Most email security statistics come from surveys of the companies that answered. These count the public DNS records of every domain on the internet that can receive mail, which is where the answer actually lives.
Email authentication is one of the few security controls anyone can check from the outside. SPF, DKIM and DMARC live in public DNS, so whether a domain can be forged is a matter of record, not of opinion or survey answers.
Most figures below come from StackScan's SPF and DMARC study of 173 million mail domains, which read the DNS of every domain on the internet that can receive mail instead of a sample of large companies. That difference is why the numbers look worse than the usual vendor reports: the long tail of small domains is where protection is thinnest.
Every share is of the 173,136,975 domains that publish an MX record unless the line says otherwise.
A domain with no SPF and no DMARC still sends mail perfectly well. It is simply unprotected, because a receiver has nothing to check a forged message against.
Coverage
Share of the 173.1 million domains that can receive mail1
Every domain in the grey part can be named as the sender of a message, and a receiver has no record to check it against.
Enforcement
p=none, 30,281,845 domains. It asks for reports and tells receivers to deliver the message anyway.1v=DMARC1; p=none;, which enforces nothing: 11,543,817 of them.1Broken records
_dmarc, where no receiver will ever look for it.1By provider
Share of each provider's customer domains that publish SPF1
The platform sets the default, and most domains keep whatever they were given.
Domains without mail
Strictness
~all, enforce DMARC. That is lower than the domains with no SPF.1-all, enforce DMARC, the only group that clearly behaves differently.1The rules
29.0% of the 173.1 million domains that can receive mail publish a DMARC record, and 12.5% have one that enforces quarantine or reject. The rest either publish nothing or ask receivers to deliver forged mail anyway.
Nothing to the message. It asks receivers to send reports and deliver the mail normally. It is meant as a short monitoring stage before enforcement, and 45.8% of published DMARC records never leave it.
No. SPF checks the envelope sender, which the recipient never sees. DMARC is what ties the visible From address to SPF or DKIM and tells the receiver what to do when that check fails.
Yes, and more easily than one that does. 88.2% of websites with no MX record publish neither SPF nor DMARC. A one-line SPF record of v=spf1 -all and a DMARC policy of reject closes the gap.
Each figure was read from its source rather than from a roundup. The mail figures describe all 173.1 million domains with an MX record as StackScan measured them in September 2026; shares of DMARC records use every published record as the base where the line says so.
Nothing here comes from a survey. The measurements come from DNS records, either StackScan's or the OpenINTEL data behind The Register's report. Where a number is a rule rather than a measurement, the source is the provider's own announcement or reputable coverage of it.
The wider picture is in our cybersecurity statistics, and the AI in B2B sales numbers cover the other side of the inbox.
Want to see what a domain runs before you trust mail from it? Fifteen website technology checkers, compared.