Defaults.Exposed

Defaults.ExposedReports

DMARC Enforcement: 11.84% Now Block Spoofing (July 2026)

Published · updated

Figures as of 2026-07-29 · methodology v8. Aggregate census data; we never publish an individual domain’s status or grade. See how we grade.

11.84% of domains now tell mail servers to junk or refuse email that impersonates them. That is the share publishing a DMARC policy of quarantine or reject — the only two settings that actually instruct receiving servers to act on a spoofed message. We measure it across every domain where a DMARC lookup was possible: the alive population of our census, 297 million domains, excluding the 21 million dead ones that cannot publish mail policy. Last month the figure was 10.6%. It has risen by 1.2 percentage points.

This is the tracker. Each month we re-measure DMARC across every alive domain — is a record present, and what policy does it publish? Those are directly observed facts, counted the same way every edition regardless of how our composite grading methodology (currently v8) evolves. Watch this number. We also publish the inverse view: the Email Spoofability Index.

The direction is encouraging. The level is not. 74.19% of the domains we could evaluate publish no record at all. And among the owners who did the paperwork, the most common policy blocks nothing. Which side of that 74.19% is your domain on? Run the free check — instant, no signup.

What counts as “enforcement”?

A DMARC record lets a domain owner publish a policy in DNS for email that fails authentication — mail that claims to come from the domain but cannot be proven to have done so. Three policies are possible. p=none means deliver the failing mail anyway and just send the owner reports: monitoring, not protection. p=quarantine treats failing mail as suspicious, typically routing it to the spam folder. p=reject refuses delivery outright.

Only quarantine and reject count as enforcement. They are the difference between watching impersonation and telling receivers to stop it. A domain at p=none has given the world’s mail servers no instruction to act on mail that fails its authentication — which is most of the internet right now.

How fast is DMARC enforcement growing?

From 10.6% last edition to 11.84% in this one. A 1.2-point monthly gain sounds small until you turn it into domains. The move represents roughly 5.0 million net-new enforcing domains. Behind that figure sit owners tightening policy, providers rolling out better defaults, and normal domain churn.

The pressure is structural, and it now bears directly on email deliverability — whether your mail gets delivered at all. Google and Yahoo require DMARC from bulk senders. Cyber-insurance questionnaires ask for it by name. Compliance frameworks increasingly list it explicitly. Enforcement is becoming a cost of doing business by email. And because the record sits in public DNS, everyone can see who has paid it.

One methodological note. Our composite grading changed between editions — June ran v7, July runs v8 — which is exactly why we never compare grades month-over-month. The DMARC facts here are unaffected: whether a record is present, and what policy it publishes, are observed the same way every time. The census population also shifts as domains register and lapse, so read the point-change as a population-level trend, not a tally of which specific domains moved.

Where does the rest of the internet stand on DMARC?

The full posture ladder, this edition:

PostureThis editionWhat DMARC tells receivers to do
No DMARC record74.19% of DMARC-evaluated domainsNothing — delivery depends on the receiver’s own filtering
p=none (monitor only)38,460,270 domains — 54.1% of published recordsTake no action against failing mail; just send reports
Enforcement (quarantine / reject)11.84% of DMARC-evaluated domainsSpam-folder or refuse failing mail
Malformed record38,650 domainsTypically treated as no record — receivers ignore records they cannot parse

The rows use different denominators, as labelled, so they do not sum to 100%.

In total, 71,141,310 domains publish a DMARC record of some kind. The malformed pile is its own small tragedy. Those records carry syntax errors serious enough that receivers will typically discard them. The owners tried, and got nothing for it: a DMARC record that cannot be parsed protects exactly as much as no record. The free check flags a malformed record instantly, before a receiver silently discards it.

Which TLDs lead DMARC enforcement? (.ai vs .com vs Europe)

Group enforcement by top-level domain — the ending of a domain name, such as .com — and a clear story appears: the newer or more coordinated the namespace, the better the posture. Here are five namespaces we track, with the share of each at enforcement. The full by-TLD table covers the rest.

TLDShare of domains at enforcement
.ai29.79%
.ch33.24%
.com10.82%
.de21.93%
.nl29.59%

The headline contrast is .ai at 29.79% against .com at 10.82%. The web’s incumbent namespace, the default business choice since before the web existed, trails a boutique tech-brand TLD by a wide margin. Young namespaces skew towards recently configured domains on modern hosting stacks, where DMARC is part of the setup rather than a retrofit. .com carries the accumulated weight of everything registered before email authentication mattered.

