← All insights · Mon, 03 Aug 2026
Most domains that publish DMARC never actually turn it on. Here's the data.
Across 50,000 of the world's most-linked domains, 64.5% publish a DMARC record. Sounds healthy, until you read the policy.
Only 22.9% of all domains are on p=reject. Of the domains that publish DMARC at all, the split is:
p=none, 36.7%p=reject, 35.5%p=quarantine, 27.8%p=none is monitoring only: it asks receivers to do nothing. A domain on p=none announces a policy it doesn't enforce, spoofable in practice, even though the record exists. The takeaway for anyone sending or securing email: publishing DMARC is not the same as being protected by DMARC. The path is p=none → p=quarantine → p=reject, and most of the web stops at step one.
Data: MailTester Ninja Email Infrastructure Index, 50,000 domains, snapshot Mon, 03 Aug 2026 04:19:04 GMT. Reuse freely under CC BY 4.0.
p=none tells receiving mail servers to take no action on messages that fail DMARC, it is monitoring only. The domain is not protected against spoofing until it moves to p=quarantine or p=reject.
In MailTester Ninja's 50,000-domain sample, 22.9% of all domains enforce DMARC with p=reject.