DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It
2 days ago
- DMARC, introduced in 2012, is still not adopted by 45.1% of 67,336 domains checked; 68.4% either lack DMARC or have a non-enforcing policy.
- Among domains with a DMARC record, 42.5% use p=none (monitor only), 27.7% use p=quarantine, and only 29.7% enforce p=reject.
- The primary barrier to moving from p=none to enforcement is the difficulty of identifying all legitimate email senders from aggregate reports, which often contain cryptic or hashed rua= addresses.
- Country-level differences show Poland with the highest no-record rate (64.6%) and the UK with the highest enforcement rate (25.5% p=reject).
- SPF is the most widely adopted email authentication control (72.7%), while BIMI (2.6%), MTA-STS (1.4%), and DNSSEC (0% passing validation) lag far behind.
- DMARC was standardized in 2026 with RFCs 9989–9991, replacing the Public Suffix List with a DNS Tree Walk for organizational domain detection.
- Neither SOC 2 nor ISO 27001 explicitly require DMARC, but it may be implemented as part of risk-based email security controls.
- The example of Cranswick (cranswick.co.uk) with three rua= addresses illustrates the complexity that prevents many domains from moving to enforcement.