DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It

An analysis of 67,336 domains reveals that 68.4% fail to enforce DMARC email authentication policies, despite the standard being available since 2012. The study highlights that many organizations remain in a 'monitoring' state (p=none) indefinitely rather than moving to active rejection of unauthorized emails.
DMARC has existed since 2012. It is a free DNS record that tells receiving mail servers what to do with email that fails to authenticate as coming from your domain: report it, quarantine it, or reject it outright. It is primarily concerned with unauthorised use of a domain in the visible From address; it doesn't stop lookalike-domain registrations, display-name spoofing, or a phishing email sent from a compromised legitimate account. Fourteen years on, we checked the DNS records for 67,336 domains in CipherCue's tracked entity set between 2026-04-14 and 2026-07-28. This is a snapshot of CipherCue's dataset, not a statistically representative sample of every company worldwide; the method note below covers how the cohort is built. 30,362 of them (45.1%) still don't have a record.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in