.com vs .ai DMARC Enforcement (2026): .ai Is 3× Ahead
Publicat · actualizat
Figures as of 2026-07-29 · methodology v8. This is aggregate census data; we never publish an individual domain’s status or grade. See how we grade.
The internet’s youngest large domain population is almost three times as likely to enforce email authentication as its oldest. This edition of our census graded 148 million .com domains and 929,142 .ai domains. .com is the internet’s founding population. .ai is the registry the AI boom made its default address. DMARC is the record that tells the world’s mail servers what to do when a stranger tries to send email as your exact domain. On that one control, the generations are far apart: 29.79% of graded .ai domains enforce a DMARC policy, against 10.82% of graded .com.
That is not a rounding error. It is a different population with different defaults, visible at scale. And it has almost nothing to do with the letters after the dot.
How do .com and .ai compare, measure by measure?
| Measure | .com | .ai |
|---|---|---|
| Domains graded | 147,816,687 | 929,142 |
| DMARC published (any policy) | 23.5% | 42.4% |
DMARC enforced (quarantine/reject) | 10.82% | 29.79% |
| TLS 1.3 negotiated | 90.95% | 96.02% |
| DNSSEC signed and valid | 4.59% | 3.77% |
| Graded F (this edition) | 73.7% | 71.3% |
How to read the percentages: the DMARC and graded-F rows are shares of all graded domains in each TLD. The TLS 1.3 row counts only domains that completed a TLS handshake. The DNSSEC row counts only domains whose DNSSEC status could be evaluated.
See how secure .com is overall and which TLD leads on DMARC enforcement, or the full by-TLD DMARC table.
The email rows carry the story. It comes in two parts.
First, publication. 42.4% of graded .ai domains publish a DMARC record of some kind. That is close to double .com’s 23.5%. Publishing the record is the entry ticket. It is how a domain tells the world’s mail servers what to do with mail that fails authentication.
Second, follow-through. This is the sharper signal. Compare the enforcement row with the publication row. On .com in this edition, fewer than half of the domains that publish DMARC have moved past p=none. That is monitoring mode: it watches for spoofing but blocks nothing, which is why posture checkers flag it as “DMARC policy not enabled”. On .ai, a clear majority of publishers enforce. The new internet does not just adopt the control more often. It finishes the job more often.
For grade context: in this edition’s snapshot, 73.7% of graded .com domains carry an F. The .ai figure is 71.3%. The TLS 1.3 and DNSSEC rows are in the table for the full picture. We focus on the email rows for a simple reason: they are the controls a domain owner can change this afternoon, and the ones attackers routinely probe. Which row does your domain sit in? Run the free check. It reads the same DMARC, TLS and DNSSEC records in seconds, with no signup.
This article is the head-to-head. For the wider class comparison, which sets .xyz, .io and .top against the legacy trio, see New gTLDs vs Legacy Domains.
Why is .ai better at email security than .com?
Nothing about the letters “.ai” is magic. Three structural forces likely drive the gap. A fourth, quieter one may be doing even more work.
No legacy estate. DMARC, modern TLS and signed DNS all arrived decades into .com’s life. The .com zone carries every era of the internet at once: mail servers older than authentication, DNS set up by administrators who have since retired, parked portfolios nobody has touched in years. .ai’s population is overwhelmingly young. Most of it was registered into a world where these standards already existed.
Onboarding changed. Register a domain at a mainstream registrar today and connect a hosted email suite. The setup wizard typically writes your SPF record for you — the list of servers allowed to send as you. It sets up DKIM, the cryptographic signature on each message. Increasingly, it prompts for a DMARC record before you send your first email. The old internet had to retrofit security. The new one receives it as a default.
The registrant base is tech-heavy and hungry for deliverability. .ai skews toward startups, developer tools and founders who read email deliverability checklists. Their business depends on outbound email actually arriving. The major mailbox providers now demand authentication from bulk senders. So for exactly the companies flocking to .ai, DMARC was never just hygiene. It was a revenue requirement from day one.
Then there is the quieter fourth force: selection. .ai is a comparatively expensive, actively renewed namespace. It likely carries far less of the abandoned and parked inventory that weighs down .com’s averages. We have not measured how much of the gap that difference in make-up explains, and it may account for more than any of the other three. Old zones do not get better on their own. They just get older.
What can .com owners copy from the .ai playbook?
The .ai advantage is a set of defaults, not a deeper talent pool. Defaults can be copied. Start by finding out which of these you already have: the free check reads your records in seconds.
Wire authentication into setup, not audit time. Every new domain, subsidiary or campaign domain should leave the registrar with SPF, DKIM, and DMARC in place, just as a new .ai startup’s does. Then publish DMARC in monitoring mode. p=none is free, asks receivers to change nothing about delivery, and simply shows you who is sending as you. The .com data shows where the real trap lies: stopping there. Put a date in the calendar to move to quarantine, then reject; enforcement also unlocks BIMI, which puts your verified logo next to your email in supporting inboxes.
Your providers already know the path. The setup wizards that give new domains their head start work just as well on a decades-old .com — re-run your registrar’s and email suite’s setup flows, and most will flag what is missing. While you are in there, modernise the front door: most current hosting and CDN tiers negotiate TLS 1.3 by default, and many registrars have reduced DNSSEC to a single toggle.
If moving to enforcement is the part that feels risky, the A-Grade Playbook offered with your free scan results makes it safe and boring: exact record values, the right order of changes, and a re-check after each one.
Does your TLD protect you from spoofing?
Your TLD does not protect you. Your records do. The census gap is a fact about populations, not about any single domain. DMARC enforcement works the same on any TLD. A .com that enforces is no easier to spoof directly than a .ai that does. A domain that does not enforce is exposed on either registry. Attackers read DNS records, not brand history.
The exposure is concrete. Invoice fraud and business email compromise begin with a spoofed sender. A domain without DMARC enforcement is materially easier to impersonate, because nothing in its records asks receivers to stop mail sent in its name. The asymmetry is brutal. Enforcement costs a free DNS record and an afternoon of care. One accounts-payable clerk paying one convincing fake invoice costs more than every fix on this page. Third parties increasingly check too: cyber insurers, procurement questionnaires and secure email gateways read the same public records our census does.
And the bar keeps moving. As authentication becomes normal, mailbox providers treat unauthenticated mail with growing suspicion. The cost of doing nothing rises every time a neighbor upgrades. The new internet has set that expectation. The old internet’s mail is now judged against it.
In seconds, you can see your own domain the way our census and any attacker see it. Run the free domain security check: no signup, nothing to install, just your public records, graded.
Quick answers
What share of .com domains enforce DMARC? In the defaults.exposed census of 148 million graded .com domains, 10.82% enforce a DMARC policy of quarantine or reject as of 2026-07-29.
Is .ai better at email security than .com? As a population, yes. 29.79% of graded .ai domains enforce DMARC, versus 10.82% of graded .com. That is an almost three-to-one enforcement gap in this edition of the census.
Does registering a .ai domain protect against spoofing? No. Protection comes from your own SPF, DKIM and DMARC records. Only 29.79% of graded .ai domains enforce a blocking DMARC policy. On any TLD, a domain without enforcement — including one that publishes p=none — is no better protected against direct spoofing than a domain with no records at all. The free check reads your records the way every receiver and any attacker can, and grades them in seconds, no signup.