Website StrategyAugust 1, 20269 min read

84% of Local Business Domains Have No Email Policy That Does Anything. We Measured 150.

An autopsy of one signal across 150 Greater Fall River business domains: SPF, DMARC, and whether the mailbox on the website can even receive mail. Anchored on the 13 optometry practices Google returns for Swansea.

By Joshua Amado

Share
Underneath the Braga Bridge, where the city meets the highway.
Underneath the Braga Bridge, where the city meets the highway.

Start with what the optometry practices around Swansea have actually earned.

Thirteen of them come back when you ask Google for an optometrist in Swansea, MA. Between them they hold 1,404 Google reviews at a weighted average of 4.88 stars, and the lowest-rated one in the set still sits at 3.4. You cannot buy that. You cannot automate it. It is the accumulated residue of twenty years of getting somebody's kid into glasses that fit, and it is the single hardest asset in this entire article to replace.

So this piece is not about whether they are good at their job. They plainly are. It is about one narrow, invisible, unglamorous thing that is broken on four out of five business domains in this region — theirs included — and what it quietly costs.

The signal, and only the signal#

An autopsy slices one way, all the way down. So this is not "here are ten things wrong with ten websites." It is one question, asked of 150 domains at once:

Can this business's email be trusted to arrive, and can anyone else send mail pretending to be them?

Three DNS records answer it. MX says whether the domain can receive mail at all. SPF says which servers are allowed to send as you. DMARC says what a receiving mail server should do when a message fails those checks — and it is the only one of the three that has an enforcement setting.

150
Domains measured
Across 14 trades and 8 towns
34
Have no MX record
The domain cannot receive mail
98 of 116
No enforcing DMARC
84% of the ones that do receive mail

How we measured it#

Every domain Avalon has audited since 11 July 2026 across Fall River, Swansea, Somerset, Dartmouth, New Bedford, Fairhaven, Tiverton and Providence — 150 unique domains, 14 trades. On 1 August 2026 we ran three public DNS queries against each one and counted the answers. Every result was queried twice, on separate passes with different concurrency, and the two passes disagreed on zero domains.

You can reproduce any number here from your own laptop in a few seconds:

dig +short TXT example.com          # look for v=spf1
dig +short TXT _dmarc.example.com   # look for v=DMARC1 and p=
dig +short MX example.com

There is no proprietary scoring in this article. It is dig and arithmetic.

What we did not measure: whether DKIM is signing correctly (the selector name is not discoverable without knowing the mail host), whether SPF records actually pass on real sends, and how much mail any of these businesses sends. Those are not in this dataset and we are not going to pretend otherwise.

The result, by trade#

TradeDomains receiving mailHave SPFHave DMARCDMARC actually enforcing
HVAC2121112
Restaurant1311114
Veterinarian131382
Florist121165
Hair salon11611
Jeweler9772
Plumber8640
Print shop8631
Dentist5310
Cleaning services5530
Auto repair4211
Electrician3300
Day care3200
Driving school1010
All trades116945718

Read the last two columns together, because the gap between them is the whole story. Fifty-seven domains went to the trouble of publishing a DMARC record. Only eighteen set it to a policy that does anything. Thirty-nine of them are sitting at p=none — which tells the receiving mail server, in effect, "I have noticed this problem and I would like you to take no action about it."

p=none is a valid and sensible first step. It is a monitoring mode. You are supposed to be there for a few weeks while you read the reports and find the systems sending on your behalf, then move to quarantine and then reject. What we are looking at across this region is a lot of businesses who took step one in 2024, when Google and Yahoo announced their bulk-sender requirements, and never took step two.

A utility box painted with circuit-board artwork — small-scale public art.
A utility box painted with circuit-board artwork — small-scale public art.Fall River, MA

What it costs#

Two different failures live in this data, and they cost different things.

The first is delivery. Twenty-two of the 116 domains publish no SPF record at all. Seventeen publish neither SPF nor DMARC. Their outbound mail — appointment confirmations, invoices, the reply to a new patient's question — is unauthenticated, and Google is not coy about what happens next.

If you don't meet the requirements described in this article, your email might not be delivered as expected, or might be marked as spam.
Google Gmail Help, Email sender guidelines Source

That same page states that messages not authenticated with SPF or DKIM "might be marked as spam or rejected with a 5.7.26 error." A rejection at least bounces and you find out. Spam-foldering does not. The patient thinks you ignored them.

