In October 2026 we ran the public checks from our free website audit across 124 websites belonging to independent businesses and charities in Warwickshire: tradespeople, accountants and solicitors, shops and cafés, salons and clinics, engineering firms and local charities, in seven towns. 110 could be read; the rest were down or turned automated visitors away. This is what we found. No business is named and none ever will be.
The headline figures
- 78% could have their email forged. Of the sites with email on their own domain, more than three in four had no DMARC policy that would stop someone sending email in their name — the trick behind most fake-invoice fraud. 44% had no DMARC record at all and only 10% were fully protected. That is close to the national picture: three in four UK domains had no effective protection in December 2025.
- 47% sent none of the five standard security headers, the one-line server settings that tell browsers to block common attacks such as clickjacking. Only 4% sent all five.
- 41% had no privacy policy we could find on the homepage, about or contact page, even though many collect personal details through a contact form, a newsletter or analytics.
- 17% had a domain due for renewal within three months and six sites within a month. Most will renew without trouble. The ones that do not take their website and every email address down with them.
- 26% announced the exact version of their server software, which tells an attacker which known weaknesses to try.
- 12% still carried Google Analytics code that stopped working in 2023, so whatever reports it once fed have been empty since.
- 15% loaded tracking as soon as the page opened with no cookie banner at all.
What the sites do for the business
Very little is automated. A quarter took payments or sold online, but only 5% let customers book online, 10% showed reviews automatically and just 2% offered live chat. For most of these businesses the website is a brochure and every enquiry still needs a person to answer it.
Town by town
Each town is between 13 and 17 sites, so treat these as a guide rather than a ranking. The share of sites whose email could be forged:
- Coventry: 56%
- Leamington Spa: 62%
- Nuneaton and Bedworth: 73%
- Kenilworth: 87%
- Rugby: 88%
- Stratford-upon-Avon: 92%
- Warwick: 92%
Every health and beauty business we checked that uses email on its own domain could have it forged, as could nine in ten of the trades. Professional services and engineering firms did better on email but worse on security settings: seven in ten sent none of the five headers.
What it means
None of this means these are bad businesses or bad websites. The median site scored 78 out of 100 on our checks and most of the gaps are settings nobody was ever told about — usually a few minutes' work for whoever looks after the site. But they are exactly the gaps that fraudsters, search engines and AI assistants notice first.
How to check your own
Our instant check shows four of these results for any website in a few seconds. The free website audit covers everything above and more, explained in plain English and read by a person before it is sent. You can see a real sample report first.
How we did it
The sites were drawn from public directories — Chamber of Commerce and Chamber of Trade member lists, local business registers and searches by trade and town — and include only independent businesses and charities with their own website. National chains, public bodies and our own clients were left out. Each site was checked once in early October 2026 from our server, reading only what any visitor or a domain lookup can see: the homepage and up to two linked pages, DNS records, the security certificate and the public domain registry. Nothing was submitted and nothing was changed. The results are kept on file; no individual result will be published.