TheDMARCEnforcementGap:What8,000DomainsToldUs
We checked the DMARC, SPF and DKIM records of 8,000 domains. 84% of the top 5,000 publish DMARC, 66% enforce it, and the long tail enforces at 30%.
Robby Frank
CEO & Founder
Every DMARC adoption statistic you have read counts a domain as protected the moment it publishes a record. We checked what the records actually say, on 8,000 domains, and the number that matters is not adoption. It is enforcement. Among the 5,000 most-visited domains that receive mail, 84.4% publish DMARC and 65.5% enforce it. In a band of 3,000 domains ranked around 500,000, 65.2% publish and 29.5% enforce. Every domain in the gap between those two figures is exactly as spoofable as a domain with no record at all.
This post is the short version. The full study, with every chart, the per-domain CSV and the script that collected it, is at The State of Email Authentication, September 2026.
About the data: the study was run by 1Lookup.io, the data verification platform behind this site. 1Lookup is part of the Momentum Labs group of companies and is the data partner for its sister brands (Prymatica, Emailchaser, VoiceDrop and ExpressNumber), which run their own verification through it.
What we measured, and how
On 4 September 2026 a script queried public DNS for every domain in the Tranco top-sites ranking's first 5,000 places, plus ranks 500,001 to 503,000 as a long-tail comparison. For each domain it read the MX record, the SPF record with every include expanded, the _dmarc record, eight common DKIM selectors, and the BIMI, MTA-STS and TLS-RPT records. The queries went over DNS-over-HTTPS to Cloudflare and Google, the same resolvers our free DMARC checker uses. No 1Lookup credits were spent and nothing private was touched.
Two denominators matter. Publication and enforcement rates below are shares of domains that receive mail (at least one MX host), because a CDN or an asset host has no reason to publish DMARC. Figures about what is inside a record are shares of the domains that publish that record. 33 domains whose lookups errored are excluded from everything.
Published is not enforced
A DMARC record carries one of three policies. p=none asks receivers to report what they see and deliver the mail anyway. p=quarantine sends failing mail to spam. p=reject refuses it. Only the last two stop anyone sending mail in your name. Here is how the sample splits, by traffic rank:
| Tranco rank band | Mail-receiving domains | DMARC published | DMARC enforced | Still p=none | Fully protected |
|---|---|---|---|---|---|
| 1 to 100 | 65 | 89.2% | 73.8% | 15.4% | 73.8% |
| 101 to 1,000 | 629 | 88.6% | 74.2% | 14.3% | 72.8% |
| 1,001 to 5,000 | 2,823 | 83.4% | 63.4% | 19.9% | 60.6% |
| 500,001 to 503,000 | 2,102 | 65.2% | 29.5% | 35.6% | 27.3% |
"Fully protected" means an SPF record plus a DMARC policy of quarantine or reject applied to 100% of mail. Read the last row twice. In the long tail, more domains sit on p=none (35.6%) than enforce (29.5%).
The DMARC Enforcement Gap
We call the share of DMARC records that stay on p=none the DMARC Enforcement Gap. In the top 5,000 it is 22.3% of published records. In the long tail it is 54.6%: more than half of the domains that bothered to publish DMARC never moved past reporting.
The gap is not laziness, mostly. p=none is the correct first step. If you switch enforcement on before you have found every system that legitimately sends as your domain (the CRM, the billing platform, the marketing agency, the ticketing tool), you block your own mail. So the playbook says: publish p=none, collect the aggregate reports for a few weeks, fix alignment for every sender you find, then step up to p=quarantine with pct=10 and climb from there.
Most domains publish step one and stop. Then they show up as "DMARC adopters" in every industry survey.
Reports nobody reads
p=none only does anything if somebody reads the reports it generates, and reports only go somewhere if the record names a rua address. In the top 5,000, 19.1% of p=none records have no rua at all. In the long tail it is 48.1%. Those domains asked the world to report spoofing to nobody.
Of the domains that do enforce, 2.8% in the top 5,000 apply the policy to less than 100% of mail (pct under 100), which is the climbing phase and fine. Strict alignment (adkim=s or aspf=s) is rare at 7.7%; relaxed alignment is the default and the study does not treat it as a fault.
SPF is everywhere and quietly broken
93.1% of the top 5,000 mail domains publish SPF. The interesting numbers are inside the record.
RFC 7208 caps SPF evaluation at ten DNS-querying mechanisms, counted through every include. Past ten, a strict receiver returns a permanent error and the record protects nothing. We expanded every chain: 3.0% of top-5,000 SPF records (98 domains) are over the limit today, and another 14.8% sit at eight to ten lookups, one newly added SaaS vendor away from the same failure. 0.6% publish more than one SPF record, which the RFC also treats as a permanent error.
The all mechanism tells the receiver what to do with a sender the record does not list. In the top 5,000, 47.9% of records end in -all (reject) and 45.4% in ~all (soft fail, which most receivers treat as "deliver, maybe mark"). In the long tail the picture flips: 34.3% hard fail, 59.4% soft fail. A domain on ~all with DMARC on p=none has, in practice, opted out of authentication while publishing two records that look like it opted in.
Your mailbox provider predicts your policy
The MX record names who runs the mailbox, and that turns out to predict enforcement better than rank does. In the top 5,000:
| Provider (from MX) | Domains | DMARC published | DMARC enforced |
|---|---|---|---|
| Proofpoint | 299 | 96.7% | 81.9% |
| Mimecast | 78 | 93.6% | 79.5% |
| Google Workspace | 1,200 | 90.3% | 73.8% |
| Microsoft 365 | 514 | 92.2% | 72.0% |
| Self-hosted or other | 1,045 | 77.6% | 55.6% |
| Amazon SES / WorkMail | 56 | 51.8% | 39.3% |
The gateways win because a security vendor's onboarding walks the customer to enforcement. Self-hosted mail trails by 20 points. In the long tail the same ordering holds at lower levels: Microsoft 365 domains enforce at 48.6%, Google Workspace at 32.0%, self-hosted at 22.4%.
The other three records almost nobody publishes
DKIM has no discovery mechanism, so we probed eight common selectors (google, selector1, selector2, k1, s1, default, dkim, mail). That found a key on 64.3% of top-5,000 mail domains and 53.5% of the long tail. Treat it as a floor, not adoption. BIMI, the record that puts a brand logo in the inbox and requires enforced DMARC first, is on 15.7% of the top 5,000 and 1.9% of the long tail. MTA-STS (3.9% and 1.0%) and TLS-RPT (4.7% and 1.2%) are close to nonexistent outside the top 100.
What to do about it
- Find out whether you are in the gap. Run your domain through the free DMARC checker. If the policy reads
p=noneand it has for more than a quarter, you have the reports you need. Move top=quarantine; pct=10, watch a week, then raisepct.

