Press Release

Nearly half of commercial real estate firms leave their email open to forgery, new scan finds

Brokerages are twice as exposed as the developers and REITs they work for, according to a scan of 398 CRE firms' domains

September 30, 2026 · All press releases

— Nearly half of commercial real estate firms have not switched on the standard protection that stops criminals sending email in their name, according to a scan of 398 CRE firms' internet domains published today by DeshTEK Digital.

The scan checked each firm's DMARC record — the published instruction that tells receiving mail servers what to do with an email that fails authentication. 182 of the 398 firms, or 46%, had no enforcing policy, meaning a forged email appearing to come from the firm is delivered to the recipient's inbox rather than blocked.

Of those, 80 firms had no DMARC record at all. A further 102 had published one and left it set to p=none — a monitoring mode that reports forgery to the firm without stopping it. Only 115 firms, 29% of the sample, used p=reject, the setting that actually blocks a forged message.

Thirty-three firms, 8% of the sample, had neither DMARC nor an SPF record, the two basic email authentication mechanisms.

Brokerages are the least protected

The gap between segments was wider than the overall figure suggests:

SegmentFirms scannedNo enforcing DMARC
Net lease specialists1782%
Brokerage and advisory8260%
Healthcare and medical office1354%
Industrial2850%
Retail1250%
REITs5235%
Capital markets and investment management2133%
Developers and owners2129%

Firms holding institutional capital have largely done the work. The brokerages coordinating transactions between them have not — despite being the party whose email most plausibly carries closing and payment instructions.

"A developer with a security team has DMARC set to reject. The brokerage arranging their next disposition often does not, and that brokerage is the one emailing wiring details near a closing," said Rahul Singh, Founder of DeshTEK Digital. "The asymmetry is the whole finding: the protection is concentrated exactly where the transaction is not."

"The 102 firms sitting at p=none are the interesting group," said Singh. "They did the hard part — someone published a DMARC record — and then left it in monitoring mode, which tells you about forgery after it has already been delivered. Moving to quarantine or reject is an afternoon's work for whoever runs the domain."

Websites

The scan also found that 43 firms, 11% of the sample, publish a website address that does not load, and four are serving an expired TLS certificate, which shows visitors a browser security warning. Every failed site was re-checked individually with a browser user agent and retries; 33 sites that failed an automated first pass proved reachable and were excluded from those figures.

Method

The scan was run on 30 September 2026 against 449 domains supplied from public company listings. After removing duplicate domains, consolidating firms that appear under more than one domain, and excluding 30 architecture, engineering and construction firms, 398 distinct commercial real estate firms remained, each counted once. For each firm, DMARC and SPF records were read from public DNS over DNS-over-HTTPS, with every negative result re-checked against a second independent resolver. Certificates were read by direct connection to port 443.

All data is public. Nothing required a login, and no firm's systems were accessed. DeshTEK Digital is publishing the method in full and will share the anonymised dataset with journalists on request. Individual firms are not named, because the intent is to describe an industry gap rather than to expose any firm's exposure.

Two limitations are stated plainly. The sample is a compiled list rather than a random one, and it is weighted toward large REITs and institutional firms, which are better protected than average — the true industry-wide figure is likely worse, not better. And DKIM, the third authentication mechanism, cannot be checked without knowing a firm's selector, so its absence from this study does not mean these firms lack it.

What firms can do

Checking a domain's DMARC record takes seconds and requires no special tools. Firms that find no record, or one set to p=none, can publish or update it through whoever manages their DNS. Moving from monitoring to enforcement requires first confirming that every legitimate sender — the CRM, the marketing platform, the listing service — is authorised, which is why many firms stop at p=none and never return to it.

DeshTEK Digital's Website Reputation & Blocklist Check tests SPF and DMARC alongside spam blocklists, antivirus vendors and SSL certificates, and is available on its free plan.

About DeshTEK Digital

DeshTEK Digital is an AI marketing intelligence platform built specifically for commercial real estate. Its 28 tools cover website, SEO and reputation audits, AI search visibility testing and citation tracking across Claude, ChatGPT and Gemini, backlink analysis scored for CRE relevance and toxicity, broker and team authority scoring, lease abstraction, listing and offering-memorandum copy, market pages, outreach sequences, social publishing and white-label client reporting. The platform is operated by DeshTek Technologies (OPC) Pvt. Ltd., based in Bengaluru, India. More at deshtekdigital.com.

Media contact

Company
DeshTek Technologies (OPC) Pvt. Ltd.
Email
info@godeshtek.com
Website
www.deshtekdigital.com
LinkedIn
linkedin.com/company/deshtek-technologies
###

Related