Insights · Last verified 2026-09-14

Can someone send email pretending to be your Hawaiʻi business? For nine in ten, yes.

We checked the public email records of 689 locally owned businesses on Kauaʻi, Oʻahu, Maui, and Hawaiʻi Island. Here is what we found, how we checked, and what to do about it.

The short answer: of 593 locally owned Hawaiʻi businesses whose domains receive email, 519 (88%) do not tell Gmail or Outlook to reject mail pretending to come from them. 337 have no DMARC record at all. Only 74 enforce it. Another 96 of the 689 domains we checked run no email at all and are listed separately below.

The numbers, island by island

IslandDomains with mailNo DMARC recordMonitor-only (p=none)EnforcedExposed
Kauaʻi11175251190%
Oʻahu211126612489%
Maui1106440695%
Hawaiʻi Island16172563380%
All four islands5933371827488%

What "exposed" means, in plain English

Email has no built-in proof of who sent it. Three public DNS records fix that: SPF lists who may send as you, DKIM signs each message, and DMARC tells the receiving inbox what to do with mail that fails those checks. A domain with no DMARC record, or with DMARC set to "p=none," is telling Gmail and Outlook to deliver forgeries anyway. That is the door the "updated payment details" scam walks through, and the weeks after a disaster are when it walks through most.

Why this matters right now

Hurricane Lowell hit Kauaʻi on September 8–9, 2026. In the weeks after a storm, insurers, lenders, contractors, and customers all send more email than usual, and criminals impersonate every one of them. A business that cannot reject forged mail in its own name is also a business whose vendors and customers cannot tell a real invoice from a fake one.

Check your own domain in ten seconds. Go to mxtoolbox.com/dmarc.aspx and type your web address. "No DMARC record found" or "p=none" means you are in the 88%.

Method

Between September 13 and 14, 2026 we read the public SPF and DMARC DNS records of 689 locally owned businesses (restaurants, tour and activity operators, contractors, shops, farms, and professional services; no real-estate brokerages, property managers, medical practices, government, or off-island chains). Lists came from public directories and each business's own website. The check reads public records only and touches no company's systems. Source files: security_check_kauai.csv, security_check_oahu.csv, security_check_maui.csv, security_check_bigisland.csv, held by Hawaii Intelligence and available to journalists on request.

What this report cannot tell you

Whether any business has actually been impersonated; whether DKIM is configured (that needs the sender's selector, which we did not guess); or anything about a company's internal security. It measures one public setting, the one that decides whether forged mail is rejected.

What to do

If your domain is exposed: publish SPF, turn on DKIM in Google Workspace or Microsoft 365, add a DMARC record at p=none, watch the reports for two weeks, then move to p=quarantine and p=reject. It is a day of work and no software to buy. If you would rather not do it yourself, we do it for a flat fee, records you paste, staged to full enforcement over 60 days: email micah@hawaiiintelligence.com with your web address and we will start with a free one-page diagnostic.

Forward this to an ownerEmail it
The Hawaiʻi Business Brief

What every Hawaiʻi business owner needs to know this week. Free, every Tuesday.

Rules and deadlines, recovery programs, scams in circulation, and the Standard. No selling.