68.4% of Domains Still Don't Enforce DMARC After 14 Years
Original: DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It
Why This Matters
DMARC enforcement gaps leave the majority of company domains exposed to email spoofing and phishing attacks.
CipherCue analyzed DNS records for 67,336 domains between April and July 2026 and found that 68.4% — or 46,071 domains — either have no DMARC record or have one set to p=none, meaning no enforcement. Only 16.3% use p=reject, the strictest setting.
DMARC (Domain-based Message Authentication, Reporting and Conformance) has been a publicly available email authentication standard since 2012, yet enforcement remains low. CipherCue's analysis of 67,336 tracked domains found that 30,362 (45.1%) have no DMARC record at all. Of the 36,974 domains that do have a record, 15,709 (42.5%) are set to p=none — a monitoring-only mode that collects data but does not instruct receiving servers to quarantine or reject unauthenticated mail. Only 10,963 domains (16.3% of all checked) have reached p=reject, the fully enforcing policy. Another 10,258 (15.2%) use p=quarantine.
CipherCue attributes the stall at p=none not merely to inertia, but to fragmented reporting infrastructure. Analysis of 36,974 DMARC records revealed 10,268 distinct rua= reporting domains across 26,179 reporting addresses; 79% of those domains appear only once in the dataset. Major reporting endpoints include Proofpoint (1,605 appearances) and Cloudflare (1,273). The company notes that without consolidating and interpreting aggregate reports, domain owners cannot confidently identify all legitimate mail sources — a prerequisite for safely moving to enforcement. The analysis covers CipherCue's tracked entity set and is not claimed to be a statistically representative global sample.