State of DMARC

State of DMARC, 2026-08

The scan covered 1,000,766 domains in one pass and recorded, for each, whether the domain publishes a policy receivers can act on and whether anybody can collect the reports it requests.

The 2026-08 edition is the first. It records a DNS scan of the Tranco top 1 million domains (list id JZ8PY) plus 1,321 US federal domains. The scan ran on 2026-08-20 and 2026-08-21 and looked up public TXT records for DMARC and SPF. 555 of the federal domains already rank inside the million and were scanned once, which leaves 1,000,766 rows. Every share below is a share of the 1,000,296 domains whose DMARC lookup answered, called the measured domains. The 470 lookups that failed after retries are excluded rather than counted as having no record.

Jump to tiers, rank, monitoring theater, SPF, the federal cohort, vendors, methodology or the data.

Key findings

  • In the August 2026 scan of the Tranco top million and a small federal cohort, 128,980 domains, which is 27.5% of the 469,415 valid DMARC records, publish p=none and send reports to no working destination.
  • In August 2026, 47.4% of the 1,000,296 scanned domains whose DMARC lookup answered publish a DMARC record, 46.9% publish one that receivers can act on, and 52.6% publish none.
  • 20.8% of the domains measured in August 2026, which is 207,651 domains, publish quarantine or reject with no pct or sp tag weakening it, and 11.8% publish p=reject.
  • 34,506 domains in the August 2026 scan name an external reporting address that has published no authorization record, so receivers are entitled to drop the reports addressed there.
  • Of the top 1,000 domains in the August 2026 scan, 72.1% publish a valid DMARC record and 55.8% are in the enforced tier; across ranks 100,000 to 1,000,000 those shares fall to 45.7% and 19.4%.
  • 427 of the domains scanned in August 2026 end their SPF record with a plus-all mechanism, which authorizes every host on the internet to send as them.
  • Of 1,321 US federal domains under Binding Operational Directive 18-01, which has required p=reject since October 2018, 79.2% publish p=reject in the August 2026 scan while 198 publish no DMARC record at all.

The quality tiers

These tiers sort each domain by whether receivers act on its record and whether anyone receives the reports it requests.

Quality tiers across 1,000,296 measured domains No record 52.6%, Broken 0.5%, Dead reporting 12.9%, Monitoring 10.5%, Partial enforcement 2.7%, Enforced 20.8%. No record: 525,752 domains, 52.6% Broken: 5,129 domains, 0.5% Dead reporting: 128,980 domains, 12.9% Monitoring: 105,464 domains, 10.5% Partial enforcement: 27,320 domains, 2.7% Enforced: 207,651 domains, 20.8%
TierDomainsShare
No record 525,752 52.6%
Broken 5,129 0.5%
Dead reporting 128,980 12.9%
Monitoring 105,464 10.5%
Partial enforcement 27,320 2.7%
Enforced 207,651 20.8%
  • No record 525,752 domains (52.6%) No DMARC record at the _dmarc name.
  • Broken 5,129 domains (0.5%) A record exists and receivers ignore it: more than one record, a bad v= tag, or no usable p=.
  • Dead reporting 128,980 domains (12.9%) p=none, and no rua destination that can receive a report.
  • Monitoring 105,464 domains (10.5%) p=none, with at least one rua destination that can receive a report.
  • Partial enforcement 27,320 domains (2.7%) quarantine or reject, weakened by pct below 100 or a softer sp=.
  • Enforced 207,651 domains (20.8%) quarantine or reject, with no pct or sp tag weakening it.

Two tags weaken a policy without changing it: pct= applies the policy to only that share of failing mail, and sp= sets a separate, often softer, policy for subdomains.

5,129 domains publish a broken record that receivers cannot use, including 4,477 with more than one DMARC record, which RFC 7489 treats as invalid. Broken rows are not scored as adoption.

A published-record count of 47.4% mixes dead, monitoring, partial, enforced and broken records. Broken rows count as published, never as valid. 207,651 domains (20.8%) publish quarantine or reject with no pct or sp tag weakening it. 525,752 domains (52.6%) publish no record. Most of the published remainder stays at p=none: 128,980 dead and 105,464 monitoring.

At enforcement, 10,318 domains use pct below 100 and 18,596 leave subdomains weaker than the organizational domain. Some domains appear in both counts, and the overlap is why those two figures sum to more than the 27,320-domain partial-enforcement tier.

Shares are of the 1,000,296 domains whose DMARC lookup answered. 470 domains failed to resolve after retries and are excluded rather than counted as having no record.

Run the same tier rules against your own domain.

Valid records and enforcement by rank

The top 1,000 domains publish and enforce at far higher rates than the rest of the million, so their numbers do not represent it. Both series are shares of the domains in that bucket whose DMARC lookup answered.