The second failure is impersonation, and it is worse. Without an enforcing DMARC policy, anyone in the world can send an email with your practice's domain in the From line, to your own patient list, and most receiving servers will deliver it. A fake "your appointment has moved, click here to confirm" from a domain your patients already trust is a very good phishing email. You will find out about it when someone calls the front desk, upset.

Ninety-eight of 116 local domains are in that position right now. So are seven of the nine optometry domains around Swansea.

Back to Swansea#

Of the 13 practices, 10 have a live website, 2 have no website at all, and 1 blocked our checker — so it is excluded from the counts rather than counted against it. That leaves nine unique domains, and all nine can receive mail.

  • 8 of 9 publish an SPF record. One publishes none.
  • 5 of 9 publish a DMARC record.
  • 2 of 9 have DMARC set to enforce — and one of those two is a national chain's corporate domain, not a local practice.
  • On 2 of the 9 sites, the contact address published for patients is a free Gmail mailbox rather than an address at the practice's own domain, which means the domain's DNS records are not protecting that inbox at all.

Now stack that against how else a patient can reach them, from the same audit run:

6 of 10
Have no contact form
The only way in is the phone
9 of 10
Offer no online booking
Every appointment happens during office hours
2 of 10
Phone number you cannot tap
On a phone, on the website

That is the actual shape of the problem, and it is not really an email problem. It is a reachability problem. A practice with no contact form and no online booking has made the telephone its only inbound channel. A practice whose domain fails authentication has made email an unreliable outbound channel. Do both and you have a business that can only be reached between 9 and 5, by someone willing to call, and that cannot reliably answer.

Meanwhile the median site in this set takes 7.6 seconds to show anything on a phone against Google's 2.5-second "good" threshold, and the slowest takes 20.7 seconds — but that is a different autopsy for a different week.

The fix you can do today, for free, in five minutes#

Open a terminal — Terminal on a Mac, PowerShell on Windows — and run the middle command from the method section above against your own domain. If nothing comes back, you have no DMARC record. If something comes back containing p=none, you have one that does nothing.

Then publish this single TXT record at your DNS host, on the hostname _dmarc:

v=DMARC1; p=none; rua=mailto:you@yourdomain.com

That is monitoring mode on purpose. For the next three or four weeks you will get aggregate reports telling you every system sending mail as you — your booking software, your newsletter tool, the practice management system nobody remembers signing up for. Do not skip to p=reject. Turning enforcement on before you know who sends for you is how a practice blocks its own appointment reminders.

If you'd rather not touch DNS, the other free fix takes two minutes: put a working contact form on your website. Six of ten Swansea optometry sites do not have one, and a form posts to your inbox regardless of what your SPF record says.

The waterfront boardwalk at golden hour, lamps coming on along the rail.
The waterfront boardwalk at golden hour, lamps coming on along the rail.Fall River, MA

What Monday looks like#

If you run an optometry practice — or a salon, or an HVAC company, the numbers barely move between trades — here is the order, cheapest first:

  1. Run the three dig commands. Five minutes, free. You now know where you stand instead of guessing.
  2. Publish p=none with a reporting address. Fifteen minutes at your DNS host, free. Reports start arriving within a day or two.
  3. Add a contact form. One to two hours on most website platforms, free to about $15/month. This is the highest-return item on the list, because it works whether or not anything else on this page is fixed.
  4. Read four weeks of DMARC reports, then move to p=quarantine. An hour of reading spread over a month. This is the step 39 businesses in this dataset never took.
  5. Add online booking. Nine of ten practices here have none. Half a day to set up, and it is the only item that adds appointments rather than protecting the ones you have.

None of this ranks you higher on Google. That is not what it is for. It is for the fifty-eight-year-old who found you through a five-star review, emailed a question at 8pm on a Sunday, and never heard back — because there was no form, and your reply landed in a spam folder neither of you will ever open.


If you want someone to run these checks on your domain and tell you plainly what came back, that is a phone call, not a project. 774.559.8992 · Joshua.Amado@AvalonPartner.com

Every business referenced in this article is anonymised. They did not ask to be measured, and it would be unfair to grade them in public by name. The aggregate numbers are all reproducible with the commands above.

Want help putting this into practice?

Avalon Partner helps Fall River and South Coast businesses fix the gaps that cost them leads. Call 774.559.8992 or email Joshua.Amado@AvalonPartner.com.

Keep reading