The European country-code TLDs tell a policy story instead. .ch (33.24%) and .nl (29.59%) sit near the top of our tracked league. The Netherlands has pushed email-authentication standards through public-sector comply-or-explain rules for years, and the zone’s numbers are consistent with that push. .de sits at 21.93%.

The DMARC p=none trap

Of the 71,141,310 DMARC records published, 54.1% are set to p=none. That is 38 million domains. The majority of all DMARC effort on the internet currently blocks nothing. It is the least comfortable finding in this report.

p=none exists for a good reason: it is the intended starting posture. You publish it and collect aggregate reports. The reports show which legitimate services send mail as your domain. You fix their authentication, then tighten the policy. It was designed as a ramp.

For 38 million domains, the ramp became the destination. This is also the posture that makes domain checkers flash the warning “DMARC policy not enabled”. A record exists, but the policy blocks nothing.

From an attacker’s viewpoint, p=none and no record are close to equivalent. The spoofed invoice is treated like any other mail. Nothing in the owner’s policy asks anyone to stop it, and if it slips past content filters, it lands in the inbox. The only party who notices is the domain owner — and only if someone actually reads the reports.

What this means for your business

Business email compromise, or BEC, is fraud run through impersonation by email. A staple vector is exact-domain spoofing: a forged message whose From address is your actual domain, not a lookalike. The classic plays all lean on it. The fake invoice with new bank details. The chief executive’s urgent transfer request. The payroll-diversion email to HR. BEC also runs on lookalike domains, display-name tricks and compromised real accounts — territory no DMARC policy covers. The stakes are not abstract. The FBI’s IC3 logged $2.77 billion in reported BEC losses in 2024, and a single redirected invoice is routinely a five-figure wire that does not come back. Your DMARC record is the only standing instruction you can give receiving mail servers to refuse mail that impersonates your domain. Without one, whether spoofed mail gets through depends entirely on each receiver’s own filtering.

The census says most attackers don’t even need a lookalike. With 74.19% of domains publishing no record and 54.1% of published records at p=none, for most domains nothing in DMARC stands in the way of exact-domain spoofing.

There is also a quieter effect: your DMARC posture is public. Counterparties, insurers and security-rating services read it straight from DNS. A domain at enforcement signals operational maturity to anyone who looks. The parties deciding whether to trust your invoices, your onboarding process or your insurance application increasingly do look — and the check takes seconds. Run it on your own domain — free, instant, no signup.

How do you get from no DMARC record to p=reject?

The path is well-trodden, and the failure mode is well known: domains stall at p=none because tightening feels risky. Here is the sequence that works:

The reporting stage exists precisely so that tightening is boring. Skip the review and you break your own newsletters. Do the review but never tighten, and you join the 38 million. The free check tells you which step you’re on today. If the answer isn’t reject, the A-Grade Playbook offered with your results turns the scan into a risk-sequenced runbook: exact record values, a safe order, and a re-check after each change. Tightening stops feeling risky.

Check where your own domain stands right now. Run the free, instant domain security check — DMARC policy included, alongside the rest of our graded checks, no signup. It shows you which rung of the posture ladder you’re on. Next month we re-measure the entire census, and this number moves again. Every monthly edition lands on the DMARC hub. Bookmark it for the running series.

Quick answers

What share of domains enforce DMARC? As of 2026-07-29, 11.84% of the domains evaluated in the defaults.exposed census publish a policy of quarantine or reject. Dead domains are excluded — they cannot publish mail policy. That is up 1.2 percentage points from 10.6% the previous month.

How many domains have no DMARC record at all? 74.19% of evaluated domains in the 2026-07-29 census publish no record, leaving receiving mail servers with nothing to apply against exact-domain spoofing.

Does p=none stop spoofing? No. p=none tells receivers to deliver failing mail normally. 54.1% of the 71,141,310 records in this census use it — meaning 38 million domains have a record that blocks nothing.

Why does my checker say “DMARC policy not enabled”? Either there is no DMARC record at all, or the record is at p=none — the posture of 54.1% of published records. Moving to p=quarantine or p=reject clears it.

How do I check my own domain? defaults.exposed runs a free, instant check — no signup — and shows which rung of the posture ladder your domain is on.