DMARC adoption and enforcement by Tranco rank bucket Top 1k: Valid DMARC record 72.1%, Enforced tier 55.8%. 1k to 10k: Valid DMARC record 66.0%, Enforced tier 43.8%. 10k to 100k: Valid DMARC record 57.0%, Enforced tier 31.5%. 100k to 1M: Valid DMARC record 45.7%, Enforced tier 19.4%. 0% 25% 50% 75% 100% Valid DMARC record Enforced tier Top 1k, Valid DMARC record: 72.1% 72.1% Top 1k, Enforced tier: 55.8% 55.8% Top 1k 1k to 10k, Valid DMARC record: 66.0% 66.0% 1k to 10k, Enforced tier: 43.8% 43.8% 1k to 10k 10k to 100k, Valid DMARC record: 57.0% 57.0% 10k to 100k, Enforced tier: 31.5% 31.5% 10k to 100k 100k to 1M, Valid DMARC record: 45.7% 45.7% 100k to 1M, Enforced tier: 19.4% 19.4% 100k to 1M domaincanary.com/research/state-of-dmarc
Rank bucket Measured Valid DMARC Enforced tier
Top 1k 1,000 72.1% 55.8%
1k to 10k 8,998 66.0% 43.8%
10k to 100k 89,924 57.0% 31.5%
100k to 1M 899,608 45.7% 19.4%

Fewer domains publish a record further down the list, and the enforced share falls faster than the valid-record share.

The buckets cover the Tranco million only; the 766 federal cohort domains outside the million are measured in the overall shares but sit in no bucket.

Monitoring theater

The rua tag on a DMARC record names the addresses where receivers send aggregate reports. A record with a rua on it looks like monitoring. Whether anything can arrive depends on a second record, published by the destination.

128,980
p=none with no reachable rua
34,506
unauthorized external rua
29,782
every rua destination dead
161,990
authorized external rua

128,980 domains publish a p=none DMARC record whose reporting address is missing, dead, or never authorized. That is 12.9% of measured domains and 27.5% of every valid record in the scan. This report calls it monitoring theater. The record passes a presence scan as adoption, and no report it requests ever arrives.

The only line DNS can draw is whether a destination can receive the report at all. Whether anyone reads what arrives is not measurable from the outside, so the monitoring tier means reports can land, and nothing stronger.

When the rua address sits on another organization's domain, RFC 7489 requires an authorization TXT record at <domain>._report._dmarc.<rua-host>. Receivers that do not find a DMARC version tag there must not send the reports, and they emit no error to the domain that named the address. 34,506 domains on this scan name at least one external report address that never authorized them, and receivers discard the reports addressed to those destinations.

29,782 domains name only destinations that are provably dead. That subset overlaps the unauthorized-external group, and a domain can appear in both. Neither subset covers the whole dead tier, since a p=none record with no rua tag also counts as dead by naming no destination at all.

192,507 domains name at least one external reporting address. 143 of those could not be resolved to a verdict and are counted as neither authorized nor dead. The categories are per destination and are not exclusive. At least 4,132 domains name more than one kind, which is why the counts sum past the total.

SPF

DMARC passes on SPF or DKIM alignment, so an SPF record that receivers refuse to evaluate takes half the alignment surface with it.

64.0%
of measured domains publish SPF
5.7%
of published SPF records permerror

639,891 of the 1,000,296 measured domains publish an SPF record. 36,736 of those records (5.7%) return permerror, the state where receivers refuse to evaluate the record at all: 16,592 exceed the ten-lookup limit and 10,474 publish more than one record, and the two causes overlap.

Terminal qualifier

EndingDomainsShare
-all (fail) 236,588 39.2%
~all (softfail) 332,225 55.1%
?all (neutral) 15,856 2.6%
+all (pass everything) 427 0.1%
no all mechanism 18,059 3.0%

Shares are of the 603,155 domains with a usable SPF record. Records that already permerror are left out, because receivers never reach their final mechanism.

US federal civilian domains

CISA Binding Operational Directive 18-01 required these domains to reach p=reject.

TierDomainsShare
No record 198 15.0%
Broken 6 0.5%
Dead reporting 25 1.9%
Monitoring 20 1.5%
Partial enforcement 9 0.7%
Enforced 1,063 80.5%

The enforced count, 1,063, sits above the reject count, 1,046, because 26 quarantine domains join the tier and 9 weakened domains leave it.

The federal reject share, 79.2% (1,046 domains), towers over the general population: across the whole scan, 118,165 domains (11.8%) publish p=reject, a baseline that itself contains this cohort. The gap runs the other way too: 198 federal domains (15.0%) publish no DMARC record even though the directive's p=reject deadline passed in October 2018, and 25 publish a dead record.

1,321 domains in the cohort. 79.2% publish p=reject and 81.2% publish quarantine or reject.

Who receives the reports

The rua tag is the one part of a DMARC record that names a collector, so counting those names measures which platforms are named to receive reports. The largest named collector is Cloudflare, on 27,809 domains, followed by Brevo at 15,817 and Valimail at 14,379.

A free collector changes who can get a first working rua, because the operator does not need a contract before reports start arriving, which is what moves a record from dead to monitoring. Cloudflare, the largest collector in the scan, offers its collection free with the domain, and Postmark's free DMARC Digests also sits in the top six.

