Money moves by email on domains that can be spoofed
When a business connects its domain to a payment processor, an e-signature service, a mailing platform or a collaboration suite, the vendor usually asks it to publish a TXT (Text) record at the apex holding a string only that vendor issued. The record is a receipt: someone who controls the zone proved it to that vendor at some point. The census can’t tell whether the account behind it is still open.
The September 2026 census read the apex TXT records of the 316,600,902 domains carrying a grade, so those receipts can be counted and set beside the one record that decides whether mail claiming to be from the domain can be forged: DMARC (Domain-based Message Authentication, Reporting and Conformance).
Take Stripe. 92,762 of those domains carry Stripe’s proof-of-ownership token, the record Stripe asks for before it will send receipts, invoices and failed-payment notices from a business’s own domain instead of stripe.com. 88.4% of them publish a DMARC record, against 24.8% of all domains carrying a grade.
Only 33.1% of the Stripe-verified domains enforce DMARC with p=quarantine or p=reject. 55.2% sit at p=none, which asks receiving mail servers to deliver mail that fails the check as normal and send the domain a report.
Contracts do better than payments. Of the 56,830 domains an organisation has claimed in DocuSign, 60.9% enforce DMARC. Marketing does worse: of the 295,854 domains verified with Klaviyo, 24.8% enforce and 69.2% sit at p=none.
Each commercial cohort with more than a thousand domains is ahead of the census as a whole on DMARC enforcement and on SPF (Sender Policy Framework) records ending -all, and has fewer domains with no DMARC record. Each is also ahead of the control cohort of domains that proved themselves to Google, where 17.8% enforce.
What a verification token proves
A token also says nothing about how much the account is used, or whether the vendor’s own mail authentication records were ever finished. Each cohort below is named by what its token proves, no more.
| Cohort | What its token proves | Domains |
|---|---|---|
| Stripe | stripe-verification=: the domain was verified in a Stripe account. Stripe’s documentation lists a proof-of-ownership TXT record as the first of three DNS (Domain Name System) records for a custom email domain, the setting that sends receipts, invoices and failed-payment notices from the business’s own domain. | 92,762 |
| DocuSign | docusign=: an organisation claimed the domain in DocuSign Admin, which puts the DocuSign users with email addresses at that domain under the organisation’s management. | 56,830 |
| HubSpot developer app | hubspot-developer-verification=: the domain was verified for a HubSpot developer account. This is the token an app builder places; it doesn’t identify HubSpot CRM or Marketing Hub customers, whose sending domains are verified with CNAME (Canonical Name) records. | 12,268 |
| Klaviyo | klaviyo-site-verification=: the domain was verified in a Klaviyo account, the ownership step before a branded sending domain for marketing email. | 295,854 |
| Mailchimp | mailchimp-domain-verification=: the domain was verified in a Mailchimp account by its apex TXT method. Mailchimp verifies most sending domains by CNAME, so this cohort is tiny and isn’t the Mailchimp customer base. | 144 |
| Atlassian organisation | atlassian-domain-verification=: an Atlassian organisation verified the domain so it can manage the accounts of users with email addresses at it. Atlassian’s separate sending-domain token, for Jira and Confluence notification mail, is a different record and isn’t counted here. | 210,562 |
| Zoom | zoom-domain-verification=: the domain was verified in a Zoom account. | 4,105 |
| Slack | slack-domain-verification=: a Slack workspace or Enterprise Grid claimed the domain for its email addresses. | 29,094 |
| Google Search Console (control) | google-site-verification=: someone proved control of the domain to a Google product, most often Search Console. It says nothing about money or email, which is why it stands in as the control. | 29,008,806 |
The cohorts overlap. A domain that carries Stripe, DocuSign and Google tokens sits in three rows. The nine rows sum to 29,710,425 memberships, and 36,886,085 distinct domains carry at least one of the 22 tokens counted for this page, so the rows are not added together anywhere on this page.
