Skip to Main Content

PALISADE RESEARCH / 2026

Evidence for the email infrastructure people rely on.

Reproducible DNS research on DMARC, SPF, BIMI and the infrastructure behind them. Built for people who need figures they can inspect, cite and act on.

WHY DMARC MATTERSWithout a valid, enforcing DMARC policy, participating receivers have less domain-owner direction when a forged message uses an organization's exact From domain and fails aligned authentication.

RESEARCH PROGRAM

8
published reports
1
study in flight
100%
methods disclosed

RESEARCH LIBRARY

Published work & upcoming releases

Every release includes its methodology, limitations, citation text and aggregate data.

THE 2026 PROGRAM

Four studies, one shared standard

Published reports are citation-ready; upcoming pages stay out of search until their evidence and reviews are complete.

PublishedAugust 14, 2026

Observed MX provider benchmark 2026

A fresh scan of the pinned Tranco top 100,000 compares Microsoft 365, Google Workspace, recognized gateways and other observed MX operators without treating provider choice as a cause of better security.

99,300 domains observed

Read the report
PublishedAugust 14, 2026

Canada and Quebec email-authentication benchmark 2026

A DNS measurement of 1,030 sourced Canadian organization-domain pairs with provincial and sector breakdowns, built from official organization lists rather than assuming every .ca domain represents a Canadian organization.

1,028 domains observed

Read the report
In productionOctober 13, 2026

U.S. election email security tracker 2026

A responsibly disclosed measurement of public email-authentication records: not a vulnerability ranking, compromise assessment or claim about election integrity.

Election-security, state-government and cybersecurity publications

View the research plan
PublishedAugust 14, 2026

North American MSP email-authentication benchmark 2026

An aggregate benchmark of MSP organizational domains, designed to inform channel operations without ranking named companies or making claims about client environments.

566 domains observed

Read the report
PublishedSeptember 1, 2026

Top 1,000 ecommerce websites DMARC benchmark 2026

A public-DNS measurement of 999 unique domains from 1,000 ranked ecommerce entries, including a 323-domain U.S. segment. It measures published authentication records, not inbox placement, compromise or business quality.

998 domains observed

Read the report
PublishedAugust 21, 2026

DMARC adoption in the NRF Top 100 U.S. retailers, 2026

A public-DNS benchmark of the complete NRF 2026 Top 100 Retailers population. Every row pairs one ranked U.S. retailer with a documented customer-facing domain; it does not identify every brand or sending domain operated by that business.

100 domains observed

Read the report
PublishedAugust 17, 2026

Top 1,000 global web brands email-authentication benchmark 2026

A public-DNS benchmark of the current Tranco top 1,000 domains. Every row is a direct source-domain observation, not an inferred company or brand-domain match.

999 domains observed

Read the report

SECTOR DEEP DIVES

Focused findings from the shared datasets

These briefs clear the same observation, sourcing, findings and outreach gates as the main reports.

Why this matters

What is the risk when DMARC is missing?

For any organization, the practical issue is control of the identity people see in the From line. A missing or monitoring-only DMARC policy leaves less protection at participating receiving mail systems when a message fails aligned authentication.

Learn how DMARC evaluates a message →
Risk context

01 · DOMAIN IDENTITY

The visible From address can be forged

An attacker can send a message that displays the organization's exact domain in the From line. Without a valid DMARC record, participating receivers have no DMARC handling request from that domain owner when aligned SPF and DKIM fail.

02 · PRACTICAL HARM

Fraud becomes easier to believe

A forged message can imitate a familiar executive, billing team, support desk or customer-service address. That can make payment redirection, credential theft and malicious links more convincing to employees, customers and partners.

Risk, not incident evidence: this DNS state does not prove spoofing, fraud, compromise or weak internal controls. DMARC also does not stop lookalike domains, abuse of a compromised legitimate account or every phishing technique.