A recent analysis conducted by CipherCue on 67,336 domains between April 14, 2026, and July 28, 2026, found that 68.4% of these domains do not enforce DMARC policies. This includes domains that completely lack a DMARC record and those with records set to policies that do not actively block or quarantine unauthenticated emails.
Specifically, 30,362 domains (45.1%) were found to have no DMARC record at all. Among the domains that do have a record, only 10,963 (29.7%) utilize a "p=reject" policy, which drops emails that fail authentication. Another 10,258 domains (27.7%) use "p=quarantine", sending unauthenticated emails to junk folders, while the largest group, 15,709 domains (42.5%), is set to "p=none", which only collects reports without enforcing any action.
DMARC (Domain-based Message Authentication, Reporting, and Conformance) has been publicly available since 2012. It functions as a free DNS record that instructs receiving mail servers on how to handle emails that fail to authenticate as originating from a specific domain. Its primary purpose is to address unauthorized use of a domain in the visible 'From' address.
DMARC relies on two underlying building blocks: SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail). SPF allows a domain to publish a list of authorized sending servers, while DKIM adds a cryptographic signature to messages to confirm their origin and integrity. DMARC then ties these authentication methods to the 'From' address seen by the recipient.
While DMARC is effective in verifying if a domain owner authorized a message, it does not provide comprehensive protection against all forms of email-based attacks. It specifically checks if the domain owner, provable through SPF or DKIM, authorized the message. This mechanism is narrower than often perceived.
DMARC does not prevent issues such as lookalike-domain registrations, display-name spoofing, or phishing emails sent from compromised legitimate accounts. Organizations relying solely on DMARC for email security may overlook other vulnerabilities that DMARC is not designed to address.
The low rate of DMARC enforcement indicates a significant gap in email security adoption across many organizations. This leaves them vulnerable to email spoofing and phishing attacks, where malicious actors can impersonate legitimate domains to deceive recipients.
Despite DMARC's 14-year existence, a substantial number of domains have not implemented or fully utilized its enforcement capabilities, highlighting an ongoing challenge in securing email communications.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
DMARC (Domain-based Message Authentication, Reporting, and Conformance) verifies if the domain owner authorized an email, using SPF or DKIM. This mechanism is narrower than commonly perceived and does not provide complete protection against all forms of email-based attacks like phishing.
A recent analysis of 67,336 domains found that 68.4% either lack a DMARC record or have one that does not enforce a policy, meaning they do not reject or quarantine unauthenticated emails. This indicates a significant gap in email security adoption, leaving many organizations vulnerable to email spoofing and phishing attacks.