Public-data study, 8,000 domains, collected 4 September 2026
The State of Email Authentication, September 2026
Every adoption statistic you have read about DMARC counts a domain as protected the moment it publishes a record. We looked at what the records actually say. Among the 5,000 most-visited domains that receive mail, 84.4% publish DMARC and 65.5% enforce it. In a band of 3,000 domains ranked around 500,000, 65.2% publish and 29.5% enforce. The gap between those two numbers is where spoofing lives.
Key findings
- 65.5%
- of the top 5,000 enforce DMARC
- 22.3%
- of published records are p=none
- 29.5%
- enforce in the long tail
- 3%
- of SPF records break the 10-lookup limit
84.4% publish a record; 3,517 mail-receiving domains.
The DMARC Enforcement Gap: a record that reports spoofing and blocks none of it.
Domains ranked 500,001 to 503,000. 65.2% publish; 54.6% of those are p=none.
98 domains. Another 14.8% sit at 8 to 10 lookups.
Published is not enforced, and rank decides which you get
The table counts only domains with an MX record, because a domain that receives no mail has no reason to publish DMARC. “Fully protected” means an SPF record plus a DMARC policy of quarantine or reject applied to 100% of mail.
| Tranco rank band | Mail domains | SPF | DMARC published | DMARC enforced | p=none | Fully protected |
|---|---|---|---|---|---|---|
| Top 100 | 65 | 95.4% | 89.2% | 73.8% | 15.4% | 73.8% |
| 101 to 1,000 | 629 | 94.1% | 88.6% | 74.2% | 14.3% | 72.8% |
| 1,001 to 5,000 | 2,823 | 92.8% | 83.4% | 63.4% | 19.9% | 60.6% |
| 500,001 to 503,000 | 2,102 | 91.1% | 65.2% | 29.5% | 35.6% | 27.3% |
DMARC policy split, top 5,000
- p=reject40.3%
- p=quarantine25.3%
- p=none (reports only)18.8%
- No DMARC15.6%
DMARC policy split, ranks 500,001 to 503,000
- p=reject13.2%
- p=quarantine16.3%
- p=none (reports only)35.6%
- No DMARC34.8%
The DMARC Enforcement Gap
We call the share of DMARC records set to p=none the DMARC Enforcement Gap. A p=none record tells every receiver: report what you see, then deliver it anyway. It is the correct first step, because turning enforcement on before you have found every legitimate sender (the CRM, the billing system, the agency) blocks your own mail. It is also where a great many domains stop. In the top 5,000 the gap is 22.3% of published records. In the long tail it is 54.6%: more than half of the domains that bothered to publish DMARC never moved past reporting.
The reporting is often not even read. 19.1% of p=none records in the top 5,000 carry no rua address, so no aggregate reports go anywhere; in the long tail it is 48.1%. Those domains are counted as “DMARC adopters” in every industry survey and are exactly as spoofable as a domain with no record.
- Top 5,000: p=none share of published records22.3%661 of 2,969
- Long tail: p=none share of published records54.6%749 of 1,371
- Top 5,000: enforcing records applied to less than 100% of mail (pct<100)2.8%64 domains
- Top 5,000: strict alignment (adkim=s or aspf=s)7.7%229 domains
SPF: nearly universal, frequently broken
93.1% of the top 5,000 mail domains publish SPF. The interesting numbers are inside the record. RFC 7208 caps evaluation at ten DNS-querying mechanisms counted through every include; past ten, a strict receiver returns permerror and the record protects nothing. We expanded every chain.
The all mechanism, top 5,000
-all rejects unlisted senders; ~all only marks them; ?all and a missing all mean nothing is enforced.
- -all (hard fail)47.9%
- ~all (soft fail)45.4%
- ?all (neutral)2.3%
- no all term4.3%
The all mechanism, long tail
- -all (hard fail)34.3%
- ~all (soft fail)59.4%
- ?all (neutral)2.3%
- no all term3.9%
DNS lookups per SPF record, top 5,000
Counted recursively through include and redirect. Amber columns are over the limit of ten.
DKIM, BIMI, MTA-STS and TLS-RPT
DKIM has no discovery mechanism: a key lives under a selector name only the sender knows. We probed eight common selectors (google, selector1, selector2, k1, s1, default, dkim, mail), so the DKIM figure is a floor, not adoption. The other three records are cheap to publish and rarely are.
