Skip to Main Content
Research dossier · 2026
Published researchReleased August 14, 2026

North American MSP email-authentication benchmark 2026

Across 566 observed MSP organizational domains, 89.0% published valid DMARC and 68.5% of publishers enforced quarantine or rejection. These are aggregate observations of a sourced Clutch directory cohort, not ratings of individual providers or their clients.

Why this matters

Without an enforcing policy, participating receivers have less domain-owner direction for forged support, invoice or password-reset messages that use an MSP’s exact From domain.

89.0%

DMARC adoption

504 of 566

68.5%

Enforcement among publishers

345 of 504

16.7%

Publishers without aggregate reporting

84 of 504

5.9%

SPF recursive lookup failures

32 of 542

KEY FINDINGS

Most publish DMARC, but 39.0% of observed MSP domains still did not enforce it

The benchmark covers Clutch-listed providers appearing in sampled U.S., Canada and local MSP market pages. It measures only each provider's public organizational domain and says nothing about client environments, service quality or internal controls.

ENFORCEMENT GAP

221 of 566 observed domains were not enforcing DMARC

345 domains enforced quarantine or rejection. The remaining 221 either had no valid DMARC record or published a monitoring-only policy at the scan time.

SIZE-BAND VIEW

DMARC adoption ranged from 82.8% to 96.4%

The 2–9 employee band measured 82/99; the 250–999 band measured 54/56. This is descriptive and does not establish that size caused the difference.

OPERATIONS

16.7% of publishers had no aggregate-reporting address

That was 84/504 DMARC publishers. SPF recursive lookup failures affected 32/542 SPF publishers.

“Not currently enforcing DMARC” is a public-DNS observation, not proof of compromise or poor service. The report deliberately publishes no company-level rankings or scores.

Why this matters

What is the risk when DMARC is missing?

MSP domains are trusted in support and administrative workflows. A missing or monitoring-only policy leaves less protection at participating receivers when a forged message using the MSP’s visible From domain fails aligned authentication.

Learn how DMARC evaluates a message →
Risk context

01 · DOMAIN IDENTITY

The visible From address can be forged

An attacker can send a message that displays the organization's exact domain in the From line. Without a valid DMARC record, participating receivers have no DMARC handling request from that domain owner when aligned SPF and DKIM fail.

02 · PRACTICAL HARM

A fake support request can look legitimate

A forged message could imitate an MSP’s support desk, invoice, password-reset or remote-access request to target its own staff, prospects or clients. This study measures only the MSP’s organizational domain and says nothing about client environments or service quality.

Three different DNS states

No valid DMARC
No domain-owner DMARC policy. Aggregate reports cannot be requested through that record.
DMARC at p=none
Monitoring only. Reports may be collected, but the owner requests no DMARC-based quarantine or rejection.
p=quarantine or reject
The owner asks receivers to act on messages that fail aligned authentication. Receiver behavior can still vary.

Risk, not incident evidence: this DNS state does not prove spoofing, fraud, compromise or weak internal controls. DMARC also does not stop lookalike domains, abuse of a compromised legitimate account or every phishing technique.

Scope

What this study measures

  • 01At least 500 unique MSP organizational domains found on publicly indexed Clutch U.S. and Canada MSP market pages.
  • 02Minimal factual collection: provider name, source market page, public size band, official-site destination and normalized domain.
  • 03Aggregate comparison by size band and other sufficiently supported public segments; market-page appearance is not treated as headquarters evidence.
Research questions

Questions the data answers

  1. 01How many MSP organizational domains publish and enforce DMARC?
  2. 02How often do MSPs collect aggregate reports?
  3. 03How common are SPF lookup-limit and multiple-record failures?
  4. 04Do sufficiently large public company-size bands differ after applying the same measurement rules?
Release record

How this research became citable

  1. August 14, 2026

    Clutch source snapshot and domain deduplication

  2. August 14, 2026

    DNS scan, 100-mapping QA and claims review

  3. August 14, 2026

    Public release

    The release passed the stated evidence and review gates.

Delivery package
What is available
  • Country and eligible segment aggregate tables.
  • Four channel-ready charts with numerator and denominator labels.
  • Methodology and collection-compliance statement.
  • A 40–60-target channel and MSP-community outreach brief.

Media posture

Offer specialist channel editors an aggregate first look; never use individual results as an outreach threat or sales tactic.

Published comparisons

How the observed groups compare

Groups below the 30-domain threshold are suppressed. Every visible percentage includes its numerator and denominator.

GroupObservedDMARCEnforcementNo reportingSPF lookup failureBIMI among enforcing
10 - 4924288.8% (215/242)65.1% (140/215)20% (43/215)6.9% (16/231)6.4% (9/140)
50 - 24913889.1% (123/138)73.2% (90/123)13% (16/123)3% (4/135)6.7% (6/90)
2 - 99982.8% (82/99)61% (50/82)17.1% (14/82)5.3% (5/94)6% (3/50)
250 - 9995696.4% (54/56)74.1% (40/54)13% (7/54)9.4% (5/53)7.5% (3/40)
For editors and analysts

Reusable charts

SVG and PNG versions are licensed CC BY 4.0.

Citation & media kit

Use this research

The aggregate findings and charts are free to quote, republish and build on under CC BY 4.0. Attribute Palisade and link to this report so readers can inspect the methodology and denominators.

Suggested citation
Copy this text when quoting or republishing the dataset.
Palisade. “North American MSP email-authentication benchmark 2026.” 2026-08-14. https://www.palisade.email/research/north-american-msp-email-security-2026
Methodology

How we measured this

  1. 1.Freeze factual rows from publicly indexed Clutch U.S., Canada and local MSP result pages, then resolve each public Visit Website destination to the provider domain.
  2. 2.Direct automated access stopped at Clutch's access challenge. The collection did not rotate proxies, solve CAPTCHAs, call private APIs or bypass access controls.
  3. 3.Deduplicate official-site hostnames and retain source-page provenance without copying reviews, descriptions, contacts or marketing copy.
  4. 4.Verify a minimum of 100 mappings manually and publish only aggregate DNS statistics.

Measurement record

Corpus and observations
566 observed of 567
Scan window
Aug 14, 2026, 08:45 PM UTC to Aug 14, 2026, 08:45 PM UTC
Scanner version
2.0.0
MX classifier version
2026-08-14.2

Pinned source snapshot

950f20754010ce2d1cb61865a53a96bbcccddaf3bc5e1a196142d8900864a1e4

Limitations

  • An MSP corporate domain does not describe the authentication state of its clients.
  • Clutch-listed organizations appearing in the sampled market result pages are a sourced directory cohort, not every North American MSP.
  • Some firms appear in both national or local markets; market presence is not evidence of headquarters location.
  • Public service and partnership labels are used only when their source supports a defensible grouping.
Source record

Trace the evidence

Clutch MSP directory

Public discovery source for MSP market listings and official-site destinations.

Clutch public sitemap

Public discovery route for current directory market pages; no profile copy is republished.

Publication policy

Publish only aggregate results. Use the phrase “MSP organizational domains not currently enforcing DMARC”; never imply that it measures client security or service quality.