Nine cohorts against DMARC and SPF
Each share in this table uses its own row’s domain count as the base. “Enforce” is a DMARC policy of p=quarantine or p=reject. “p=none” is a record with that policy. “No DMARC” is no record at all; the small remainder in each row is a record with no valid p= tag. “SPF -all” is an SPF record that ends in -all, which tells receivers to reject mail from any server the record doesn’t list.
The rows are ranked by the enforce share, and the last row is all domains carrying a grade, whatever their TXT records say.
| Cohort | Domains | Enforce | p=none | No DMARC | SPF -all |
|---|---|---|---|---|---|
| DocuSign | 56,830 | 60.9% | 26.9% | 12.2% | 56.2% |
| Slack | 29,094 | 51.9% | 31.8% | 16.2% | 36.1% |
| Atlassian organisation | 210,562 | 50.8% | 28.9% | 20.3% | 52.7% |
| HubSpot developer app | 12,268 | 39.7% | 43.2% | 17.1% | 29.3% |
| Zoom | 4,105 | 34.5% | 40.9% | 24.6% | 22.6% |
| Stripe | 92,762 | 33.1% | 55.2% | 11.6% | 24.9% |
| Klaviyo | 295,854 | 24.8% | 69.2% | 5.9% | 26.5% |
| Google Search Console (control) | 29,008,806 | 17.8% | 24.6% | 57.5% | 15.4% |
| Mailchimp | 144 | 0.0% | 91.0% | 9.0% | 93.8% |
| All domains carrying a grade | 316,600,902 | 11.6% | 13.2% | 75.2% | 18.2% |
Figure 1. Each bar is one cohort, split by the DMARC policy the census read, with the cohort’s own domain count on the right. The cohorts overlap, so the bars are not added together.
DocuSign, Slack and Atlassian, the cohorts where an administrator claims a domain for a whole organisation, lead the table, and in each of them half or more of the domains enforce DMARC. The Mailchimp row is 144 domains and too small to read.
Stripe sits in the lower half with a shape of its own. Its no-DMARC share, 11.6%, is among the lowest in the table, and its p=none share, 55.2%, is the second highest of the cohorts with more than a thousand domains, behind Klaviyo.
Stripe’s setup page for a custom email domain says a DMARC policy is required and suggests starting at p=none, then moving to quarantine or reject. Most Stripe-verified domains publish a record, and most of those records say p=none. The census can’t show whether that advice played any part. Klaviyo’s row has the same shape at a larger scale: 5.9% without a record, 69.2% at p=none.
The control cohort and the baseline read the other way round. Among the 29,008,806 domains that proved themselves to Google, 57.5% have no DMARC record at all, and among all domains carrying a grade the figure is 75.2%. Restricting the control to the 26,315,677 domains whose only verification-shaped TXT record is Google’s moves it little: 16.8% enforce and 59.3% have no record.
How the SPF record ends
Most domains in every commercial cohort publish SPF: 88.3% of Stripe-verified domains do, against 47.4% of all domains carrying a grade. The table splits each cohort by the mechanism that ends the record, on the same base as the table above.
| Cohort | SPF record | -all | ~all | ?all, +all or no recognised ending | No SPF |
|---|---|---|---|---|---|
| DocuSign | 97.6% | 56.2% | 38.7% | 2.7% | 2.4% |
| Slack | 93.6% | 36.1% | 55.2% | 2.3% | 6.4% |
| Atlassian organisation | 94.6% | 52.7% | 39.2% | 2.7% | 5.4% |
| HubSpot developer app | 88.7% | 29.3% | 57.3% | 2.1% | 11.3% |
| Zoom | 80.0% | 22.6% | 55.9% | 1.6% | 20.0% |
| Stripe | 88.3% | 24.9% | 60.2% | 3.2% | 11.7% |
| Klaviyo | 82.2% | 26.5% | 53.5% | 2.2% | 17.8% |
| Google Search Console (control) | 68.2% | 15.4% | 49.7% | 3.1% | 31.8% |
| Mailchimp | 98.6% | 93.8% | 4.9% | 0.0% | 1.4% |
| All domains carrying a grade | 47.4% | 18.2% | 26.6% | 2.6% | 52.6% |
Figure 2. Each bar is one cohort, split by the mechanism that ends its SPF record.
