WORLDWIDE COHORT
95.5% published DMARC; 79.4% of publishers enforced
953/998 observed domains published valid DMARC. 757/953 publishers requested quarantine or rejection.

Across 998 of 999 unique domains from 1,000 ranked ecommerce entries, 95.5% published valid DMARC and 79.4% of publishers enforced quarantine or rejection. The 323-domain U.S. segment measured 96.0% adoption and 82.9% enforcement.
Why this matters
This benchmark measures public authentication records, not inbox placement: an enforcing DMARC policy gives participating receivers more direction when a forged exact-domain message fails aligned authentication.
95.5%
DMARC adoption
953 of 998
79.4%
Enforcement among publishers
757 of 953
8.8%
Publishers without aggregate reporting
84 of 953
3.8%
SPF recursive lookup failures
37 of 962
KEY FINDINGS
The source ranking contained 1,000 entries. One duplicated DNS target was counted once, leaving 999 unique domains; 998 returned usable observations. Country labels come from the source, and only groups with at least 30 observed domains are published.
WORLDWIDE COHORT
95.5% published DMARC; 79.4% of publishers enforced
953/998 observed domains published valid DMARC. 757/953 publishers requested quarantine or rejection.
UNITED STATES
96.0% adoption and 82.9% enforcement
All 323 source-classified U.S. domains were observed. 310/323 published valid DMARC, and 257/310 publishers enforced it.
OPERATING GAPS
8.8% of publishers omitted aggregate reporting
That was 84/953 DMARC publishers. SPF recursive lookup failures affected 37/962 SPF publishers.
These figures describe public DNS configuration at one scan time. They do not measure inbox placement, sender reputation, phishing, compromise, internal controls or business quality, and Palisade does not publish named source rows for this study.
Why this matters
Ecommerce email often carries order, account, loyalty, delivery and payment messages that customers are primed to trust. A missing or monitoring-only policy leaves less protection at participating receivers when a forged message using the site’s visible From domain fails aligned authentication.
Learn how DMARC evaluates a message →01 · DOMAIN IDENTITY
An attacker can send a message that displays the organization's exact domain in the From line. Without a valid DMARC record, participating receivers have no DMARC handling request from that domain owner when aligned SPF and DKIM fail.
02 · PRACTICAL HARM
A forged shipping update, account-security alert, loyalty message or invoice can be used to steal credentials, payment details or trust. Public DNS state does not show that any ecommerce business experienced fraud or that a message reached an inbox.
Three different DNS states
Risk, not incident evidence: this DNS state does not prove spoofing, fraud, compromise or weak internal controls. DMARC also does not stop lookalike domains, abuse of a compromised legitimate account or every phishing technique.
September 1, 2026
Public ranking retrieved, checksummed and deduplicated
September 1, 2026
Public DNS scan and aggregate review completed
September 1, 2026
Evidence package, charts and report released
The release passed the stated evidence and review gates.
Media posture
Share the methodology and aggregate evidence with specialist editors; do not redistribute the underlying ranking or pitch named domains as failures.
Groups below the 30-domain threshold are suppressed. Every visible percentage includes its numerator and denominator.
| Group | Observed | DMARC | Enforcement | No reporting | SPF lookup failure | BIMI among enforcing |
|---|---|---|---|---|---|---|
| United States | 323 | 96% (310/323) | 82.9% (257/310) | 8.1% (25/310) | 5.4% (17/313) | 40.1% (103/257) |
| United Kingdom | 78 | 97.4% (76/78) | 86.8% (66/76) | 3.9% (3/76) | 2.6% (2/77) | 40.9% (27/66) |
| Germany | 50 | 98% (49/50) | 75.5% (37/49) | 4.1% (2/49) | 2.1% (1/48) | 48.6% (18/37) |
| Japan | 50 | 94% (47/50) | 68.1% (32/47) | 12.8% (6/47) | 0% (0/46) | 46.9% (15/32) |
| France | 39 | 92.3% (36/39) | 77.8% (28/36) | 2.8% (1/36) | 0% (0/37) | 28.6% (8/28) |
| India | 33 | 90.9% (30/33) | 86.7% (26/30) | 10% (3/30) | 13.3% (4/30) | 19.2% (5/26) |
| Australia | 31 | 100% (31/31) | 96.8% (30/31) | 3.2% (1/31) | 3.2% (1/31) | 33.3% (10/30) |
SVG and PNG versions are licensed CC BY 4.0.
The aggregate findings and charts are free to quote, republish and build on under CC BY 4.0. Attribute Palisade and link to this report so readers can inspect the methodology and denominators.
Palisade. “Top 1,000 ecommerce websites DMARC benchmark 2026.” 2026-09-01. https://www.palisade.email/research/global-top-1000-ecommerce-email-authentication-2026
Pinned source snapshot
cfebb6c9bb732acc6c378ad54a50abb494920b6083c30369c325891dac1dab52Worldwide traffic-oriented ecommerce ranking. Palisade cites the source and publishes only derived aggregate DNS statistics.
The publisher’s description of its multi-source ranking and index methodology.
The source publisher’s reuse terms; Palisade therefore publishes no copied ranking or named source rows.
Current DMARC discovery and policy semantics used by the DNS parser.
Current DMARC aggregate-reporting semantics used to classify published reporting destinations.
Publish only derived aggregate statistics. Do not republish the source ranking, source positions, company names or named DNS observations. Country groups below 30 observed domains remain suppressed.