reference group, since they’re the most regulated senders in the country. Every lookup is a public DNS query, run on 6 August 2026 and cross-checked on a second resolver.

For each domain we read three records: SPF, DMARC, and MX. We count a domain as spoofable when nothing tells a receiving server to reject forged mail: no DMARC record, or p=none, or a policy applied to only a fraction of mail. In each of those cases a forged message from the domain arrives with nothing to stop it. That’s the whole claim — we’re not measuring anything cleverer than “is there a barrier or isn’t there.”

Why SPF alone does nothing

This is where most setups go wrong, and it’s a quirk of how email authentication is built rather than carelessness.

Email has two “from” addresses. There is the envelope sender, used during the SMTP handshake and invisible to the reader, and there is the From: header, the name and address your mail client actually displays. SPF checks the envelope sender. The reader never sees it. An attacker can set a perfectly valid envelope sender on a domain they control, pass SPF cleanly, and still put [email protected] in the From: header the victim reads.

DMARC closes the gap. It requires the visible From: domain to align with the address that SPF or DKIM actually authenticated, and it publishes an instruction — quarantine or reject — that tells receiving servers what to do when that check fails. Without DMARC at enforcement, SPF is only ever checking an address the attacker had no reason to forge.

So the number worth watching isn’t how many domains publish SPF. It’s how many run DMARC at p=quarantine or p=reject, and that number is a lot smaller.

The sector gradient

The overall average buries the interesting part. Broken out by sector, the numbers line up closely with how regulated each one is.

Bar chart of DMARC enforcement by sector: licensed banks 58%, gambling operators 58%, academic 40%, other business 36%, government 14%, news media 11%. Overall 31% of Serbian organisations enforce; 69% are spoofable.
Green is enforced; grey is spoofable. The sectors that move money protect themselves. The ones that trade on their name mostly do not.

Banks lead, and it isn’t close. All 19 licensed banks publish SPF, 16 publish DMARC, and 11 enforce it. Payment fraud is their daily threat model and it shows. Serbian gambling operators match them at 58% — another sector where mail fraud is an immediate, quantified cost.

News media is the worst sector we measured: 11% enforcing, 89% spoofable. Forty-seven of the country’s most-read news domains, and all but a handful can be impersonated. I’ll come back to why that one matters more than it first looks.

Government sits near the bottom at 14%. Every government domain we checked publishes SPF, and almost none of them enforce anything on top of it. It’s the SPF-without-DMARC pattern at its clearest, on exactly the domains people are trained to trust.

What an attacker gets out of this

A missing DMARC record matters because of what it lets someone send. It’s the opening move in invoice fraud and phishing, and it removes the one detail that normally gives those emails away.

That detail is the sender’s address. Most phishing gets caught because the address is subtly wrong: the mail claims to be from the bank, but a careful reader notices it actually came from [email protected] and deletes it. When a domain is spoofable, the attacker doesn’t need that lookalike. They put the exact, real address in the “From” line — [email protected], [email protected], [email protected] — and the message arrives looking completely legitimate, because as far as the recipient can tell, it is. No odd-looking domain, no warning banner, nothing to catch. And finding a domain worth abusing takes no skill at all: you read a list of the ones missing the record. A survey like this is that list, which is why we don’t name the domains in it.

What that buys an attacker depends on who they’re impersonating:

Every one of these is blocked by a single line of DMARC policy set to p=quarantine or p=reject. That line is what we were counting: the domains without it are the ones exposed to all of the above.

Three failure modes we kept seeing

The same three mistakes accounted for almost every spoofable domain.

Stuck at p=none forever. 78 Serbian domains publish a DMARC record with p=none. That is monitoring mode — it sends reports and blocks nothing — and it is meant to be a two-week waypoint, not a destination. A lot of organisations turned DMARC “on,” saw no breakage, and never finished. p=none is not protection.

SPF, but no DMARC at all. 50 domains publish SPF and stop there. It’s the most common version of the problem, and it usually comes from a checklist that ended one item too early.

Two SPF records on one domain. Two domains publish multiple SPF records, which is not “extra safe” — RFC 7208 says a domain with more than one SPF record produces a permerror and the SPF check fails entirely. They would be measurably better off deleting one. It’s usually the fingerprint of two teams, or two vendors, each adding “their” record.

The fix, in the order that won’t break your mail

DMARC has a reputation for breaking legitimate email. It earns that reputation only when people skip the middle. The safe rollout is four steps and the first one changes nothing:

  1. Publish p=none with a reporting address. v=DMARC1; p=none; rua=mailto:dmarc@yourdomain. Delivery is unaffected; you simply start receiving aggregate reports of everyone mailing as you.
  2. Read the reports for two to four weeks. You will find senders you forgot — the invoicing tool, the CRM, an old newsletter platform. Make sure each legitimate one passes SPF or DKIM.
  3. Raise to p=quarantine. Failing mail now goes to spam rather than the inbox. Watch for a week.
  4. Raise to p=reject. Failing mail is refused. This is the line where spoofing your domain stops working.

For a domain that sends no mail — a parked brand, a redirect — skip the middle entirely. Two records close it completely:

yourdomain.rs.        TXT   "v=spf1 -all"
_dmarc.yourdomain.rs. TXT   "v=DMARC1; p=reject; rua=mailto:[email protected]"

-all says nothing is authorised to send as this domain; p=reject tells receivers to bin anything that fails. It’s the cheapest security control we know of, and going by our own domain this week, the easiest to forget.

What this survey does not show

A few limits worth stating. We didn’t enumerate DKIM, the third authentication method, because it sits at a selector name you can’t guess from outside. That might sound like it rescues some of the spoofable domains, so we spot-checked: several of them, including major telecoms and news sites, do publish DKIM, and it makes no difference. At p=none no receiving server is told to require a signature, so an attacker just sends unsigned mail; DKIM only matters once DMARC is enforcing. We also looked for the obsolete alternatives that predate DMARC (ADSP, Sender ID) and found none in use. Past that, the usual caveats: this is a snapshot on one day and records change; a big mailbox provider may still spam-filter some spoofed mail on reputation alone, though that’s their guess and not the domain’s doing; and Tranco ranks by traffic, so a spoofable domain can still be low-risk if nobody would bother impersonating it.

None of it changes the headline. Most of these organisations set SPF up and left it there, and two-thirds of them can still be spoofed as a result.

If you don’t know which side of that line your own domains fall on, that’s exactly the kind of thing our two-week fixed-price assessment is built to answer — we check every domain you own, tell you which are spoofable, and hand you the records to fix them. No commitment past the report.


Survey run against the top 250 .rs domains from Tranco list Q2X24 and all 19 banks licensed in Serbia, over public DNS (Cloudflare, spot-checked against Google) on 6 August 2026. We report sector aggregates only and name no organisation, good or bad.