The 2026 DMARC adoption numbers: 52.1% have a record, ~9% are actually protected
EasyDMARC's 2026 report puts DMARC adoption at 52.1% of top domains, up from 47.7% — but a record isn't protection. Here's what the enforcement gap means.
By Norbelys Chirinos, Co-founder
Founder-reviewed ·How we research and correct articles
Two DMARC vendors published their 2026 state-of-adoption research within weeks of each other, and they tell the same story from different datasets: more domains than ever publish a DMARC record, and most of those records still don’t do anything.
EasyDMARC’s 2026 DMARC Adoption & Enforcement Report, scanning roughly 1.8 million top domains worldwide, found 937,931 domains (52.1%) with a valid DMARC record, up from 858,782 (47.7%) in 2025 and 523,921 in 2023. That’s real, sustained growth — DMARC adoption has crossed the halfway mark of the domains EasyDMARC tracks for the first time. DMARC Report’s write-up of the same dataset leads with the harder number: only about 9% of domains are actually protected, meaning the record does something — quarantines or rejects unauthenticated mail — instead of just watching it happen.
Separately, Valimail’s 2026 State of DMARC Report — a different vendor, different domain sample, published a few weeks later — arrives at the same shape of conclusion through its own telemetry: DMARC “awareness” has climbed to 78%, but enforcement has plateaued around 42%, a gap Valimail calls the 36-point “Enforcement Gap.” Different numbers because it’s a different dataset and a different definition of adoption, but the same finding twice, from two vendors with no reason to coordinate a shared narrative.
Adoption and enforcement are two different claims
If you’ve read p=none vs. p=quarantine vs.
p=reject, you already know the
mechanics: a DMARC record can sit at p=none (watch and report, block
nothing) all the way through p=reject (refuse anything that fails). This
post isn’t re-explaining that ladder — it’s reporting where the industry
actually sits on it in 2026, and the answer is: near the bottom.
“We have DMARC” and “we’re protected against spoofing” are not the same
claim, and the 2026 numbers make the size of the gap between them explicit.
A domain with p=none published is, by every scanning tool, correctly
counted as “having DMARC.” It is also, in practical terms, doing nothing to
stop someone from sending fraudulent mail that appears to come from it.
What the split actually looks like
EasyDMARC’s report breaks the 52.1% down further, and the gap between large, resourced organizations and everyone else is stark:
- Fortune 500: 475 of 500 companies (95%) have adopted DMARC, and more
than 80% have reached an enforcement-level policy. 62.7% are at full
p=reject. - Inc. 5000 (high-growth mid-market): adoption is common, but only 15.2%
have reached
p=reject— nearly four times fewer than the Fortune 500’s rate.
That split matters more than the headline percentage. It means the
industry-wide 52.1% adoption figure is being pulled up by large enterprises
that have security teams dedicated to exactly this kind of DNS hygiene, while
the long tail of smaller, faster-growing companies — the ones most likely to
be reading a cold-email blog post about DMARC — are disproportionately still
sitting at p=none, unprotected, even when they technically “have DMARC.”
That’s precisely the gap Norbelys DMARC monitoring
exists for — a growing company sending cold outreach doesn’t have a Fortune
500 security team reading aggregate reports every week, but it’s exactly the
kind of domain a spoofer benefits from targeting.
Why this is worse news for smaller domains
Spoofers don’t check whether a domain “has DMARC” before choosing a target —
they check whether the policy actually blocks unauthenticated mail. A
p=none record is functionally invisible to an attacker impersonating your
domain in a phishing email; the record only becomes a defense once it’s
enforced. So the honest reading of “52.1% adoption, ~9% protected” isn’t
“the industry is halfway there.” It’s closer to “the industry has told
itself it’s halfway there, and roughly one domain in eleven has actually
finished.”
The trend line is genuinely positive — adoption climbing from 47.7% to
52.1% in a year, and enforcement-level policies rising alongside it
(EasyDMARC counted 411,935 domains at p=quarantine or p=reject, up
meaningfully from prior years) — is real progress. It’s just progress from
a low base, and it means most of the domains you exchange email with today,
including ones sending to your prospects and receiving your cold email
replies, are still running with the protection turned off.
Where the 2026 numbers put a typical domain
It helps to place a domain against the actual distribution rather than the single 52.1% headline, since “adoption” collapses four very different states into one number:
| Policy state | Rough share of the 1.8M domains scanned | What it actually means |
|---|---|---|
| No DMARC record | ~48% | Zero visibility, zero protection — anyone can spoof the domain and neither the owner nor the receiver gets a signal. |
p=none |
Largest slice of the 52.1% | “Has DMARC,” reports flowing, zero mail actually blocked. |
p=quarantine |
Smaller slice, growing | Failing mail routed to spam — real friction for spoofers, moderate risk of misrouting your own mail if reports weren’t reviewed carefully first. |
p=reject |
~9% (the “actually protected” figure) | Failing mail refused outright. The only state that stops a convincing spoof of your exact domain from reaching an inbox. |
A domain sitting in the second row can accurately tell a customer, a partner, or an auditor “we have DMARC” — and the statement would be true and still leave a spoofer a completely open door. That’s the exact gap these two reports are measuring, and it’s why “do you have DMARC” is increasingly the wrong question to ask a vendor or a partner domain; “what policy is it enforcing” is the one that actually tells you anything.
What this means if you’re running a sending program
If your own domain is one of the roughly 43% still parked at p=none, the
2026 numbers are a reason to treat the climb to enforcement as a project
with a deadline rather than something to get to eventually — see DMARC
setup for a new domain before you send your first cold
email for the sequence, and the
policy ladder itself in p=none vs. p=quarantine vs.
p=reject.
If you’re evaluating a domain you don’t control — a vendor, a partner, a company you’re about to trust with an integration — “they have DMARC” is no longer a sufficient answer in 2026. Check the actual policy tag. Norbelys DMARC monitoring tracks that distinction continuously for every domain you own, surfacing not just whether a record exists but whether it’s actually doing anything — because after this year’s numbers, that’s the only version of the question worth asking.
FAQ
Frequently asked questions
Why do EasyDMARC and DMARC Report show different-looking numbers from the same data?
EasyDMARC's headline is the raw adoption figure (52.1% of scanned domains have any valid DMARC record). DMARC Report's write-up of the same underlying dataset highlights a stricter cut — the ~9% at enforcement-level policy. Both numbers are accurate; they're answering different questions about the same 1.8 million domains.
Is Valimail's 42% enforcement figure the same as EasyDMARC's ~9% protected figure?
No, and they shouldn't be compared directly. Valimail uses its own tracked domain population and telemetry, and defines its 'Enforcement Gap' between awareness and enforcement differently than EasyDMARC defines adoption versus protection. Both point at the same underlying problem — adoption outpacing enforcement — from different samples.
If my domain is at p=none, does that count as having DMARC at all?
Yes, for adoption-counting purposes any published, valid DMARC record counts, including p=none. It just doesn't count toward the 'protected' or enforcement-level figures, which specifically require p=quarantine or p=reject.