Who Reads the World's DMARC Reports?
Published
Figures as of 2026-08-16 (August 2026 round) — methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or configuration. Vendor and service endpoints are named because they are shared infrastructure, not individual businesses.
One company sees the spoofing attempts against nearly half the report-collecting internet
One company receives the spoofing-attack telemetry for 46.8% of every report-collecting domain in our census — 13,926,320 domains — and in most cases the record that sends it was provisioned by default, not chosen.
A word on scope before anything else, because the claim deserves a precise denominator. Our monthly census scans roughly 432 million domains and grades 376.9 million of them — the graded population behind our State of Domain Security report. When we say “the report-collecting internet” in this article, we mean the 29,727,689 graded domains in the August 2026 round that publish a DMARC record with a rua reporting address. That is the population every percentage in this report is measured against.
Every domain that publishes a DMARC record with a rua address is continuously exporting a feed of intelligence: who is sending email in its name, from where, how often, and whether those messages passed or failed authentication. That includes every spoofing and impersonation attempt made against the domain. The rua address decides who gets to watch.
Where those feeds actually go has never, to our knowledge, been published as a recurring census of a population this size. Academic measurement studies have sampled the DMARC reporting ecosystem before; what has been missing is a full-population count, repeated on a schedule, that can be tracked over time. So this round, we extracted every rua address in the graded population and traced the destination. The result is a market more concentrated than almost any other layer of internet infrastructure — and the leader didn’t lead by selling anything. It leads by being the default.
Key findings
- 29,727,689 graded domains publish a DMARC
ruareporting address — the address that receives their email-authentication and spoofing telemetry. - The top recipient, onsecureserver.net, receives reports for 13,926,320 domains — 46.8% of every rua-configured domain in the census. The endpoint sits in GoDaddy’s infrastructure and is written into customers’ DNS by default (evidence below).
- The top destination receives reports for more domains than the next ninety-nine recipients combined — 13.9 million against roughly 7.7 million for everyone else in the top 100.
- The top three recipients cover 53.5% of all rua-configured domains. The top ten cover 61.5%.
- 6,644,654 distinct destination domains appear across all rua addresses — but the long tail is dominated by per-customer unique subdomains, so the distinct count wildly overstates the number of actual vendors.
- 249,969 domains send their DMARC reports straight to a gmail.com inbox — machine-generated XML attachments arriving daily into personal mailboxes, a format that in practice tends to go unread (readership itself is not externally measurable).
The address that decides who watches
DMARC is the protocol that lets a domain tell the world’s mail servers what to do with email that claims to come from it but fails authentication. It has a second, less famous function: reporting. A domain owner can add a rua tag — a reporting address — and every major mail provider will then send that address regular aggregate reports about the domain’s email traffic.
Those reports are genuinely useful. They’re how you find forgotten mail services before you enforce a strict policy, and how you spot a spoofing campaign against your brand while it’s happening. If you enforce DMARC without ever reading the reports, you’re locking the door without checking who has keys.
But the same feed is valuable to whoever collects it at scale. Aggregated across millions of domains, rua telemetry is a live map of the world’s email: which providers send for whom, where authentication is failing, and where impersonation campaigns are hitting. The rua address is, in effect, a standing instruction to the entire global mail system: send my security telemetry here.
Which makes the obvious question worth asking at census scale: where does “here” actually point?
The biggest telemetry feed we can measure was written by a default
Collapse every rua destination to its registrable domain and one name dwarfs everything else: onsecureserver.net, the reporting endpoint behind 13,926,320 domains — 46.8% of all rua-configured domains in the graded population.
Why we attribute onsecureserver.net to GoDaddy
An identification this consequential needs to be shown, not asserted, so here is the basis for it. The domain onsecureserver.net is registered to GoDaddy.com, LLC, and it is the sibling of secureserver.net — the domain GoDaddy has used for hosted-customer infrastructure for two decades, and which itself appears in our destination data. GoDaddy’s own product documentation describes automatically provisioning DMARC records for customer domains, and the default records observed across GoDaddy-managed domains in our census point their rua at addresses under onsecureserver.net at machine scale — millions of domains carrying the same auto-generated record shape, which is the signature of platform provisioning, not individual configuration.
The mechanism is mundane. When GoDaddy sets up email-related DNS for a customer domain, its default DMARC record points reporting at this endpoint. The customer doesn’t shop for a DMARC monitoring vendor or compare dashboards. The record is simply there.
The largest single collector of email-security telemetry in our census did not win a market. One registrar’s default DNS record writes the world’s biggest spoofing-telemetry feed.
