Despite being publicly available since 2012, 68.4% of company domains still do not enforce DMARC, a protocol designed to prevent unauthorized use of email domains. CipherCue analyzed 67,336 domains between April and July 2026, finding that 30,362 domains (45.1%) lack any DMARC record, while only 10,963 domains enforce it fully, according to ciphercue.com.
DMARC (Domain-based Message Authentication, Reporting & Conformance) is a free DNS record that instructs receiving mail servers on how to handle emails failing authentication checks, such as whether to report, quarantine, or reject them. The protocol focuses on preventing spoofing of the visible 'From' address but does not address lookalike domains or phishing from compromised accounts. CipherCue's dataset, though not fully representative globally, provides a snapshot of enforcement levels across a large sample of company domains.
The slow adoption of DMARC enforcement leaves a significant gap in email security for many organizations, exposing them to phishing and spoofing risks. Compared to the 14 years since DMARC's introduction, the low enforcement rate highlights ongoing challenges in email authentication adoption. This gap persists despite the protocol being a standard recommendation for protecting brand domains and reducing fraudulent emails, underscoring the need for increased awareness and implementation.
CipherCue's analysis, published on July 28, 2026, highlights that only about 16.3% of the analyzed domains fully enforce DMARC policies, while the majority either lack records or have non-enforcing policies. The next comprehensive update on DMARC adoption is expected as organizations continue to address email security amid rising cyber threats.