We present DNS email security profiling for 428 K-12 LEAs in Massachusetts, of which 379 have active domains (88.6% coverage). Domains were scored on the Lokentra 100-point Email Security Index (ESI) rubric (SPF 30 pts + DKIM 30 pts + DMARC 40 pts). Massachusetts K-12 districts achieve an average ESI score of 58.0/100, with 35.6% earning Grade A or B (strong posture) and 20.3% receiving Grade F (minimal authentication). Only 67.5% have any DMARC record, and just 34.3% have DMARC at an enforcement level (quarantine or reject) — leaving 32.5% of districts fully vulnerable to email domain spoofing. This report provides entity-level data for all 379 scored domains including provider classification, authentication status, and ESI score, sourced from NCES CCD 2024-2025 and live DNS resolution conducted April 22, 2026.
| Metric | Value |
|---|---|
| Total K-12 LEAs in state | 428 |
| Regular school districts | 323 |
| Charter LEAs | 79 |
| Other LEA types (state-operated, regional, etc.) | 26 |
| LEAs with active internet domain | 379 (88.6%) |
| Domains DNS-profiled | 379 |
| Data freshness (NCES CCD) | 2024-2025 school year |
| DNS scan date | April 22, 2026 |
To estimate human exposure, NCES national averages are applied to CCD 2024-2025 operational school counts: 381 students per school, 51 staff per school, and 2 parents or guardians per student. Massachusetts K-12 districts collectively operate approximately 1,823 schools.
| Population | Total in Dataset | At Risk (No DMARC, 32.5%) | Critically Exposed (Grade F, 20.3%) |
|---|---|---|---|
| Students | 694,563 | 225,732 | 140,996 |
| Parents and guardians | 1,389,126 | 451,465 | 281,992 |
| Staff and educators | 92,973 | 30,216 | 18,873 |
| Total people | 2,176,662 | 707,415 | 441,862 |
Estimates based on NCES national averages. Individual district enrollment data can be linked via NCES LEAID for precise counts.
| Protocol | Massachusetts | National K-12 (ESI) | vs. National |
|---|---|---|---|
| SPF (any configuration) | 83.4% | 79.7% | +3.7pp |
| DKIM (key published) | 68.1% | 59.6% | +8.5pp |
| DMARC (any policy) | 67.5% | 55.5% | +12.0pp |
| DMARC at enforcement (quarantine/reject) | 34.3% | ~21.0% | +13.3pp |
| DMARC at reject (full enforcement) | 15.6% | ~12.2% | +3.4pp |
| No MX records (not receiving email) | 7.1% | ~10.0% | -2.9pp |
| Grade | Score | Districts | Share | Interpretation |
|---|---|---|---|---|
| A | 90–100 | 70 | 18.5% | Full enforcement |
| B | 70–89 | 65 | 17.2% | Strong posture |
| C | 50–69 | 123 | 32.5% | Partial protection |
| D | 30–49 | 44 | 11.6% | Weak configuration |
| F | 0–29 | 77 | 20.3% | Minimal/no authentication |
| Average score | 58.0 / 100 | |||
| Provider | Districts | Share |
|---|---|---|
| Google Workspace | 271 | 71.5% |
| Microsoft 365 | 32 | 8.4% |
| Barracuda | 16 | 4.2% |
| Mimecast | 5 | 1.3% |
| GoDaddy | 3 | 0.8% |
| Proofpoint | 2 | 0.5% |
| District | Domain | County | Provider | SPF | DKIM | DMARC Policy | Score | Grade |
|---|---|---|---|---|---|---|---|---|
phacs.org |
Middlesex County | Google Workspace | ✓ | ✓ | reject | 100 | A | |
arlington.k12.ma.us |
Middlesex County | Google Workspace | ✓ | ✓ | reject | 100 | A | |
bhrsd.org |
Berkshire County | — | ✓ | ✓ | reject | 100 | A | |
billericak12.com |
Middlesex County | Google Workspace | ✓ | ✓ | reject | 100 | A | |
brookline.k12.ma.us |
Norfolk County | Mimecast | ✓ | ✓ | reject | 100 | A | |
gloucesterschools.com |
Essex County | Google Workspace | ✓ | ✓ | reject | 100 | A | |
georgetown.k12.ma.us |
Essex County | Google Workspace | ✓ | ✓ | reject | 100 | A | |
hudson.k12.ma.us |
Middlesex County | Barracuda | ✓ | ✓ | reject | 100 | A | |
leominsterps.org |
Worcester County | Google Workspace | ✓ | ✓ | reject | 100 | A | |
lawrence.k12.ma.us |
Essex County | Microsoft 365 | ✓ | ✓ | reject | 100 | A | |
