The State of DMARC 2026
We resolved the DMARC, SPF, BIMI and MX records of the top 100,000 domains on 30 July 2026 and measured what is actually deployed. 57.0% publish a DMARC policy, but only 63.4% of those enforce it — and enforcement collapses as you move down the ranking.
- 57.0%
- Publish DMARC
- 63.4%
- Of those, enforce
- 36.6%
- Stuck at p=none
- 21.0%
- Collect no reports
52,569 of 92,190 observed domains
33,315 of 52,569 domains with DMARC
Monitoring only — a spoofed message is still delivered
Have DMARC but no rua tag, so nothing is sent anywhere
Where the 52,569 domains with DMARC actually sit
Publishing a record is not the same as being protected. Only the quarantine and reject slices below do anything to a spoofed message.
| p=reject — spoofed mail refused | 35.2% (18,516) |
|---|---|
| p=quarantine — sent to junk | 28.2% (14,799) |
| p=none — delivered anyway | 36.6% (19,254) |
Enforcement falls away outside the top 1,000
The blended figure hides the real distribution. Among the 998 domains in the 1–1k band, 83.5% of DMARC publishers enforce. In the 10k–100k band, where 83,422 of the domains in this study sit, it is 62.0%.
| 1–1k — publish DMARC | 72.2% |
|---|---|
| 1–1k — of those, enforce | 83.5% |
| 1k–10k — publish DMARC | 65.2% |
| 1k–10k — of those, enforce | 73.3% |
| 10k–100k — publish DMARC | 56.1% |
| 10k–100k — of those, enforce | 62.0% |
1–1k
72.2% publish · 83.5% enforce
998 observed
1k–10k
65.2% publish · 73.3% enforce
7,770 observed
10k–100k
56.1% publish · 62.0% enforce
83,422 observed
One in five domains with DMARC is not collecting any reports
21.0% of domains with a valid DMARC record publish no rua tag. The policy is live and receivers honour it, but no aggregate report is sent anywhere, so the domain owner cannot see which of their senders are failing — the exact data a move to enforcement depends on.
| Measure | Share | Of |
|---|---|---|
| No aggregate reporting (rua)Of domains publishing DMARC | 21.0% | 11,049 of 52,569 |
| Enforcing on a sample only (pct<100)Of domains at quarantine or reject | 4.1% | 1,382 of 33,315 |
| Subdomains weaker than the domainsp= set below the organizational policy | 4.6% | 2,399 of 52,569 |
| Published but unusable recordDuplicate or malformed — receivers ignore it entirely | 0.4% | 394 of 92,190 |
Most SPF records still end in a soft fail
69.1% of observed domains publish SPF, but 50.4% of those end with ~all rather than -all. A soft fail asks receivers to accept unauthorised mail and mark it, which is the safe setting during a rollout and a weak one to leave in place permanently.
| Soft fail (~all) | 50.4% |
|---|---|
| Hard fail (-all) | 44.5% |
| No all mechanism | 2.8% |
| Neutral (?all) | 2.3% |
| More than one SPF record | 0.9% |
| Over the 10-lookup limit | 2.4% |
The lookup limit is the quiet one. 2.4% of SPF records need more than the ten DNS lookups RFC 7208 §4.6.4 allows (1,555 of 63,688). Every one of those evaluates to PermError, so the record is published, looks correct in a text editor, and authenticates nothing. It usually happens by accretion — each new sending tool adds one more include: until the eleventh tips it over, with no warning anywhere.
