We Checked SPF and DMARC on the Top 10,000 Domains: 4 in 10 Mail Domains Don't Enforce DMARC
We looked up SPF, DMARC and MTA-STS records for the 10,000 most popular domains. Of 7,214 domains that receive mail, 3,000 do not enforce DMARC. Breakdowns by rank and TLD, a rollout plan, and the full CSV.
We looked up SPF, DMARC and MTA-STS records for the 10,000 most popular domains. Of 7,214 domains that receive mail, 3,000 do not enforce DMARC. Breakdowns by rank and TLD, a rollout plan, and the full CSV.
Anyone can put any address in an email's From line. Three DNS records, SPF, DKIM and DMARC, decide whether the receiving server can tell a forgery from the real thing. For export businesses, a spoofable domain is how buyers end up with fake "our bank details have changed" emails. For cold emailers, missing records push legitimate mail toward spam.
On 28 September 2026 we looked up the email authentication records of the top 10,000 domains in the Tranco ranking. Here is what we found.
Key findings
- 7,214 of the top 10,000 domains publish MX records (they receive mail). The figures below are for those 7,214 mail domains.
- 92.7% publish SPF and 82.3% publish DMARC, but only 58.4% enforce it (p=quarantine or p=reject, applied to all mail).
- That leaves 3,000 mail domains (41.6%) without DMARC enforcement: 1,279 have no DMARC record at all, and most of the rest sit at p=none, which reports but blocks nothing.
- Higher-ranked domains do better: 73.4% of the top 1,000 enforce DMARC, against 52.9% of those ranked 5,001-10,000.
- 2,761 domains receive no mail, yet only 19% say so with SPF -all plus an enforced DMARC policy. The rest can be used in forged From lines.
- 43% of SPF records end in -all (hard fail) and 44.5% in ~all (soft fail). 0.7% of domains publish more than one SPF record, which receivers treat as an SPF error.
- Only 3.7% of mail domains publish MTA-STS.
By rank
| Rank | Mail domains | Has DMARC | Enforces DMARC | p=none only |
|---|---|---|---|---|
| 1–1,000 | 700 | 89.3% | 73.4% | 14.6% |
| 1,001–5,000 | 2,815 | 83.2% | 61.9% | 19.4% |
| 5,001–10,000 | 3,699 | 80.3% | 52.9% | 25.2% |
By TLD
TLDs with at least 60 mail domains. Government domains lead; .jp and .net trail.
| TLD | Mail domains | Has DMARC | Enforces DMARC |
|---|---|---|---|
| .gov | 92 | 98.9% | 81.5% |
| .fr | 82 | 87.8% | 65.9% |
| .com.br | 70 | 97.1% | 65.7% |
| .com | 3,630 | 83.9% | 62.9% |
| .ru | 277 | 83.8% | 62.5% |
| .org | 350 | 84.3% | 53.4% |
| .de | 152 | 86.2% | 50.7% |
| .it | 72 | 90.3% | 47.2% |
| .net | 400 | 63.8% | 39.8% |
| .jp | 105 | 76.2% | 35.2% |
Big names at p=none
On the survey date, live.com, msn.com, azure.com, samsung.com and yandex.ru all published p=none on their main domain: reports are collected, forgeries are not blocked. The Microsoft domains set sp=quarantine, so their subdomains are protected. p=none is often a step in a rollout, but it does mean forged mail using the main domain is not stopped by DMARC.
What to do with your own domain
- Keep exactly one SPF record listing every real sending service, ending in ~all or -all.
- Turn on DKIM signing in your mail provider (Google Workspace, Microsoft 365, SendGrid and so on).
- Roll out DMARC in three steps: p=none with rua reports, then p=quarantine once legitimate mail passes, then p=reject.
- Since February 2024, Gmail and Yahoo require senders of more than 5,000 messages a day to their users to have SPF, DKIM and DMARC (p=none meets the minimum).
; 1) Monitor: collect reports, change nothing
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]"
; 2) After 2-4 weeks of clean reports
_dmarc.example.com. IN TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]"
; 3) Enforce
_dmarc.example.com. IN TXT "v=DMARC1; p=reject; rua=mailto:[email protected]"
Domains that never send mail, such as spare or parked domains, should say so, or anyone can forge them:
; example.com accepts no mail
example.com. IN MX 0 .
example.com. IN TXT "v=spf1 -all"
_dmarc.example.com. IN TXT "v=DMARC1; p=reject;"
Methodology and limits
- Domains: the top 10,000 registrable domains of Tranco list 64X3X, retrieved 28 September 2026.
- DNS: MX, SPF, _dmarc and _mta-sts TXT lookups on 28 September 2026 via 1.1.1.1 and 8.8.8.8; 25 domains failed to resolve and are excluded.
- "Enforces DMARC" means exactly one valid record with p=quarantine or p=reject and pct=100.
- DKIM is not measured: its records sit under sender-chosen selectors that cannot be enumerated from outside.
- Only the registrable domain is checked, not subdomains. DNS is a point-in-time snapshot and may have changed since.
Check your own domain
Free DMARC & SPF checker: SPF, DMARC, DKIM and MTA-STS, whether your domain can be forged, and how to fix it.
Set up the domain, then write the email
Free AI cold email generator: a 3-email sequence with a spam-word check, 5 free runs a day.