- 64.3%
- publish a DKIM key under a common selector
- 15.7%
- publish BIMI
- 3.9%
- publish MTA-STS
- 4.7%
- publish TLS-RPT
Top 5,000. Long tail: 53.5%. A floor, see method.
Brand logo in the inbox; requires enforced DMARC. Long tail: 1.9%.
Forces TLS on inbound mail. Long tail: 1%.
Reports on failed TLS delivery. Long tail: 1.2%.
Who enforces: by mailbox provider
The MX record names the provider or security gateway in front of the mailbox. Providers with fewer than 40 domains in a band are left out so no percentage rests on a handful of domains. “Self-hosted or other” is every MX host we could not attribute.
Top 5,000
| Provider | Domains | DMARC published | DMARC enforced |
|---|---|---|---|
| Google Workspace | 1,200 | 90.3% | 73.8% |
| Self-hosted or other | 1,045 | 77.6% | 55.6% |
| Microsoft 365 | 514 | 92.2% | 72% |
| Proofpoint | 299 | 96.7% | 81.9% |
| Mimecast | 78 | 93.6% | 79.5% |
| Amazon SES / WorkMail | 56 | 51.8% | 39.3% |
| Yandex | 43 | 79.1% | 41.9% |
Ranks 500,001 to 503,000
| Provider | Domains | DMARC published | DMARC enforced |
|---|---|---|---|
| Self-hosted or other | 952 | 57% | 22.4% |
| Google Workspace | 419 | 75.2% | 32% |
| Microsoft 365 | 354 | 83.1% | 48.6% |
| Cloudflare Email Routing | 46 | 41.3% | 10.9% |
| Yandex | 45 | 35.6% | 22.2% |
Mailbox provider share, top 5,000 mail domains
- Google Workspace34.1%1,200 domains
- Self-hosted or other29.7%1,045 domains
- Microsoft 36514.6%514 domains
- Proofpoint8.5%299 domains
- Mimecast2.2%78 domains
- Amazon SES / WorkMail1.6%56 domains
- Yandex1.2%43 domains
- Cloudflare Email Routing1%35 domains
What this means if you send email

- Check whether you are in the gap. Run your domain through the free DMARC checker. If the policy reads p=none and you have been on it for more than a quarter, you have collected enough reports to move to p=quarantine with pct=10 and step up from there.
- Count your SPF lookups, not your SPF terms. The free SPF checker expands every include and reports the total against the limit of ten. Every SaaS vendor you add to the record costs one or more lookups; the 14.8% of top domains at eight to ten lookups are one signature away from breaking.
- The recipient side is a data-quality problem too. A cold list full of domains with no MX, a null MX or an obvious parking host bounces before authentication ever matters. The free MX lookup shows a domain's mail route; the email validation API runs the full Email Verification Ladder (syntax, domain, mailbox, risk) on a whole list.
Questions this study answers
- What percentage of domains use DMARC in 2026?
- Among the 5,000 most-visited domains that receive mail (3,517 domains with an MX record), 84.4% publish a DMARC record. Among a band of 3,000 domains ranked around 500,000, 65.2% do. Measured by 1Lookup over public DNS on 4 September 2026.
- What percentage of domains actually enforce DMARC?
- 65.5% of the top 5,000 mail-receiving domains set p=quarantine or p=reject, the two policies that block spoofed mail. 18.8% publish a record with p=none, which only reports. In the long-tail band, enforcement falls to 29.5%.
- Is DMARC p=none enough?
- No. p=none asks receivers to send reports and to deliver spoofed mail anyway. It is the right first step while you find every legitimate sender, but a domain that stays on p=none is exactly as spoofable as one with no record. 22.3% of the DMARC records in the top 5,000 are still p=none, and 19.1% of those do not even name a reporting address, so nobody is reading the reports.
- How many SPF records exceed the 10 DNS lookup limit?
- 3% of SPF records in the top 5,000 (98 domains) resolve to more than ten DNS-querying mechanisms once every include is expanded, which makes the record invalid at receivers that apply RFC 7208 strictly. A further 14.8% sit at eight to ten lookups, one added vendor away from the same failure.
- How was this measured?
- A script queried public DNS over DNS-over-HTTPS for every domain in the Tranco ranking's top 5,000 and ranks 500,001 to 503,000: MX, the SPF TXT record and every include it references, the _dmarc TXT record, eight common DKIM selectors, and the BIMI, MTA-STS and TLS-RPT records. No 1Lookup credits were spent and no private data was touched. The script and the per-domain CSV are published with the report.