Back to news
Cybersecurity Alert
June 5, 2026 by EmailMeNow IT Consulting

Cybersecurity Audit of Major U.S. Tax Preparers in 2026

Independent audits of the largest U.S. tax preparation brands — H&R Block, Jackson Hewitt, Intuit, Liberty Tax, and more — reveal a wide range of cybersecurity results. Weak email authentication is a direct path to refund fraud and preparer impersonation.

Tax PreparersIRSFTC SafeguardsTax SeasonEmail Security
Digital audit dashboard with a United States map showing cybersecurity scores of tax preparers

An independent cybersecurity review across the largest tax preparers in the United States — national retail tax chains, online DIY platforms, and professional tax-software vendors including H&R Block, Intuit, and Jackson Hewitt — reveals a surprisingly wide range of results. These organizations handle sensitive customer and financial data at national scale, yet several show the same email-authentication gaps found at much smaller regional institutions.

Using data from audit.emailmenow.com, we evaluated each preparer’s primary domain across email, website, and network security — including SPF, DKIM, DMARC, MTA-STS/TLS, and security headers.

In this national audit, scores ranged from 76% to 30%7 of 17 (41%) scored below 60%.

Cybersecurity Scores of Tax Preparers

Overall compliance scores from audit.emailmenow.com. Re-run any domain at the link to verify.

RankTax PreparerDomainOverall ScorePerformance Level
1FreeTaxUSAfreetaxusa.com76%Strong
2TaxSlayertaxslayer.com73%Strong
3H&R Blockhrblock.com70%Strong
3Liberty Taxlibertytax.com70%Strong
3ezTaxReturneztaxreturn.com70%Strong
3Intuitintuit.com70%Strong
7Sprintaxsprintax.com64%Above Average
8TaxActtaxact.com61%Above Average
9Credit Karma Taxcreditkarma.com60%Above Average
9Cash App Taxescash.app60%Above Average
11Drake Softwaredrakesoftware.com55%Average
12Wolters Kluwerwolterskluwer.com54%Below Average
12Ace Cash Expressacecashexpress.com54%Below Average
14Jackson Hewittjacksonhewitt.com50%Below Average
15ATAXatax.com44%Weak
16Thomson Reuters Taxtax.thomsonreuters.com35%Weak
17OLT Prooltpro.com30%Weak

What the Results Reveal

  • Scores range from 76% (FreeTaxUSA) down to 30% (OLT Pro) — 6 brands reach a strong (70%+) posture.
  • Online-first brands lead: FreeTaxUSA (76%) and TaxSlayer (73%) outscore several legacy retail chains.
  • OLT Pro (30%) and Thomson Reuters Tax (35%) sit at the bottom — well below H&R Block (70%), Intuit (70%), and Liberty Tax (70%).
  • Without an enforced DMARC policy, criminals can spoof a preparer’s domain to phish taxpayers about refunds, stimulus payments, or “account verification.”

Why This Matters for Tax Preparers

Paid and DIY tax preparers are bound by IRS e-file and Publication 4557 safeguards, FTC Safeguards Rule requirements, and state consumer-protection oversight. Email authentication (SPF, DKIM, and an enforced DMARC policy) is the single highest-impact control against refund fraud, preparer impersonation, and W-2 phishing during filing season.

Check any preparer’s posture at audit.emailmenow.com/?industry=cpa-firms.

See also — state audits

Recommendations

  • Enforce DMARC (p=reject), strict SPF (-all), and DKIM signing.
  • Add MTA-STS and website security headers.
  • Adopt verified call-back procedures for any change to payment or wiring instructions, and train customer-facing staff.

Protect your organization. Run a free Instant Cybersecurity Audit at audit.emailmenow.com/?industry=cpa-firms.

Contact EmailMeNow IT Consulting for help with tax-season email security hardening.


Source & methodology: Overall compliance scores from the free scan at audit.emailmenow.com — each domain checked for email authentication (SPF, DKIM, DMARC), transport security (MTA-STS/TLS), website security headers, and network security. Re-run any domain at the link to verify.