We Checked SPF and DMARC on the Top 10,000 Domains: 4 in 10 Mail Domains Don't Enforce DMARC

We looked up SPF, DMARC and MTA-STS records for the 10,000 most popular domains. Of 7,214 domains that receive mail, 3,000 do not enforce DMARC. Breakdowns by rank and TLD, a rollout plan, and the full CSV.

English Implementation & Architecture SummaryBase URL: https://api.callaiapi.com/v1

We looked up SPF, DMARC and MTA-STS records for the 10,000 most popular domains. Of 7,214 domains that receive mail, 3,000 do not enforce DMARC. Breakdowns by rank and TLD, a rollout plan, and the full CSV.

Auth Header: Bearer <YOUR_API_KEY>•Billing: TRON USDT from $1 · Pay-as-you-go•Compatibility: 100% OpenAI SDK Drop-in

Anyone can put any address in an email's From line. Three DNS records, SPF, DKIM and DMARC, decide whether the receiving server can tell a forgery from the real thing. For export businesses, a spoofable domain is how buyers end up with fake "our bank details have changed" emails. For cold emailers, missing records push legitimate mail toward spam.

On 28 September 2026 we looked up the email authentication records of the top 10,000 domains in the Tranco ranking. Here is what we found.

Key findings

  • 7,214 of the top 10,000 domains publish MX records (they receive mail). The figures below are for those 7,214 mail domains.
  • 92.7% publish SPF and 82.3% publish DMARC, but only 58.4% enforce it (p=quarantine or p=reject, applied to all mail).
  • That leaves 3,000 mail domains (41.6%) without DMARC enforcement: 1,279 have no DMARC record at all, and most of the rest sit at p=none, which reports but blocks nothing.
  • Higher-ranked domains do better: 73.4% of the top 1,000 enforce DMARC, against 52.9% of those ranked 5,001-10,000.
  • 2,761 domains receive no mail, yet only 19% say so with SPF -all plus an enforced DMARC policy. The rest can be used in forged From lines.
  • 43% of SPF records end in -all (hard fail) and 44.5% in ~all (soft fail). 0.7% of domains publish more than one SPF record, which receivers treat as an SPF error.
  • Only 3.7% of mail domains publish MTA-STS.

By rank

RankMail domainsHas DMARCEnforces DMARCp=none only
1–1,00070089.3%73.4%14.6%
1,001–5,0002,81583.2%61.9%19.4%
5,001–10,0003,69980.3%52.9%25.2%

By TLD

TLDs with at least 60 mail domains. Government domains lead; .jp and .net trail.

TLDMail domainsHas DMARCEnforces DMARC
.gov9298.9%81.5%
.fr8287.8%65.9%
.com.br7097.1%65.7%
.com3,63083.9%62.9%
.ru27783.8%62.5%
.org35084.3%53.4%
.de15286.2%50.7%
.it7290.3%47.2%
.net40063.8%39.8%
.jp10576.2%35.2%

Big names at p=none

On the survey date, live.com, msn.com, azure.com, samsung.com and yandex.ru all published p=none on their main domain: reports are collected, forgeries are not blocked. The Microsoft domains set sp=quarantine, so their subdomains are protected. p=none is often a step in a rollout, but it does mean forged mail using the main domain is not stopped by DMARC.

What to do with your own domain

  • Keep exactly one SPF record listing every real sending service, ending in ~all or -all.
  • Turn on DKIM signing in your mail provider (Google Workspace, Microsoft 365, SendGrid and so on).
  • Roll out DMARC in three steps: p=none with rua reports, then p=quarantine once legitimate mail passes, then p=reject.
  • Since February 2024, Gmail and Yahoo require senders of more than 5,000 messages a day to their users to have SPF, DKIM and DMARC (p=none meets the minimum).
; 1) Monitor: collect reports, change nothing
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]"
; 2) After 2-4 weeks of clean reports
_dmarc.example.com. IN TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]"
; 3) Enforce
_dmarc.example.com. IN TXT "v=DMARC1; p=reject; rua=mailto:[email protected]"

Domains that never send mail, such as spare or parked domains, should say so, or anyone can forge them:

; example.com accepts no mail
example.com.        IN MX   0 .
example.com.        IN TXT  "v=spf1 -all"
_dmarc.example.com. IN TXT  "v=DMARC1; p=reject;"

Methodology and limits

  • Domains: the top 10,000 registrable domains of Tranco list 64X3X, retrieved 28 September 2026.
  • DNS: MX, SPF, _dmarc and _mta-sts TXT lookups on 28 September 2026 via 1.1.1.1 and 8.8.8.8; 25 domains failed to resolve and are excluded.
  • "Enforces DMARC" means exactly one valid record with p=quarantine or p=reject and pct=100.
  • DKIM is not measured: its records sit under sender-chosen selectors that cannot be enumerated from outside.
  • Only the registrable domain is checked, not subdomains. DNS is a point-in-time snapshot and may have changed since.
站内推荐实用工具

Check your own domain

Free DMARC & SPF checker: SPF, DMARC, DKIM and MTA-STS, whether your domain can be forged, and how to fix it.

Check a domain
站内推荐实用工具

Set up the domain, then write the email

Free AI cold email generator: a 3-email sequence with a spam-word check, 5 free runs a day.

Write the sequence