Email security · September 2026

Email security in 2026: 22 numbers on SPF, DMARC and who can forge your domain

Most email security statistics come from surveys of the companies that answered. These count the public DNS records of every domain on the internet that can receive mail, which is where the answer actually lives.

22 statistics173.1M domains7 sourcesChecked September 2026

Email authentication is one of the few security controls anyone can check from the outside. SPF, DKIM and DMARC live in public DNS, so whether a domain can be forged is a matter of record, not of opinion or survey answers.

Most figures below come from StackScan's SPF and DMARC study of 173 million mail domains, which read the DNS of every domain on the internet that can receive mail instead of a sample of large companies. That difference is why the numbers look worse than the usual vendor reports: the long tail of small domains is where protection is thinnest.

How to read the percentages

Every share is of the 173,136,975 domains that publish an MX record unless the line says otherwise.

A domain with no SPF and no DMARC still sends mail perfectly well. It is simply unprotected, because a receiver has nothing to check a forged message against.


Coverage

Half of the internet's mail domains publish no SPF at all

Share of the 173.1 million domains that can receive mail1

47.4%52.6%
Publish SPFPublish no SPF

Every domain in the grey part can be named as the sender of a message, and a receiver has no record to check it against.

173.1M
domains on the internet can receive mail: 173,136,975 publish an MX record. That is the population every share on this page is measured against unless it says otherwise.1
52.6%
publish no SPF record, 91,155,504 domains.1
71.0%
publish no DMARC record, 122,890,494 domains.1
12.5%
have a DMARC policy that actually does something, quarantine or reject: 21,685,399 domains.1

Enforcement

Publishing DMARC is not the same as enforcing it

45.8%
of every published DMARC record is p=none, 30,281,845 domains. It asks for reports and tells receivers to deliver the message anyway.1
11.5M
domains publish the single commonest DMARC record on the internet, v=DMARC1; p=none;, which enforces nothing: 11,543,817 of them.1
57.7%
of the domains publishing DMARC ask for no reports at all, 38,148,614 of them. They set a policy and cannot see whether it works.1
4.7%
of the domains publishing DMARC point their reports at a specialist DMARC service, 3,129,895 domains. The whole tooling industry is working with that slice.1

Broken records

Records that exist and still do nothing

679,765
domains publish more than one SPF record. RFC 7208 treats that as a permanent error, so SPF does nothing at all on them.1
355,492
publish their DMARC record on the domain itself rather than under _dmarc, where no receiver will ever look for it.1
10.2M
of GoDaddy's 13,786,006 DMARC domains have no MX record at all. One GoDaddy template string is the second commonest DMARC record on the internet, copied 11,329,644 times.1

By provider

Your mail provider predicts your records

Share of each provider's customer domains that publish SPF1

Microsoft 365
60.0%
Google Workspace
41.8%
GoDaddy mail
6.7%

The platform sets the default, and most domains keep whatever they were given.

38.6%
of the top million domains now receive mail through Google Workspace (21.8%) or Microsoft 365 (16.8%). Self-hosted mail fell from 44.6% of those domains in 2016 to 22.4% in 2026, on DNS data reported by The Register.6
53.9M
domains use GoDaddy for DNS and 45.0M use Cloudflare. Ten companies answer DNS for 49.9% of every domain that publishes a nameserver, so a handful of defaults decide most of the numbers above.2

Domains without mail

The domains that send nothing are the easiest to forge

62M
websites have no MX record, so their owners never think about mail at all.1
88.2%
of those publish neither SPF nor DMARC. A receiver checking a message forged from one of them finds no record and delivers it.1
8.7%
of them enforce DMARC, against 12.5% of mail domains. Where one does publish, it is usually a registrar template, and 73.7% of those templates enforce.1

Strictness

A stricter-looking SPF is not always a safer domain

12.3%
of domains with no SPF at all still enforce DMARC.1
8.5%
of domains whose SPF ends in a soft fail, ~all, enforce DMARC. That is lower than the domains with no SPF.1
21.0%
of domains ending SPF in a hard fail, -all, enforce DMARC, the only group that clearly behaves differently.1

The rules

Why the numbers matter more since 2024

5,000
messages a day to personal Gmail accounts is the line above which Google requires SPF, DKIM and a published DMARC record. Below it, every sender still needs SPF or DKIM.3
75%
fewer unauthenticated messages reached Gmail users after Google's previous round of authentication rules, the company said when it announced the 2024 requirements. Yahoo adopted the same rules.5
May 2025
is when Microsoft applied the same 5,000-a-day rule to Outlook.com, Hotmail.com and Live.com, sending non-compliant bulk mail to Junk first, with outright rejection to follow.7

Questions

29.0% of the 173.1 million domains that can receive mail publish a DMARC record, and 12.5% have one that enforces quarantine or reject. The rest either publish nothing or ask receivers to deliver forged mail anyway.

Nothing to the message. It asks receivers to send reports and deliver the mail normally. It is meant as a short monitoring stage before enforcement, and 45.8% of published DMARC records never leave it.

No. SPF checks the envelope sender, which the recipient never sees. DMARC is what ties the visible From address to SPF or DKIM and tells the receiver what to do when that check fails.

Yes, and more easily than one that does. 88.2% of websites with no MX record publish neither SPF nor DMARC. A one-line SPF record of v=spf1 -all and a DMARC policy of reject closes the gap.

Method and sources

Each figure was read from its source rather than from a roundup. The mail figures describe all 173.1 million domains with an MX record as StackScan measured them in September 2026; shares of DMARC records use every published record as the base where the line says so.

Nothing here comes from a survey. The measurements come from DNS records, either StackScan's or the OpenINTEL data behind The Register's report. Where a number is a rule rather than a measurement, the source is the provider's own announcement or reputable coverage of it.

  1. StackScan, SPF and DMARC Statistics 2026, DNS of all 173,136,975 domains that can receive mail, published 12 September 2026. SPF and DMARC Statistics 2026
  2. StackScan, Web Hosting Statistics 2026, DNS of 292,860,014 resolving domains. Web Hosting Statistics 2026
  3. Google, Email sender guidelines for Gmail. Email sender guidelines
  4. IETF, RFC 7208, Sender Policy Framework. RFC 7208
  5. TechCrunch, Sarah Perez, 3 October 2023, on Gmail's 2024 sender requirements and Yahoo joining them. Gmail to enforce harsher rules in 2024
  6. The Register, Simon Sharwood, 26 August 2026, reporting Artem Berezin's analysis of OpenINTEL DNS data from 2016 to 2026. Self-hosted email is in steep decline
  7. Microsoft, Defender for Office 365 blog, 2025, on Outlook's requirements for high-volume senders. Outlook's new requirements for high-volume senders
Related

The wider picture is in our cybersecurity statistics, and the AI in B2B sales numbers cover the other side of the inbox.

Want to see what a domain runs before you trust mail from it? Fifteen website technology checkers, compared.