nrsd.org |
Worcester County | Google Workspace | ✓ | ✓ | reject | 100 | A | |
peabody.k12.ma.us |
Essex County | Google Workspace | ✓ | ✓ | reject | 100 | A | |
norton.k12.ma.us |
Bristol County | Google Workspace | ✓ | ✓ | reject | 100 | A | |
saugus.k12.ma.us |
Essex County | Google Workspace | ✓ | ✓ | reject | 100 | A | |
southhadleyschools.org |
Hampshire County | — | ✓ | ✓ | reject | 100 | A |
| District | Domain | County | Provider | SPF | DKIM | DMARC Policy | Score | Grade |
|---|---|---|---|---|---|---|---|---|
cclighthouseschool.org |
Barnstable County | Google Workspace | ✗ | ✗ | — | 0 | F | |
bostonrenaissance.org |
Suffolk County | — | ✗ | ✗ | — | 0 | F | |
sturgischarterschool.com |
Barnstable County | GoDaddy | ✗ | ✗ | — | 0 | F | |
kennedyacademy.org |
Suffolk County | — | ✗ | ✗ | — | 0 | F | |
matchschool.org |
Suffolk County | Google Workspace | ✗ | ✗ | — | 0 | F | |
essexnorthshore.org |
Essex County | — | ✗ | ✗ | — | 0 | F | |
newheightscharterschool.com |
Plymouth County | — | ✗ | ✗ | — | 0 | F | |
fllac.org |
Middlesex County | — | ✗ | ✗ | — | 0 | F | |
northrivercollaborative.org |
Plymouth County | — | ✗ | ✗ | — | 0 | F | |
osacps.org |
Worcester County | Google Workspace | ✗ | ✗ | — | 0 | F | |
schools.amesburyma.gov |
Essex County | — | ✗ | ✗ | — | 0 | F | |
barnstable.k12.ma.us |
Barnstable County | Google Workspace | ✗ | ✗ | — | 0 | F | |
burlingtonpublicschools.org |
Middlesex County | — | ✗ | ✗ | — | 0 | F | |
concordpublicschools.net |
Middlesex County | — | ✗ | ✗ | — | 0 | F | |
everettpublicschools.org |
Middlesex County | — | ✗ | ✗ | — | 0 | F |
| County | Districts | Website Coverage |
|---|---|---|
| Middlesex County | 76 | 97.4% |
| Worcester County | 59 | 100.0% |
| Essex County | 45 | 93.3% |
| Norfolk County | 39 | 100.0% |
| Plymouth County | 38 | 97.4% |
| Bristol County | 30 | 100.0% |
| Suffolk County | 27 | 96.3% |
| Hampden County | 26 | 96.2% |
| Hampshire County | 23 | 100.0% |
| Franklin County | 21 | 100.0% |
These findings identify specific, actionable gaps in Massachusetts's K-12 email security posture. The 32.5% DMARC gap represents districts that can be impersonated by any sender, enabling phishing campaigns targeting parents, students, and educators with no authentication failure. Key observations:
p=none). Upgrading to p=quarantine would move them to B without infrastructure changes.The full Massachusetts K-12 dataset — 428 entities with NCES CCD enrichment (phone, address, grade span, school count, LEAID) and DNS authentication profiles — is available as part of the Lokentra ESI State Pack.
| Tier | Scope | Suggested Use |
|---|---|---|
| State Pack: Massachusetts | All 428 K-12 LEAs, full DNS profile + CCD enrichment | Regional studies, state policy, outreach |
| K-12 National | All 50 states, 20,021+ K-12 LEAs | National K-12 cybersecurity research |
| Full Registry | 801,359+ entities across all sectors | Comprehensive multi-sector research |
| API + Updates | Quarterly re-scan, REST API | Longitudinal studies, live dashboards |
Contact: research@monitorworkspace.com — Free demo at monitorworkspace.com/scorecard
Citation: Lokentra Research Team (2026). Massachusetts K-12 Email Security Intelligence: DNS Authentication Profiling of 428 School District LEAs. Lokentra U.S. Email Security Index (ESI) — State Intelligence Series. https://lokentra-site.web.app/research/states/ma-k12-paper.html
Data sources: NCES Common Core of Data (CCD) 2024-2025; DNS records resolved via Google Public DNS (8.8.8.8) and Cloudflare (1.1.1.1). All entity data derived from publicly accessible government registries.
National baseline figures from Lokentra U.S. Education Sector Email Security Intelligence Dataset (March 2026). See education-dataset-paper.html for full methodology.