Each bar counts the domains whose rua list names a destination belonging to that platform, once per domain. A domain naming two platforms counts for both.

Domains reporting to each DMARC platform (top 12 of 26 named) Cloudflare 27,809, Brevo 15,817, Valimail 14,379, Proofpoint 12,762, dmarcian 10,392, Postmark 10,201, Mimecast 6,717, GoDaddy 5,925, Red Sift 5,429, EasyDMARC 5,315, MxToolbox 4,882, DMARC Advisor 3,068. Cloudflare: 27,809 domains Cloudflare 27,809 Brevo: 15,817 domains Brevo 15,817 Valimail: 14,379 domains Valimail 14,379 Proofpoint: 12,762 domains Proofpoint 12,762 dmarcian: 10,392 domains dmarcian 10,392 Postmark: 10,201 domains Postmark 10,201 Mimecast: 6,717 domains Mimecast 6,717 GoDaddy: 5,925 domains GoDaddy 5,925 Red Sift: 5,429 domains Red Sift 5,429 EasyDMARC: 5,315 domains EasyDMARC 5,315 MxToolbox: 4,882 domains MxToolbox 4,882 DMARC Advisor: 3,068 domains DMARC Advisor 3,068

140,904 matches across 26 platforms. The largest destination that matches no platform in the list is axa.com, named by 3,904 domains; a destination like this is usually a company collecting reports for its own portfolio of domains rather than a vendor.

MTA-STS, TLS-RPT and BIMI

These three records tend to follow DMARC, and each one sits far behind it.

9,520
MTA-STS policy record
11,442
TLS-RPT record
17,339
BIMI record

As shares of the 1,000,296 measured domains: 1.0% MTA-STS, 1.1% TLS-RPT and 1.7% BIMI.

Methodology

Population Tranco list JZ8PY, 1,000,000 domains, plus the cohort frames below. 1,000,766 rows were scanned in total.
Frames tranco: 1,000,000 domains from https://tranco-list.eu/list/JZ8PY
cohort:us-federal-gov: 1,321 domains from research/cohorts/us-federal-gov.csv
555 cohort domains also rank in the Tranco million and were scanned once, which is why the frames sum to more than the row count.
Collection window 2026-08-20T07:24:24.037Z to 2026-08-21T08:47:10.620Z. Aggregated 2026-08-23T21:05:32.632Z.
Resolver Queries went to unbound:5353, with retries against 1.1.1.1, 8.8.8.8.
Error rate 470 DMARC lookups failed after retries, which is 0.05% of the scanned rows. Those rows are excluded from every share on this page.
Public Suffix List Whether a reporting address is external is decided by comparing organizational domains against the Public Suffix List fetched 2026-08-19T18:23:44.687Z, sha256 780c7961bd74b9ee. The list is pinned per snapshot so a re-run classifies destinations the same way.
Multiple records More than one v=DMARC1 record at _dmarc is invalid per RFC 7489. This scan scores those 4,477 domains as broken.
Vendor classification Each rua destination is classified by the host that receives the mail, so a platform reselling another platform's collection counts under the receiving host. Hosts the map does not recognize stay unmatched rather than guessed.
Absence versus failure NXDOMAIN or an empty TXT answer is absence. A timeout or SERVFAIL after retries is unknown. Failures are never counted as absence.
Independent comparison The adoption tracker at dmarcdkim.com/dmarc-adoption (retrieved August 2026), which updates daily over a different population of 1.35 million accumulated domains, reports 11.4% at full reject where this scan finds 11.8% (118,165 domains) at p=reject. This scan's count includes 1,858 rejects weakened by pct and 7,758 with a weaker sp, which the tier framework scores as partial. The two measurements land close on policy rates. Their adoption headlines differ because the tracker measures domains that came to its attention, a set that leans toward owners who already care about email, while a pinned Tranco snapshot includes every popular domain whether or not anyone ever thought about its mail.
Scanner Version a551ef2-dirty.

Limitations

This measurement reads what domains publish in DNS, so nothing in it reports a delivered-mail pass rate or an actual rejection.

A domain that publishes a reporting address that the scan could not resolve to a verdict is counted as neither authorized nor dead, which holds the headline figures down rather than up.

  • This edition covers one scan window, so it reports a level, not a trend.
  • DNS at a million names still fails. 470 lookups ended in error after retries and are excluded rather than scored as no DMARC. The remaining flakiness is a bound on every rate.
  • rua authorization was checked at scan time only. A destination that authorized the next day, or revoked the next day, is not in this snapshot.
  • The named cohort is one list so far: 1,321 US federal domains. Other planned cohorts are not in this edition.
  • Vendor classification of rua hosts is incomplete; unmatched destinations will move into named platforms in later revisions.

The data

Using this

The aggregate data is published under CC BY 4.0: reuse it, including commercially, with attribution. Suggested citation:

DomainCanary. State of DMARC, 2026-08. https://domaincanary.com/research/state-of-dmarc. Data licensed CC BY 4.0.