Skip to content
← BlogComplianceAnalysis6 min read

The UK blocked 80 million spoofed emails a month. That's what enforcement, not adoption, looks like

National DMARC mandates cut phishing delivery from 69% to 14%. The UK blocked 80 million spoofed emails in 30 days — proof enforcement works.

By Norbelys Chirinos, Co-founder

Founder-reviewed ·How we research and correct articles

If you want one number that argues for DMARC enforcement over DMARC adoption, this is it: after UK central government departments reached 100% strict DMARC enforcement, the National Cyber Security Centre reported that over 80 million spoofed emails were blocked from government domains in a single 30-day period — mail that would previously have been delivered, because nothing was checking whether it was really from who it claimed to be.

That NCSC figure is a few years old now, but it’s still the case study industry reports keep reaching for in 2026, because nobody has published a cleaner before-and-after at national scale since. It’s worth revisiting now precisely because this year’s DMARC adoption numbers show the rest of the world is still mostly stuck where the UK government used to be: record published, protection switched off.

Adoption without enforcement doesn’t stop anything

This is the point our post on the 2026 adoption numbers makes with global data — most domains that publish DMARC never turn it into an active defense. The UK case study is the clean demonstration of why that distinction is the whole ballgame. Before central government departments moved to enforcement, they largely had DMARC records too — visibility into spoofing attempts, aggregate reports arriving, everything except the part where the mail actually got blocked. The 80 million figure is what changed the moment enforcement flipped on: not more visibility, but mail that stopped arriving at all.

Why enforcement blocks mail that a record alone doesn’t

The mechanical difference is smaller than the outcome suggests. A DMARC record with a p=none policy asks receiving mail servers to check SPF and DKIM alignment and report back what they saw — but it explicitly tells them not to act on a failure. The mail gets delivered either way; the domain owner just finds out about it later, in an aggregate report. Flip that same record to p=reject, and the instruction to receiving servers changes to: if this message fails alignment, don’t deliver it at all. Nothing about the underlying authentication changes. What changes is whether a failure has a consequence at the moment the message arrives, instead of a line item in a report nobody reads until the following week.

That’s the entire mechanism behind the UK’s 80 million blocked messages. Spoofed mail claiming to be from a government domain was almost certainly already failing SPF and DKIM checks before the enforcement switch flipped — receiving servers could already tell it wasn’t legitimate. What changed is that “we can tell” became “we will stop it,” and the volume of mail that had been quietly failing checks and getting delivered anyway turned out to be enormous the moment enforcement made that failure count for something.

The pattern holds at the country level, not just one government

EasyDMARC’s analysis of national DMARC mandates found the same effect comparing countries, not just one agency before and after. Countries with government-driven DMARC mandates — the US, UK, and Czech Republic among them — saw the steepest drops in successful phishing delivery. In the US specifically, the rate of phishing emails successfully reaching an inbox fell from 68.8% to 14.2% between 2023 and 2025 — a number close enough to round to the “69% to 14%” figure now circulating in 2026 industry coverage.

The control group makes the case harder to argue with. Countries with voluntary guidance and no enforcement mandate didn’t just fail to improve — some got worse. The Netherlands, despite having DMARC guidance available, saw phishing-delivery vulnerability rise from 76.5% to 97.1% over the same period. Adoption without a mandate to actually enforce policy doesn’t just stall; it can go backward, as legitimate infrastructure changes outpace records nobody’s actively maintaining.

Why “we have a mandate coming” is different from “we have a record”

The distinction matters for anyone building the internal case for DMARC work, because it answers the objection that shows up in almost every one of these conversations: does enforcement actually change outcomes, or is it theater? The UK number is theater’s opposite — it’s a direct, measured count of malicious mail that stopped being delivered as a mechanical consequence of a policy tag changing from p=none to p=reject across a large domain estate.

That argument travels well beyond government. Security Boulevard’s July 2026 look at the financial-services sector found the exact same adoption-without-enforcement pattern in one of the most security-conscious, heavily regulated industries there is: high DMARC adoption, and still a large share of domains not actually enforcing. Regulation and internal maturity get organizations to “we have a record.” Getting to “we block the fake mail” takes a deliberate decision to finish the job — which is precisely what the UK government did, and precisely what most sectors, financial services included, still haven’t.

A few things worth clarifying

Does moving to p=reject risk blocking my own legitimate email?

Yes, if you flip the switch before you know every service that sends mail on your domain's behalf. That's exactly why the climbing path exists — p=none to monitor, p=quarantine to test consequences at reduced risk, then p=reject once aggregate reports confirm every legitimate sender is passing alignment. Skipping straight to enforcement without that review is the single most common way organizations break their own newsletter, invoicing, or support-desk mail during a DMARC rollout.

How long did it take the UK government to reach full enforcement?

The NCSC's Active Cyber Defence programme ran the climb over several years across the whole central government domain estate, not as a single flag flip. The scale is the point: getting hundreds of departmental domains from a bare DMARC record to verified, sustained p=reject enforcement is a coordination problem as much as a technical one — which is exactly why most organizations, including, per the 2026 sector data, most banks, never finish the climb even though starting it takes an afternoon.

Using this as the internal pitch

If you’re trying to justify moving your own organization’s domain from monitoring to enforcement and the response is “we already have DMARC, isn’t that enough,” the UK case study is the concrete answer: no. The record alone changed nothing measurable. Enforcement blocked 80 million messages in a month. If you need the safe, staged path from record to enforcement without breaking your own legitimate mail along the way, see p=none vs. p=quarantine vs. p=reject for the climbing checklist, and how to read your aggregate reports for the step that has to happen before any of it is safe.

For a domain you’re actively sending cold email from, the same logic applies in the other direction too — an unenforced domain doesn’t just leave your own brand exposed to spoofing, it’s also the kind of authentication gap mailbox providers increasingly weigh when deciding whether your legitimate mail lands in the inbox at all. Norbelys DMARC monitoring tracks your policy status continuously — sources, SPF/DKIM alignment, and pass rate all update as reports arrive — so the move from record to enforcement is a planned project with evidence behind each step, instead of something that only gets attention after a national report makes the gap embarrassing. It’s the same climb the UK government made from p=none to p=reject, run against your own domain instead of a national government’s estate, with Norbelys showing you what would have broken before you flip the policy that blocks it.