And defaults have consequences. Because the record is written by default, most of those 13.9 million domain owners likely never made an active choice about it — and many will not know the record exists, or that a continuous feed describing their email traffic, legitimate and fraudulent, flows to an endpoint they never picked. Consent by inertia is the governing mechanism for nearly half the report-collecting population we measure.
The league table: who receives the world’s DMARC reports
After the GoDaddy-linked endpoint, the market looks more like a market: dedicated DMARC vendors, email-infrastructure providers, hosting and registrar defaults, and security firms. Here is the top of the table, by registrable destination domain, in descending order of reach. We do not print rank numbers, for two reasons given in full in the methodology: multi-organisation suffixes (co.uk, com.br, com.au) are excluded as collapse artifacts, and because our extraction counts only the first rua URI per record, ordering among the mid-table entries could shift under full multi-URI extraction. The counts themselves are exact.
| Destination (registrable domain) | Operated by / known as | Domains reporting to it |
|---|---|---|
| onsecureserver.net | GoDaddy infrastructure (auto-provisioned default) | 13,926,320 |
| cloudflare.net | Cloudflare | 1,117,946 |
| brevo.com | Brevo * | 860,282 |
| vali.email | Valimail | 703,302 |
| proofpoint.com | Proofpoint | 472,743 |
| reportdmarc.nl | reportdmarc.nl | 334,243 |
| gmail.com | Personal / workspace Gmail inboxes | 249,969 |
| 163.com | NetEase mail | 231,745 |
| dmarcian.com | dmarcian | 198,202 |
| dmarc-report.com | dmarc-report.com | 197,755 |
| dmarcanalyzer.com | DMARC Analyzer | 146,581 |
| inboxsetup.com | inboxsetup.com | 131,461 |
| postmarkapp.com | Postmark | 118,133 |
| glockapps.com | GlockApps | 113,989 |
| simply.com | Simply.com (hosting shared endpoint) | 94,659 |
| atomynow.com | not identity-verified | 93,757 |
| businessidentity.llc | not identity-verified | 93,126 |
| mailgun.org | Mailgun | 92,719 |
| lovable.dev | Lovable (site-builder shared endpoint) | 84,685 |
| lh.pl | LH.pl (hosting shared endpoint) | 82,755 |
| domeneshop.no | Domeneshop (registrar shared endpoint) | 77,002 |
| agari.com | Agari | 68,100 |
| ondmarc.com | Red Sift (OnDMARC) | 66,712 |
| mailinblue.com | Brevo (legacy Sendinblue domain) * | 65,872 |
| dmarcadvisor.com | DMARCAdvisor | 60,111 |
* mailinblue.com is the legacy domain of Sendinblue, which rebranded as Brevo. We count the two destination domains separately because that is how the DNS records point; merged under one operator, Brevo’s combined reach would be 926,154 domains — still comfortably third.
The gap between first and second place is not a gap; it’s a different order of magnitude. The GoDaddy-linked endpoint receives reports for more domains than the next ninety-nine recipients in our data combined — and the next-largest entry, Cloudflare at 1,117,946 domains, is itself a giant by any normal market standard.
One qualification, stated once and meant hard: these are measurements of where DNS records point — reach, not customers. The 13.9 million figure is a default-provisioned footprint, not 13.9 million people who bought monitoring. There is no evidence in our data of misuse by any recipient, and the large collectors are, on the whole, exactly the organisations you’d want handling this data competently. Auto-provisioned monitoring is arguably better than the alternative most domains choose, which is no reporting at all. The story here is structure and consent, not scandal.
It’s also worth noticing what kind of names fill the table. Dedicated DMARC specialists (Valimail, dmarcian, Red Sift, DMARC Analyzer, DMARCAdvisor) sit alongside email-sending platforms (Brevo, Postmark, Mailgun), security vendors (Proofpoint, Agari), and — tellingly — hosting providers and registrars whose shared endpoints exist for the same reason GoDaddy’s does: they wrote the record for the customer. The world’s spoofing telemetry doesn’t flow to one kind of company. It flows to whoever was standing nearest when the DNS record got written.
How concentrated is it, really?
Concentration in this market is easy to understate, because the raw destination count looks enormous: 6,644,654 distinct rua target domains appear in the data. That sounds like a healthy, fragmented ecosystem.
It isn’t. The long tail is overwhelmingly per-customer unique subdomains — vendors that give each client their own reporting hostname — so millions of “distinct” destinations collapse into a handful of actual operators. Measured where it matters, at the registrable domain, the picture inverts:
| Slice of the market | Share of all 29,727,689 rua-configured domains |
|---|---|
| Top 1 recipient (onsecureserver.net) | 46.8% |
| Top 3 recipients | 53.5% |
| Top 10 recipients | 61.5% |
Read that middle row again. A domain owner who publishes a rua address today has a better-than-even chance — 53.5% — that their telemetry lands with one of just three organisations. For a data feed that describes every impersonation attempt against every one of those domains, that is a remarkable amount of visibility pooled in very few places. A market this concentrated, carrying data this sensitive, built this silently, deserves at minimum to be measured on a recurring basis — which is what this report now does.
