MailTester Ninja

← All insights · Mon, 03 Aug 2026

The DMARC enforcement gap: 64.5% publish it, only 22.9% enforce it

Most domains that publish DMARC never actually turn it on. Here's the data.

Across 50,000 of the world's most-linked domains, 64.5% publish a DMARC record. Sounds healthy, until you read the policy.

Only 22.9% of all domains are on p=reject. Of the domains that publish DMARC at all, the split is:

p=none is monitoring only: it asks receivers to do nothing. A domain on p=none announces a policy it doesn't enforce, spoofable in practice, even though the record exists. The takeaway for anyone sending or securing email: publishing DMARC is not the same as being protected by DMARC. The path is p=none → p=quarantine → p=reject, and most of the web stops at step one.

Free deliverability tools → Check any domain (MX, SPF, DMARC), test your own inbox placement scored out of 100, generate SPF and DMARC records, or run a blocklist check, all free with no signup and nothing stored, at deliverability.mailtester.ninja/tools.
Verify a real address → This is aggregate DNS data. To check whether a specific email address exists and is deliverable, use MailTester Ninja , real-time, nothing stored.

Data: MailTester Ninja Email Infrastructure Index, 50,000 domains, snapshot Mon, 03 Aug 2026 04:19:04 GMT. Reuse freely under CC BY 4.0.

FAQ

What does p=none mean in DMARC?

p=none tells receiving mail servers to take no action on messages that fail DMARC, it is monitoring only. The domain is not protected against spoofing until it moves to p=quarantine or p=reject.

What percentage of domains enforce DMARC with p=reject?

In MailTester Ninja's 50,000-domain sample, 22.9% of all domains enforce DMARC with p=reject.

Data · Email checker · Email verifier · Blocklist checker · Blocklists explained · Widget
Built & updated automatically by MailTester Ninja, the email verifier that stores nothing. DNS-only, aggregate data, no personal information. · JSON API · RSS