- Count lookups, not terms. The free SPF record checker expands every include and reports the total against the limit of ten. If you are at eight or more, flatten a vendor before adding the next one.

- Treat the receiving side as a data-quality problem. Authentication decides whether your mail is trusted. Whether it can be delivered at all is decided before that, by the list. A domain with no MX, a null MX or a parked host bounces regardless of how well you signed the message. The free MX lookup shows one domain's route; the email validation API runs the whole Email Verification Ladder, syntax, domain, mailbox and risk, across a list.
Frequently asked questions
What percentage of domains use DMARC in 2026?
In this census, 84.4% of the 3,517 top-5,000 domains that receive mail publish a DMARC record, and 65.2% of the 2,102 long-tail domains do.
What percentage of domains enforce DMARC?
65.5% of the top 5,000 mail domains set p=quarantine or p=reject. In the long tail it is 29.5%.
Is DMARC p=none enough?
No. It reports spoofing and blocks none of it. It is the right first step and the wrong place to stop; 22.3% of top-5,000 DMARC records and 54.6% of long-tail records are still there.
How many SPF records exceed the ten-lookup limit?
3.0% of top-5,000 SPF records, 98 domains, resolve to more than ten DNS lookups once every include is expanded. A further 14.8% sit at eight to ten.
Can I check the numbers?
Yes. The per-domain CSV has one row for each of the 8,000 domains with every raw fact, and the collection script is in the 1Lookup marketing repository. Licence CC BY 4.0; cite "1Lookup email authentication census, September 2026".
Meet the Expert Behind the Insights
Real-world experience from building and scaling B2B SaaS companies

Robby Frank
Head of Growth at 1Lookup
"Calm down, it's just life"
About Robby
Self-taught entrepreneur and technical leader with 12+ years building profitable B2B SaaS companies. Specializes in rapid product development and growth marketing with 1,000+ outreach campaigns executed across industries.
Author of "Evolution of a Maniac" and advocate for practical, results-driven business strategies that prioritize shipping over perfection.