The 250,000 domains reporting to a Gmail inbox
One row of the league table deserves its own section: 249,969 domains send their DMARC aggregate reports directly to a gmail.com address.
This is the self-service end of the market. Someone — a founder, an IT contractor, a diligent office manager following a setup guide — created the DMARC record themselves and pointed the reports at the inbox they had. It’s a completely reasonable thing to do. It’s also, in practice, how telemetry goes to die.
DMARC aggregate reports are machine-generated XML files, typically compressed, arriving from every mail provider that handled the domain’s traffic — often several per day. In a dashboard, they’re a security feed. In a personal inbox, they’re an unread folder that fills forever. The spoofing attempt is in there, dutifully reported, base64-encoded, filed by Gmail somewhere below the newsletters.
We can’t see whether those reports are read; no external measurement can. But the format makes the likely outcome obvious. These 249,969 domains have done the responsible thing — they collect their telemetry — and the collection point almost guarantees nobody is watching it. If that’s your domain: the fix isn’t to remove the record. It’s to point it somewhere that parses XML so you don’t have to. Several of the vendors in the table above will do it free at small scale.
Publishing policy blind
The concentration story has a quieter sibling, and it may matter more for the average business.
Not every domain that publishes DMARC collects reports. The 29,727,689 domains in this report are the ones that do — the rest of the DMARC-publishing population carries a policy with no rua address at all. (We are deliberately not quoting an exact size for that blind cohort here; the cross-check on the full DMARC-publisher denominator was not complete at press time, and this report only prints numbers that survived verification. The rua-configured count is the verified figure, and it is what every percentage in this article is anchored to.)
Publishing DMARC without reporting means the protocol still works — mail servers still get their instructions — but the domain owner has switched off the feedback loop. They will never see the forgotten newsletter platform that’s about to break when they tighten policy. They will never see the spoofing campaign that their policy is (or isn’t) stopping. They’ve installed the alarm and disconnected the bell.
The pattern fits everything else we’ve measured about domain security: the internet’s defences fail not because protection is expensive, but because nobody is looking. Adding a rua tag to an existing DMARC record is a one-line DNS edit. It is free, and the barrier is awareness, not cost — the same finding, at yet another layer.
What this means if you own a domain
Three questions, in order of importance:
- Do you have DMARC at all, and is it enforcing? Reporting is the feedback loop; enforcement is the lock. Our State of Domain Security report covers how rarely that lock is engaged across the population.
- Does your DMARC record have a
ruaaddress? If not, you’re publishing blind: your policy runs with no feedback. One line fixes it. - Do you know where your
ruapoints — and did you choose it? If your domain lives at a registrar that provisions DMARC automatically, your telemetry may already be flowing to an endpoint you’ve never heard of. That may be fine. But it should be a decision, not an accident of onboarding. And if it points at a personal inbox, promote it to a tool that actually parses the reports.
None of these steps costs money at the scale of a typical business domain. All three are DNS edits an owner can make in an afternoon.
What this means
For IT managers and security teams, the concentration finding has two immediate implications. First, if your domain is among the 13.9 million sending telemetry to GoDaddy’s onsecureserver.net endpoint by default, verify that this was a deliberate choice and that the reporting is being actioned. Default-provisioned monitoring that nobody monitors provides the appearance of oversight without the reality. If you need active spoofing-campaign visibility, a purpose-built DMARC reporting service — several offer free tiers at small scale — is a one-line DNS change away. Second, the 46.8% concentration of DMARC telemetry in a single endpoint represents a systemic intelligence-sharing dependency that most security teams have not mapped. If that endpoint experiences an outage or a data incident, the spoofing telemetry for nearly half the report-collecting internet is affected simultaneously.
For business owners, the most actionable question from this report is the simplest: do you know where your DMARC rua points, and is anyone looking at it? The 249,969 domains sending reports to Gmail inboxes represent thousands of businesses that have done everything right in terms of configuration and nothing right in terms of operationalisation. DMARC reports in an inbox fill with unread XML until the inbox is full. Moving the rua address to a service that parses reports into a human-readable dashboard is a single DNS edit, and free options exist for small domains. The spoofing attempt you were warned about three weeks ago — but never saw because nobody reads the raw XML — is the preventable incident this change fixes.
