Research
Most domains that deploy DMARC never turn it on. Across 100,000 domains from the Tranco top-1M list, 58.7% publish a DMARC record but only 20.9% actually reject anything. More than a third of everyone who has done the work gets none of the protection.
| Mechanism | Share of domains |
|---|---|
| Has MX (receives mail) | 72.7% |
| SPF published | 70.7% |
| DMARC published | 58.7% |
| DMARC at enforcement (quarantine or reject) | 37.6% |
| DMARC at p=reject | 20.9% |
| MTA-STS | 2.0% |
| TLS-RPT | 2.4% |
| BIMI | 4.9% |
Adoption rates are the least useful thing a survey like this produces. The gap between publishing a record and being protected by it is where the real picture is. All figures below are shares of the domains that publish the record at all, so they describe people who have already done most of the work.
3.4% of published SPF records exceed the ten DNS-lookup limit set by RFC 7208. Over that limit the evaluation is a permerror, and most receivers treat a permerror as no SPF at all. The record still resolves. It still looks correct in a DNS lookup. It has simply stopped working, usually because someone added one more vendor to a record that was already at nine. Nothing surfaces this except reading the aggregate reports or counting the lookups.
20.8% of domains at quarantine or reject publish no rua
address. They are rejecting mail on the basis of a policy whose effects they cannot see. If that
policy is breaking a legitimate sending source, the only signal is a user complaining.
7.0% of enforcing domains set sp=none, which exempts
every subdomain. An attacker does not need to spoof the apex when
billing.example.com is unprotected and equally convincing.
| Rank band | Domains | SPF | DMARC | Enforcing | MTA-STS |
|---|---|---|---|---|---|
| Rank 1-1000 | 1000 | 76.4 | 73.0 | 61.3 | 3.6 |
| Rank 1001-10000 | 9000 | 75.0 | 66.4 | 48.9 | 2.6 |
| Rank 10001-100000 | 90000 | 70.2 | 57.7 | 36.2 | 1.9 |
DMARC enforcement roughly halves between the top thousand domains and the hundred-thousandth. MTA-STS barely exists outside the top tier.
Grouped by country-code TLD. This is a proxy for geography rather than a measurement of it:
a .com can be operated from anywhere, so these cuts describe domains that chose a
national TLD, not all domains in a country.
| Region | Domains | SPF | DMARC | Enforcing | MTA-STS |
|---|---|---|---|---|---|
| Australia | 532 | 92.7 | 87.2 | 67.1 | 5.6 |
| Nordics | 878 | 90.0 | 82.8 | 58.0 | 3.5 |
| Benelux | 939 | 89.6 | 81.2 | 59.6 | 5.5 |
| Baltics | 232 | 92.2 | 80.6 | 56.9 | 4.7 |
| UK | 1385 | 86.6 | 80.5 | 59.7 | 10.3 |
| France | 1004 | 89.4 | 77.0 | 44.0 | 1.8 |
| Southern Europe | 1848 | 90.3 | 76.4 | 44.0 | 1.1 |
| Brazil | 1446 | 86.2 | 75.4 | 45.7 | 1.3 |
| DACH | 2597 | 87.9 | 75.1 | 44.3 | 4.4 |
| CEE | 2159 | 91.8 | 73.7 | 44.0 | 1.6 |
| Japan | 1971 | 78.7 | 66.3 | 22.1 | 0.3 |
| India | 1291 | 72.0 | 62.7 | 45.4 | 0.4 |
V3YPN. Tranco
averages several providers over thirty days, so it is far more stable than snapshot rankings,
and every list is permanently addressable by ID. The same population can be re-derived by
anyone._dmarc,
_mta-sts, _smtp._tls and default._bimi, plus MX. SPF
lookup counts are computed by walking include and redirect chains.The full per-domain dataset and the computed findings are published so the numbers above can be checked rather than taken on trust.
The dataset is archived at Zenodo with a permanent DOI, so it stays citable and resolvable independently of this site.
Singh, R. (2026). The State of Email Authentication 2026: SPF, DMARC,
MTA-STS, TLS-RPT and BIMI adoption across 100,000 domains [Data set].
Zenodo. https://doi.org/10.5281/zenodo.22832936
DOI: 10.5281/zenodo.22832936 · Zenodo record · ORCID