Defaults.Exposed

Defaults.ExposedReports

DMARC Gap: 87 Million Domains One Record From Safety

Published

Figures as of 2026-08-16 · methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or name an individual registrant’s domain.

How many domains are one DNS record from safety?

Approximately 86.9 million domains — 23.1% of the 376.9 million domains we graded in August 2026 — publish an SPF record but no DMARC record at all. Each of them is exactly one DNS TXT entry away from having an email anti-spoofing policy. Not a migration. Not a software purchase. One line of text, pasted into a DNS console, published in minutes.

We call this the cheapest security upgrade on the internet, and we mean it literally. The record is free to publish. The syntax fits in a tweet. The domains in this cohort have already done the harder part — they set up SPF, which means someone, at some point, cared about their email posture. Then they stopped one record short.

The gap doesn’t end there. Widen the lens to every domain with SPF but no enforcing DMARC and the cohort grows to approximately 111 million domains — 29.5% of everything we graded. And the same near-miss pattern shows up in our scoring data: millions of domains sit exactly one point below a grade boundary, including a substantial cohort sitting at score 59, one point from leaving the F band.

Key numbers

What is the missing record?

DMARC is a single TXT record published at _dmarc. under a domain. It tells the world’s mailbox providers what to do with mail that claims to come from that domain but fails authentication: do nothing (p=none), send it to spam (p=quarantine), or refuse it outright (p=reject). The standard has been published since 2015 (RFC 7489 — industry knowledge, not census data). It is not new, it is not exotic, and every major DNS provider supports it because every TXT record looks the same to DNS.

Here is the strange part. The ~86.9 million domains in our headline cohort already publish SPF — the record that lists which servers are allowed to send their mail. SPF without DMARC is a lock without a door. It declares who may send, but gives receiving mail servers no instruction about what to do when someone else does. Spoofed mail sails past a bare SPF record in most real-world configurations because nothing tells the receiver to act on the failure.

So these domain owners bought the lock, hung it on the wall, and never installed the door. One more record installs it.

Where does the email-security funnel actually leak?

The August 2026 census lets us lay out the whole funnel with one denominator: 376,928,781 graded domains.

CohortDomainsShare of gradedDistance from an enforced policy
Publish SPF146,413,29738.8%
SPF but no DMARC record~86,900,00023.1%One new TXT record
SPF + DMARC, but not enforcing~24,100,0006.4%One edit to an existing record
Publish any DMARC75,543,00420.0%
DMARC at quarantine or reject34,983,6189.3%Already there
Fully protected (SPF + enforced DMARC, aligned)~10,500,000~2.8%Already there

Read the funnel top to bottom and the shape of the failure becomes clear. 38.8% of the graded internet adopted SPF. A fifth went on to DMARC. Under 10% turned enforcement on. The steepest single drop — 23.1 points of the entire graded population — happens between “published SPF” and “published DMARC,” and that drop costs one record to cross.

The ~24 million domains in the middle row deserve their own sentence. They already have a DMARC record. Someone published it, probably as p=none to monitor first, which is the correct opening move. Then the monitoring phase never ended. For them the fix is not even a new record; it is changing one tag in a record they already control.

For mail-receiving domains the picture is harsher. Of the estimated ~223 million domains with MX records — domains that actively run email — roughly 195 million lack an enforcing DMARC policy. These are not parked names. They receive mail, their brands ride on their domain, and a vast majority of them have left the spoofing question to the receiving server’s guesswork.

How many domains are one point from a better grade?

Email is where the one-record gap is biggest, but the near-miss pattern runs through the whole score distribution. Our v8 methodology grades on a 0-100 score: A at 90 and above, B at 80-89, C at 70-79, D at 60-69, F below 60. The score histogram shows heavy mass piled up just under each boundary.

Near a grade boundary, the cheapest missing points are almost always a DNS record. A B-grade domain that still lacks a CAA record (86.0% of the B band in August 2026), a DMARC reporting address, or full DMARC enforcement is typically within single-figure points of a better grade.

To see which checks those are, we looked at what still fails among domains that scored 80-89 — the B band, approximately 5.8 million domains, the cohort closest to the top. Among the checks a single DNS record can clear:

Single-record checkFailing in B band (80-89)Failing in A band (90+)
CAA record5,004,926366,381
DMARC reporting address (rua)2,000,802~36,000
DMARC policy strength~855,000~5,700
SPF exists~133,000~2,800

CAA is the standout: roughly nine in ten B-band domains, and even 366,381 of the A-band domains, don’t publish the one DNS record that restricts which certificate authorities may issue for them. Two million B-band domains have DMARC but never added a reporting address, so they fly blind on their own authentication failures. And a further ~855,000 domains scored in the 80s while still leaving their DMARC policy below enforcement — high performers with the same one-tag gap as the mass market.

The pattern holds at every altitude. Whatever a domain’s score, the nearest missing points tend to be a TXT record nobody published.

Why hasn’t this fixed itself?

Cost can’t explain it. A DMARC record is free, and the cohort we’re describing already proved it can edit DNS — that’s how the SPF record got there.

Our reading of the data points at three quieter causes.

The job looked finished. SPF was the visible task on the setup checklist, often prompted by a mail provider’s onboarding flow. DMARC rarely gets the same prompt, so the checklist ended one item early. The record that’s missing is precisely the one no wizard insisted on.

Monitoring became the destination. The ~24 million domains parked at a non-enforcing policy did the recommended thing — publish p=none, watch the reports — and then never scheduled the second step. A small related cohort dials enforcement down a different way: hundreds of thousands of DMARC records in our evidence set carry a pct= value below 100, applying their stated policy to only a sample of failing mail.