In the Stripe cohort ~all outnumbers -all by more than two to one (60.2% to 24.9%), and ~all leads in the Klaviyo, Zoom, HubSpot, Slack and Google rows as well. DocuSign and Atlassian, which lead on DMARC, also lead on -all at 56.2% and 52.7%. The SPF all qualifier page covers what a receiver does with each ending; ~all together with p=none leaves a forged message deliverable.
Where a DKIM key was found
The census can only judge DKIM (DomainKeys Identified Mail) where it knows where to look: the domain needs a mail exchanger at a provider whose DKIM selectors the census probes. Elsewhere the result is undetermined, and the site’s data page leaves those domains out of the DKIM base in the same way. So this table has its own base: the domains in each cohort where DKIM could be evaluated. The last two columns split that share by generic and country-code domains, each on its own evaluated base.
| Cohort | DKIM evaluated | Key found | Key found, gTLD | Key found, ccTLD |
|---|---|---|---|---|
| DocuSign | 52,918 | 66.3% | 64.3% | 71.9% |
| Slack | 28,015 | 71.8% | 71.8% | 71.8% |
| Atlassian organisation | 190,172 | 67.5% | 66.6% | 69.0% |
| HubSpot developer app | 10,758 | 66.4% | 66.9% | 65.6% |
| Zoom | 3,052 | 59.2% | 60.1% | 57.8% |
| Stripe | 75,838 | 63.6% | 63.2% | 64.5% |
| Klaviyo | 238,195 | 43.8% | 42.8% | 46.1% |
| Google Search Console (control) | 18,478,607 | 42.0% | 39.3% | 48.4% |
| Mailchimp | 46 | 97.8% | 85.7% | 100.0% |
| All graded domains where DKIM could be determined | 75,823,119 | 50.1% | 45.2% | 61.6% |
Figure 3. The share of each cohort’s evaluated domains where a DKIM key answered, with the number of evaluated domains on the right.
A found key is a floor. The census probes the one to three selectors that the domain’s mail provider publishes, so a key under any other selector goes unseen, and a domain that signs through a marketing platform’s own selector can still show as not found.
The Klaviyo row, at 43.8%, sits below the other commercial cohorts and below the census as a whole, at 50.1% of the 75.8 million domains where DKIM could be determined. The other six large commercial cohorts are all ahead of the census on this measure. The census can’t separate how much of Klaviyo’s gap comes from keys it didn’t look for.
Generic and country-code domains
The shares above blend generic top-level domains such as .com with country-code domains such as .de and .uk, and the two groups differ across the census: 10.5% of generic domains carrying a grade enforce DMARC, against 14.3% of country-code domains, and 78.4% against 67.0% have no record. The table splits the DMARC and SPF columns by TLD type, following IANA’s root zone database, with each cell on its own row’s base.
