Skip to main content
Home
Products
Free Tools
Industries
Compare
Resources
Pricing

Public-data study, 8,000 domains, collected 4 September 2026

The State of Email Authentication, September 2026

Every adoption statistic you have read about DMARC counts a domain as protected the moment it publishes a record. We looked at what the records actually say. Among the 5,000 most-visited domains that receive mail, 84.4% publish DMARC and 65.5% enforce it. In a band of 3,000 domains ranked around 500,000, 65.2% publish and 29.5% enforce. The gap between those two numbers is where spoofing lives.

Key findings

65.5%
of the top 5,000 enforce DMARC

84.4% publish a record; 3,517 mail-receiving domains.

22.3%
of published records are p=none

The DMARC Enforcement Gap: a record that reports spoofing and blocks none of it.

29.5%
enforce in the long tail

Domains ranked 500,001 to 503,000. 65.2% publish; 54.6% of those are p=none.

3%
of SPF records break the 10-lookup limit

98 domains. Another 14.8% sit at 8 to 10 lookups.

Published is not enforced, and rank decides which you get

The table counts only domains with an MX record, because a domain that receives no mail has no reason to publish DMARC. “Fully protected” means an SPF record plus a DMARC policy of quarantine or reject applied to 100% of mail.

Tranco rank bandMail domainsSPFDMARC publishedDMARC enforcedp=noneFully protected
Top 1006595.4%89.2%73.8%15.4%73.8%
101 to 1,00062994.1%88.6%74.2%14.3%72.8%
1,001 to 5,0002,82392.8%83.4%63.4%19.9%60.6%
500,001 to 503,0002,10291.1%65.2%29.5%35.6%27.3%

DMARC policy split, top 5,000

  • p=reject40.3%
  • p=quarantine25.3%
  • p=none (reports only)18.8%
  • No DMARC15.6%

DMARC policy split, ranks 500,001 to 503,000

  • p=reject13.2%
  • p=quarantine16.3%
  • p=none (reports only)35.6%
  • No DMARC34.8%

The DMARC Enforcement Gap

We call the share of DMARC records set to p=none the DMARC Enforcement Gap. A p=none record tells every receiver: report what you see, then deliver it anyway. It is the correct first step, because turning enforcement on before you have found every legitimate sender (the CRM, the billing system, the agency) blocks your own mail. It is also where a great many domains stop. In the top 5,000 the gap is 22.3% of published records. In the long tail it is 54.6%: more than half of the domains that bothered to publish DMARC never moved past reporting.

The reporting is often not even read. 19.1% of p=none records in the top 5,000 carry no rua address, so no aggregate reports go anywhere; in the long tail it is 48.1%. Those domains are counted as “DMARC adopters” in every industry survey and are exactly as spoofable as a domain with no record.

  • Top 5,000: p=none share of published records22.3%661 of 2,969
  • Long tail: p=none share of published records54.6%749 of 1,371
  • Top 5,000: enforcing records applied to less than 100% of mail (pct<100)2.8%64 domains
  • Top 5,000: strict alignment (adkim=s or aspf=s)7.7%229 domains

SPF: nearly universal, frequently broken

93.1% of the top 5,000 mail domains publish SPF. The interesting numbers are inside the record. RFC 7208 caps evaluation at ten DNS-querying mechanisms counted through every include; past ten, a strict receiver returns permerror and the record protects nothing. We expanded every chain.

The all mechanism, top 5,000

-all rejects unlisted senders; ~all only marks them; ?all and a missing all mean nothing is enforced.

  • -all (hard fail)47.9%
  • ~all (soft fail)45.4%
  • ?all (neutral)2.3%
  • no all term4.3%

The all mechanism, long tail

  • -all (hard fail)34.3%
  • ~all (soft fail)59.4%
  • ?all (neutral)2.3%
  • no all term3.9%

DNS lookups per SPF record, top 5,000

Counted recursively through include and redirect. Amber columns are over the limit of ten.

7.6%0
16.7%1
11.3%2
10.6%3
8.8%4
9.4%5
9.3%6
8.4%7
5.8%8
4.8%9
4.2%10
3%11+
98 records (3%) exceed ten lookups; 486 (14.8%) sit at eight to ten. 20 domains publish more than one SPF record, which RFC 7208 treats as a permanent error.

DKIM, BIMI, MTA-STS and TLS-RPT

DKIM has no discovery mechanism: a key lives under a selector name only the sender knows. We probed eight common selectors (google, selector1, selector2, k1, s1, default, dkim, mail), so the DKIM figure is a floor, not adoption. The other three records are cheap to publish and rarely are.

