Skip to Main Content
Research dossier · 2026
Published researchReleased September 1, 2026

Top 1,000 ecommerce websites DMARC benchmark 2026

Across 998 of 999 unique domains from 1,000 ranked ecommerce entries, 95.5% published valid DMARC and 79.4% of publishers enforced quarantine or rejection. The 323-domain U.S. segment measured 96.0% adoption and 82.9% enforcement.

Why this matters

This benchmark measures public authentication records, not inbox placement: an enforcing DMARC policy gives participating receivers more direction when a forged exact-domain message fails aligned authentication.

95.5%

DMARC adoption

953 of 998

79.4%

Enforcement among publishers

757 of 953

8.8%

Publishers without aggregate reporting

84 of 953

3.8%

SPF recursive lookup failures

37 of 962

KEY FINDINGS

DMARC is widespread across leading ecommerce domains, but enforcement is not universal

The source ranking contained 1,000 entries. One duplicated DNS target was counted once, leaving 999 unique domains; 998 returned usable observations. Country labels come from the source, and only groups with at least 30 observed domains are published.

WORLDWIDE COHORT

95.5% published DMARC; 79.4% of publishers enforced

953/998 observed domains published valid DMARC. 757/953 publishers requested quarantine or rejection.

UNITED STATES

96.0% adoption and 82.9% enforcement

All 323 source-classified U.S. domains were observed. 310/323 published valid DMARC, and 257/310 publishers enforced it.

OPERATING GAPS

8.8% of publishers omitted aggregate reporting

That was 84/953 DMARC publishers. SPF recursive lookup failures affected 37/962 SPF publishers.

These figures describe public DNS configuration at one scan time. They do not measure inbox placement, sender reputation, phishing, compromise, internal controls or business quality, and Palisade does not publish named source rows for this study.

Why this matters

What is the risk when DMARC is missing?

Ecommerce email often carries order, account, loyalty, delivery and payment messages that customers are primed to trust. A missing or monitoring-only policy leaves less protection at participating receivers when a forged message using the site’s visible From domain fails aligned authentication.

Learn how DMARC evaluates a message →
Risk context

01 · DOMAIN IDENTITY

The visible From address can be forged

An attacker can send a message that displays the organization's exact domain in the From line. Without a valid DMARC record, participating receivers have no DMARC handling request from that domain owner when aligned SPF and DKIM fail.

02 · PRACTICAL HARM

Order and account messages can be impersonated

A forged shipping update, account-security alert, loyalty message or invoice can be used to steal credentials, payment details or trust. Public DNS state does not show that any ecommerce business experienced fraud or that a message reached an inbox.

Three different DNS states

No valid DMARC
No domain-owner DMARC policy. Aggregate reports cannot be requested through that record.
DMARC at p=none
Monitoring only. Reports may be collected, but the owner requests no DMARC-based quarantine or rejection.
p=quarantine or reject
The owner asks receivers to act on messages that fail aligned authentication. Receiver behavior can still vary.

Risk, not incident evidence: this DNS state does not prove spoofing, fraud, compromise or weak internal controls. DMARC also does not stop lookalike domains, abuse of a compromised legitimate account or every phishing technique.

Scope

What this study measures

  • 01The complete public Top1000.com ecommerce ranking retrieved on September 1, 2026: 1,000 ranked entries resolving to 999 unique DNS targets.
  • 02A separately reported United States segment containing 323 unique source-classified domains.
  • 03Public DMARC, SPF, default-selector BIMI and MX records observed in one recorded scan window.
Research questions

Questions the data answers

  1. 01How many ranked ecommerce domains publish valid DMARC, and how many publishers enforce quarantine or rejection?
  2. 02How does the 323-domain U.S. segment compare with other sufficiently large source-country groups?
  3. 03How often do DMARC publishers omit aggregate reporting, and how often do SPF records fail the recursive lookup limit?
  4. 04Which observed MX operator groups appear across the cohort, without treating provider choice as causal?
Release record

How this research became citable

  1. September 1, 2026

    Public ranking retrieved, checksummed and deduplicated

  2. September 1, 2026

    Public DNS scan and aggregate review completed

  3. September 1, 2026

    Evidence package, charts and report released

    The release passed the stated evidence and review gates.