| Cohort | gTLD domains | Enforce | No DMARC | SPF -all | ccTLD domains | Enforce | No DMARC | SPF -all |
|---|---|---|---|---|---|---|---|---|
| DocuSign | 41,457 | 60.3% | 12.3% | 53.1% | 15,373 | 62.6% | 11.9% | 64.6% |
| Slack | 20,165 | 53.2% | 16.2% | 36.0% | 8,929 | 49.0% | 16.2% | 36.2% |
| Atlassian organisation | 127,410 | 51.6% | 20.4% | 49.7% | 83,152 | 49.5% | 20.2% | 57.2% |
| HubSpot developer app | 7,791 | 40.7% | 17.6% | 29.3% | 4,477 | 38.0% | 16.2% | 29.4% |
| Zoom | 2,571 | 35.4% | 26.3% | 22.8% | 1,534 | 32.9% | 21.6% | 22.2% |
| Stripe | 61,774 | 33.0% | 12.0% | 23.1% | 30,988 | 33.4% | 10.6% | 28.4% |
| Klaviyo | 203,173 | 24.1% | 6.0% | 24.5% | 92,681 | 26.2% | 5.7% | 30.8% |
| Google Search Console (control) | 19,728,547 | 17.8% | 59.6% | 13.4% | 9,280,259 | 17.8% | 53.1% | 19.5% |
| Mailchimp | 10 | 0.0% | 40.0% | 50.0% | 134 | 0.0% | 6.7% | 97.0% |
| All domains carrying a grade | 229,046,225 | 10.5% | 78.4% | 17.5% | 87,554,677 | 14.3% | 67.0% | 20.0% |
The vendor pattern holds on both sides. Stripe-verified domains enforce at 33.0% under generic TLDs and 33.4% under country codes, DocuSign at 60.3% and 62.6%. Across the census the country-code side is ahead on enforcement; within the commercial cohorts the two sides sit within a few points of each other.
Beside the Hidden SaaS Map
DomainsProject published The Hidden SaaS Map on 2 May 2026, a count of vendor verification tokens from a DNS crawl on 17 April 2026. Readers will set its per-vendor figures beside this page’s, so the difference in method comes first.
That crawl queried around 1.9 billion hostnames and folded each hit to its registrable apex with the Public Suffix List, so a token found on any subdomain counts for the apex, and it matched a catalogue of more than 50 vendor token formats. It reported 40,180,281 apexes with at least one tracked token, 25,988,287 for Google and 7,624,510 for Microsoft 365.
For the vendors on this page it reported 96,753 apexes for Stripe, 59,158 for DocuSign, 56,735 for HubSpot, 260,461 for Klaviyo, 230,746 for Atlassian, 61,135 for Zoom and 79,958 for Mailchimp and Mandrill together. It didn’t read DMARC, DKIM or SPF policy for any of them.
This page counts apex TXT records only, over the 316,600,902 domains the September 2026 census graded, and each cohort is one exact token string. The two sets differ in both directions: the census finds more Google and Klaviyo tokens and far fewer Zoom, HubSpot and Mailchimp ones. They differ in population, placement, token format and date, and this page doesn’t net one against the other.
What the census can and can’t see
- A token proves that someone once verified the domain with that vendor. It can’t show whether the account is still active, whether it’s used for money or mail, or whether the vendor’s own CNAME records for SPF and DKIM were ever added.
- The census reads the apex only. A token published on a subdomain, or a DMARC record that only a subdomain carries, is invisible here.
- Each row’s shares are of that row’s own domains. The rows overlap, this page counted 22 tokens in all, and the union figure above is for all 22. There is no meaningful total across the nine rows.
- DMARC, SPF and DKIM are read the way the site’s data page reads them, from the scan’s own check results, so the baseline row matches the figures published there.
- The DKIM table covers only the domains where DKIM could be evaluated, and a found key is a floor for the reason given above.
- The hubspot-developer-verification token is placed by developer accounts building HubSpot apps. It says nothing about HubSpot’s CRM or marketing customers.
- Mailchimp’s apex TXT method is rare; the vendor verifies most sending domains by CNAME, so the Mailchimp row is a small cohort and says nothing about Mailchimp’s customer base.
- All figures are aggregates. No domain is named, and the census doesn’t publish an individual business’s grade.
The DMARC page explains what p=quarantine and p=reject do to forged mail, and the DKIM page covers selectors and where a key lives.
See your own
The free scan reads any domain live, on the same checks the census uses: DMARC policy, the SPF all mechanism, and a DKIM key at the selectors your mail provider publishes. If your business takes payments, signs contracts or sends customer mail from a domain, the result tells you whether that mail can be forged today.
Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. DomainsProject figures are from its Hidden SaaS Map of 2 May 2026 and are not census data. Census numbers move every month; the current values are on the data page.