64.3%
publish a DKIM key under a common selector

Top 5,000. Long tail: 53.5%. A floor, see method.

15.7%
publish BIMI

Brand logo in the inbox; requires enforced DMARC. Long tail: 1.9%.

3.9%
publish MTA-STS

Forces TLS on inbound mail. Long tail: 1%.

4.7%
publish TLS-RPT

Reports on failed TLS delivery. Long tail: 1.2%.

Who enforces: by mailbox provider

The MX record names the provider or security gateway in front of the mailbox. Providers with fewer than 40 domains in a band are left out so no percentage rests on a handful of domains. “Self-hosted or other” is every MX host we could not attribute.

Top 5,000

ProviderDomainsDMARC publishedDMARC enforced
Google Workspace1,20090.3%73.8%
Self-hosted or other1,04577.6%55.6%
Microsoft 36551492.2%72%
Proofpoint29996.7%81.9%
Mimecast7893.6%79.5%
Amazon SES / WorkMail5651.8%39.3%
Yandex4379.1%41.9%

Ranks 500,001 to 503,000

ProviderDomainsDMARC publishedDMARC enforced
Self-hosted or other95257%22.4%
Google Workspace41975.2%32%
Microsoft 36535483.1%48.6%
Cloudflare Email Routing4641.3%10.9%
Yandex4535.6%22.2%

Mailbox provider share, top 5,000 mail domains

  • Google Workspace34.1%1,200 domains
  • Self-hosted or other29.7%1,045 domains
  • Microsoft 36514.6%514 domains
  • Proofpoint8.5%299 domains
  • Mimecast2.2%78 domains
  • Amazon SES / WorkMail1.6%56 domains
  • Yandex1.2%43 domains
  • Cloudflare Email Routing1%35 domains

What this means if you send email

Screenshot of the free 1Lookup DMARC checker showing an example result for google.com: policy reject, what that means, and the aggregate reports address
The free DMARC checker on this site reads the same record the census read, live, and says in one line whether the domain enforces. Every domain in the census can be re-checked with it.
  1. Check whether you are in the gap. Run your domain through the free DMARC checker. If the policy reads p=none and you have been on it for more than a quarter, you have collected enough reports to move to p=quarantine with pct=10 and step up from there.
  2. Count your SPF lookups, not your SPF terms. The free SPF checker expands every include and reports the total against the limit of ten. Every SaaS vendor you add to the record costs one or more lookups; the 14.8% of top domains at eight to ten lookups are one signature away from breaking.
  3. The recipient side is a data-quality problem too. A cold list full of domains with no MX, a null MX or an obvious parking host bounces before authentication ever matters. The free MX lookup shows a domain's mail route; the email validation API runs the full Email Verification Ladder (syntax, domain, mailbox, risk) on a whole list.

Questions this study answers

What percentage of domains use DMARC in 2026?
Among the 5,000 most-visited domains that receive mail (3,517 domains with an MX record), 84.4% publish a DMARC record. Among a band of 3,000 domains ranked around 500,000, 65.2% do. Measured by 1Lookup over public DNS on 4 September 2026.
What percentage of domains actually enforce DMARC?
65.5% of the top 5,000 mail-receiving domains set p=quarantine or p=reject, the two policies that block spoofed mail. 18.8% publish a record with p=none, which only reports. In the long-tail band, enforcement falls to 29.5%.
Is DMARC p=none enough?
No. p=none asks receivers to send reports and to deliver spoofed mail anyway. It is the right first step while you find every legitimate sender, but a domain that stays on p=none is exactly as spoofable as one with no record. 22.3% of the DMARC records in the top 5,000 are still p=none, and 19.1% of those do not even name a reporting address, so nobody is reading the reports.
How many SPF records exceed the 10 DNS lookup limit?
3% of SPF records in the top 5,000 (98 domains) resolve to more than ten DNS-querying mechanisms once every include is expanded, which makes the record invalid at receivers that apply RFC 7208 strictly. A further 14.8% sit at eight to ten lookups, one added vendor away from the same failure.
How was this measured?
A script queried public DNS over DNS-over-HTTPS for every domain in the Tranco ranking's top 5,000 and ranks 500,001 to 503,000: MX, the SPF TXT record and every include it references, the _dmarc TXT record, eight common DKIM selectors, and the BIMI, MTA-STS and TLS-RPT records. No 1Lookup credits were spent and no private data was touched. The script and the per-domain CSV are published with the report.