Domains that actually handle mail do better — but not at enforcement
72.3% of observed domains publish MX records. Restricting the study to those 66,655 mail-handling domains lifts DMARC adoption from 57.0% to 73.2%, yet enforcement barely moves: 62.1% against 63.4%. Publishing a policy is the step organisations take; enforcing it is the step they stall on.
| Measure | Share | Of |
|---|---|---|
| Publish DMARCOf 66,655 domains with MX | 73.2% | 48,813 of 66,655 |
| Of those, enforcep=quarantine or p=reject | 62.1% | 30,308 of 48,813 |
| Stuck at p=noneOf mail domains publishing DMARC | 37.9% | 18,505 of 48,813 |
| Publish SPFOf 66,655 domains with MX | 89.6% | 59,732 of 66,655 |
Most domains that could show a logo have not claimed it
BIMI puts a verified logo beside your mail in the inbox, and it only works from DMARC enforcement upward — so the hard prerequisite is the part most organisations never finish. Here the order is reversed: 31,933 domains have already reached enforcement with full coverage, and 87.6% of them have not published BIMI at all. Only 4.6% of observed domains publish a record, and 56.8% of those carry the Verified Mark Certificate Gmail requires before it will draw anything.
| Observed domains | 92,190 |
|---|---|
| Publish DMARC | 52,569 |
| At enforcement, full coverage | 31,933 |
| …and publish BIMI | 3,950 |
| …and carry a VMC | 2,362 |
| Point at a logo | 99.3% |
|---|---|
| Carry a VMC | 56.8% |
| Not at DMARC enforcement | 7.6% |
| Deliberately declined (empty l=) | 0.6% |
Records that point at nothing are rare, and more than half carry a certificate — domains that bother with BIMI mostly do it properly. The striking number is the one that is absent: 87.6% of domains that already meet the DMARC prerequisite have not published BIMI at all (27,983 of 31,933). They finished the hard part and skipped the visible reward.
How this was measured, and how to check it
Every figure above can be re-derived from scratch. The corpus is pinned, the scanner is described, and the aggregated dataset is downloadable.
The corpus
The top 100,000 domains of Tranco list PYGVJ, generated 2026-07-29. Tranco averages several ranking providers over 30 days specifically to resist the day-to-day churn that makes a raw traffic snapshot impossible to reproduce. The list ID is permanent, so the exact corpus behind these numbers can be re-downloaded and re-scanned.
What counts as a finding
A domain returning NXDOMAIN or NODATA genuinely publishes no such record, and that is data. A domain that times out or returns SERVFAIL was not observed, and is excluded from every figure rather than counted as having no DMARC — treating an unreachable domain as a non-adopter would inflate every number in this report. That exclusion applied to 7.8% of the corpus (7,810 domains), almost all of them timeouts.
Resolution
DMARC, SPF, BIMI and MX records were resolved against the public resolvers 8.8.8.8 and 1.1.1.1. BIMI was probed at the default selector, the one providers use when a message carries no BIMI-Selector header, so a domain publishing only under a custom selector is counted as having none. A DMARC record counts only when exactly one v=DMARC1 record carries a valid p= tag; duplicates are discarded by receivers under RFC 7489 §6.6.3 and are reported here as broken rather than absent. Two or more SPF records are a permanent error under RFC 7208 §4.5 and counted the same way.
Counting SPF lookups
The lookup figure follows each record's include: and redirect= chain recursively, counting the terms RFC 7208 §4.6.4 charges against the limit of ten and breaking cycles with a visited set. Counting stops once the total passes ten, because the finding at that point is simply “exceeds the limit” — so a domain reported as over is over, but the exact figure past eleven is a floor rather than a total.
Denominators
Every percentage on this page states what it is a percentage of. Adoption figures are over observed domains; policy and enforcement figures are over domains that publish a valid DMARC record. The two are very different populations, and a report that blurs them is not saying anything checkable.
Use this research
These figures are free to quote, chart and build on, including commercially, under CC BY 4.0. Attribution with a link is all we ask.
Cite as
Palisade. "The State of DMARC 2026: enforcement across the top 100,000 domains." 30 July 2026. https://www.palisade.email/research/state-of-dmarc-2026
Get the data
- Aggregated dataset (JSON) — every figure on this page, with counts and denominators.
- The exact domain corpus — Tranco list PYGVJ, re-downloadable at any time.
Press and analyst enquiries: hello@palisade.email.