Delivery package
What is available
  • Worldwide and eligible source-country aggregate tables with every numerator and denominator exposed.
  • A dedicated 323-domain U.S. segment and aggregate CSV/JSON downloads.
  • Reusable SVG and PNG charts with no source-ranking or named-domain redistribution.
  • A methodology and limitations record separating DNS observations from deliverability or incident claims.

Media posture

Share the methodology and aggregate evidence with specialist editors; do not redistribute the underlying ranking or pitch named domains as failures.

Published comparisons

How the observed groups compare

Groups below the 30-domain threshold are suppressed. Every visible percentage includes its numerator and denominator.

GroupObservedDMARCEnforcementNo reportingSPF lookup failureBIMI among enforcing
United States32396% (310/323)82.9% (257/310)8.1% (25/310)5.4% (17/313)40.1% (103/257)
United Kingdom7897.4% (76/78)86.8% (66/76)3.9% (3/76)2.6% (2/77)40.9% (27/66)
Germany5098% (49/50)75.5% (37/49)4.1% (2/49)2.1% (1/48)48.6% (18/37)
Japan5094% (47/50)68.1% (32/47)12.8% (6/47)0% (0/46)46.9% (15/32)
France3992.3% (36/39)77.8% (28/36)2.8% (1/36)0% (0/37)28.6% (8/28)
India3390.9% (30/33)86.7% (26/30)10% (3/30)13.3% (4/30)19.2% (5/26)
Australia31100% (31/31)96.8% (30/31)3.2% (1/31)3.2% (1/31)33.3% (10/30)
For editors and analysts

Reusable charts

SVG and PNG versions are licensed CC BY 4.0.

Citation & media kit

Use this research

The aggregate findings and charts are free to quote, republish and build on under CC BY 4.0. Attribute Palisade and link to this report so readers can inspect the methodology and denominators.

Suggested citation
Copy this text when quoting or republishing the dataset.
Palisade. “Top 1,000 ecommerce websites DMARC benchmark 2026.” 2026-09-01. https://www.palisade.email/research/global-top-1000-ecommerce-email-authentication-2026
Methodology

How we measured this

  1. 1.Retrieve the complete public ranking, decode its published website destinations and record a SHA-256 checksum without redistributing the source ranking.
  2. 2.Normalize each source destination to its direct DNS hostname. Count the single duplicated source target once, producing 999 unique domains from 1,000 ranked entries.
  3. 3.Resolve DMARC, SPF, default-selector BIMI and MX through recorded public resolvers. Keep resolver failures visible and out of percentage denominators.
  4. 4.Publish derived aggregate statistics only. Country labels are the source ranking’s classifications, not independent findings about corporate headquarters or customer geography.

Measurement record

Corpus and observations
998 observed of 999
Scan window
Sep 1, 2026, 04:30 PM UTC to Sep 1, 2026, 04:30 PM UTC
Scanner version
2.0.0
MX classifier version
2026-08-14.2

Pinned source snapshot

cfebb6c9bb732acc6c378ad54a50abb494920b6083c30369c325891dac1dab52

Limitations

  • The source is a traffic-oriented ecommerce-website ranking, not a company-revenue ranking or census of every online retailer.
  • Regional storefronts may appear as separate source entries; one duplicated DNS target was deduplicated before scanning.
  • Source country labels are not independently verified corporate domicile, ownership or sales-market classifications.
  • Public DNS configuration does not measure inbox placement, sender reputation, phishing incidence, compromise, internal controls or business quality.
Source record

Trace the evidence

Top 1000 Ecommerce Websites

Worldwide traffic-oriented ecommerce ranking. Palisade cites the source and publishes only derived aggregate DNS statistics.

Top1000 methodology

The publisher’s description of its multi-source ranking and index methodology.

Top1000 legal terms

The source publisher’s reuse terms; Palisade therefore publishes no copied ranking or named source rows.

RFC 9989 (DMARC)

Current DMARC discovery and policy semantics used by the DNS parser.

RFC 9990 (DMARC aggregate reporting)

Current DMARC aggregate-reporting semantics used to classify published reporting destinations.

Publication policy

Publish only derived aggregate statistics. Do not republish the source ranking, source positions, company names or named DNS observations. Country groups below 30 observed domains remain suppressed.