Hasty Briefsbeta

Bilingual

DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It

2 days ago
  • DMARC, introduced in 2012, is still not adopted by 45.1% of 67,336 domains checked; 68.4% either lack DMARC or have a non-enforcing policy.
  • Among domains with a DMARC record, 42.5% use p=none (monitor only), 27.7% use p=quarantine, and only 29.7% enforce p=reject.
  • The primary barrier to moving from p=none to enforcement is the difficulty of identifying all legitimate email senders from aggregate reports, which often contain cryptic or hashed rua= addresses.
  • Country-level differences show Poland with the highest no-record rate (64.6%) and the UK with the highest enforcement rate (25.5% p=reject).
  • SPF is the most widely adopted email authentication control (72.7%), while BIMI (2.6%), MTA-STS (1.4%), and DNSSEC (0% passing validation) lag far behind.
  • DMARC was standardized in 2026 with RFCs 9989–9991, replacing the Public Suffix List with a DNS Tree Walk for organizational domain detection.
  • Neither SOC 2 nor ISO 27001 explicitly require DMARC, but it may be implemented as part of risk-based email security controls.
  • The example of Cranswick (cranswick.co.uk) with three rua= addresses illustrates the complexity that prevents many domains from moving to enforcement.