Nobody told the owner it mattered. This is the recurring finding of the whole census, and it holds here with unusual force. A domain owner who hears “your domain can be spoofed, and the fix is one free DNS record” mostly just fixes it. The barrier is awareness, not cost, and at ~87 million domains the awareness gap is the single largest cheap-to-close security deficit we can measure.

What does the fix actually involve?

For the ~86.9 million with no DMARC record: publish one TXT record at _dmarc.yourdomain — start at p=none with a reporting address, watch the reports for a few weeks, then move to p=quarantine and on to p=reject once legitimate senders are accounted for. For the ~24 million already at p=none: the watching phase is over; change the tag. For anyone near a grade boundary: CAA and a DMARC reporting address are the two most commonly missing single-record checks all the way up into the A band.

That’s the whole sell. The staged rollout matters — flipping straight to p=reject on a domain with unmapped senders can hurt real mail — but every stage of it is a DNS edit, and none of it costs money.

How we measured this

What this means

For business owners and IT managers, the 86.9 million figure has a direct operational implication: the absence of DMARC means your domain can be spoofed by anyone who wants to send fraudulent email claiming to be from you. Mail systems that receive such email have no published instruction from you about what to do with it. Some will junk it; many will deliver it. Your customers and partners have no reliable way to distinguish a legitimate email from your domain from a spoofed one — because you haven’t told their mail servers to enforce any boundary.

For IT managers who have already deployed SPF, the message is simpler: you are 23.1% of the way through a two-step process and the second step costs nothing. The SPF record you published declares who is authorised to send your mail. The DMARC record you haven’t published is the instruction that tells receiving servers to act on that declaration. Without it, SPF is visibility with no enforcement. Publishing DMARC at p=none with a reporting address takes five minutes and immediately starts generating data about what is actually sending on your behalf — which is valuable even before you move to enforcement.

For security teams running phishing-awareness or email authentication programmes, the ~24 million domains parked at p=none represent a specific intervention target: these operators made it through the hardest step (publishing DMARC) and then stopped at the monitoring phase. A direct, specific message — “your DMARC monitoring phase should end; here is how to move to enforcement” — is more likely to move this cohort than a general DMARC awareness campaign, because they have already demonstrated they will take DNS action when they understand what to do.

Data to cite

FAQ

What is the one DNS record most domains are missing? A DMARC record: a TXT entry at _dmarc. that tells receiving mail servers what to do with mail failing authentication. As of August 2026, approximately 86.9 million domains (23.1% of the 376.9 million we graded) publish SPF but no DMARC record at all, making it the single most commonly missing email-security record we measure.

Does publishing a DMARC record cost anything? No. It is a standard DNS TXT record, supported by every mainstream DNS provider, and publishing one is free (industry knowledge — pricing is not census data). The realistic cost is a few weeks of attention: start at p=none with a reporting address, review the reports, then raise the policy to quarantine or reject.

Is SPF alone enough to stop email spoofing? No. SPF lists your legitimate sending servers, but without DMARC there is no published instruction telling receivers to act when a message fails that test. Our August 2026 data shows the consequence at scale: the majority of mail-receiving domains remain spoofable because no enforcing DMARC policy backs their SPF.

How many domains enforce DMARC? 34,983,618 — 9.3% of all graded domains. Of the 75,543,004 domains that publish any DMARC record, only 46.3% set it to quarantine or reject; the rest sit at a monitoring-only policy that instructs receivers to take no action.

How many domains are close to a better security grade? On our 0-100 v8 score, tens of millions of domains sit within five points of the next grade band. Near a boundary, the cheapest missing points are usually single DNS records: CAA, a DMARC reporting address, or DMARC policy strength.

How has the SPF-without-DMARC cohort changed since July 2026? This report measures the August 2026 round (asOf 2026-08-16, 376.9M graded). The SPF-only cohort is a recurring measurement; directional trends will be published as each round completes. The structural gap — SPF adoption outpacing DMARC adoption by a large margin — has been persistent across rounds. It reflects the fact that SPF is typically prompted during mail-provider onboarding while DMARC is not.

My domain already has DMARC at p=none. What should I do next? Move to enforcement. Start by reviewing the aggregate reports you have been receiving (if you set a rua address) to confirm all your legitimate mail streams are passing SPF or DKIM alignment. Once you have two to four weeks of clean data showing only expected senders, move the policy to p=quarantine. After a settling period, move to p=reject. The monitoring phase is a means, not a destination.

See where your own domain stands

Most of the ~87 million domains in this report could close their gap this afternoon, and their owners simply don’t know it exists. Our census grades real, live domains across externally observable security checks, and the most common fixes are free — the barrier is almost never cost, it’s that nobody told the owner it mattered. You can check your domain privately and free, and see exactly which checks you pass.

Check your domain free at defaults.exposed — see whether your domain has a DMARC record, what its policy is, and whether it is one of the 86.9 million that could close their spoofing gap with a single DNS edit. Takes 30 seconds. No account needed.

Read the flagship census report: The State of Domain Security 2026 →

Related from this series: The Internet Security Grade Curve · The Fully Protected Few

Aggregate data only. Data stored and processed in the EU.


How to cite this report

Press / blog: defaults.exposed (2026). DMARC Gap: 87 Million Domains One Record From Safety. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/one-dns-record-from-safety

Academic: defaults.exposed. (2026, August 18). DMARC Gap: 87 Million Domains One Record From Safety. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/one-dns-record-from-safety

In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=376,928,781 graded; SPF-only cohort ~86.9M)


About the defaults.exposed August 2026 Census

The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.

Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026