For security-conscious organisations considering or reviewing DMARC deployments, the data on publishing-blind domains argues strongly for including a rua address from day one. DMARC without reporting is an enforcement mechanism without a feedback loop. You cannot safely advance from p=none to p=quarantine to p=reject without seeing what legitimate mail flows exist that need to be authenticated before enforcement tightens. The reports are the instrument that makes safe DMARC progression possible. Omitting the rua address is not a minor gap; it is publishing blind in a security-critical configuration.
FAQ
What is a DMARC rua address, in one sentence? It’s the reporting address inside a domain’s DMARC record where the world’s mail providers send aggregate reports on that domain’s email traffic — including failed and spoofed messages; as of 2026-08-16, 29,727,689 graded domains publish one.
Is it bad that a GoDaddy default endpoint receives reports for 13.9 million domains? The finding is about structure and consent, not wrongdoing: 46.8% of the report-collecting population flows to one endpoint that, in most cases, nobody actively chose. A structure like that should at least be visible and measured — which is the point of this census.
Does receiving DMARC reports let a company read anyone’s email? No. Aggregate reports describe traffic — sending sources, volumes, authentication results — not message contents. The sensitivity is in the pattern: at scale, the feed maps who sends email for whom and where impersonation attempts are landing.
I send my DMARC reports to my own Gmail. Should I stop? Don’t remove the record — collecting telemetry puts you ahead of every DMARC publisher that collects nothing. But you’re one of 249,969 domains whose telemetry lands as raw XML in an inbox, and raw XML tends to go unread. Point the rua at a report-parsing service instead; it’s a one-line DNS change and free options exist at small scale.
How do I find out where my own domain’s reports go?
Look at your domain’s DMARC record — the rua= tag holds the answer. Or check your domain with us: the scan shows your DMARC configuration among the externally observable checks we run, privately and free.
What is the risk of publishing DMARC without a rua address?
You lose the feedback loop that makes safe policy progression possible. Without reports, you cannot identify which legitimate mail flows would break if you moved from p=none to p=quarantine or p=reject. You also cannot detect ongoing spoofing campaigns against your domain — the reports are often the only way a domain owner learns they are being impersonated. Publishing DMARC without rua is the equivalent of installing a security alarm and disconnecting the monitoring centre.
Should I use my registrar’s default DMARC reporting endpoint?
It depends on whether the endpoint is actively monitored and whether you receive actionable alerts. Many registrar-provisioned DMARC endpoints collect telemetry without surfacing it to the domain owner in a usable form. If your registrar provides a dashboard with report parsing and spoofing alerts, the default endpoint may be fine. If the endpoint collects reports that you never see, you should redirect rua to a service that surfaces the data.
Data to cite
- “One endpoint — onsecureserver.net, in GoDaddy’s infrastructure — receives DMARC spoofing-attack telemetry for 13,926,320 domains, 46.8% of every rua-configured domain in the August 2026 census.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “The top DMARC reporting destination receives reports for more domains than the next ninety-nine recipients combined — 13.9 million against roughly 7.7 million for the entire rest of the top 100.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “The top three DMARC report recipients cover 53.5% of all rua-configured domains — a domain owner publishing a rua address today has a better-than-even chance their telemetry reaches one of just three organisations.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “249,969 domains send their DMARC aggregate reports to a gmail.com inbox — machine-generated XML arriving daily into a personal mailbox, a format almost guaranteed to go unread.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “29,727,689 graded domains publish a DMARC rua reporting address in the August 2026 census — the population continuously exporting spoofing-attack telemetry to these destinations.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “Adding a rua tag to an existing DMARC record is a one-line DNS edit — it is free, and the barrier is awareness, not cost.” — defaults.exposed August 2026 Domain Security Census (432M domains)
See where your own domain stands
These are population numbers. Your domain is either publishing blind, in the Gmail cohort, or in the minority that watches its own telemetry — and finding out takes a minute.
Check your domain free at defaults.exposed — see your full DMARC configuration including whether you have a rua reporting address, where it points, and whether your policy is enforcing or merely monitoring. Takes 30 seconds. No account needed.
The State of Domain Security 2026 →
Aggregate data only. Data stored and processed in the EU.
How to cite this report
Press / blog: defaults.exposed (2026). Who Reads the World’s DMARC Reports?. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/who-reads-the-worlds-dmarc-reports
Academic: defaults.exposed. (2026, August 20). Who Reads the World’s DMARC Reports? In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/who-reads-the-worlds-dmarc-reports
In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=29,727,689 rua-configured domains)
About the defaults.exposed August 2026 Census
The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.
Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026
Aggregate data only. Data stored and processed in the EU.