One-third of top 10,000 websites lack DMARC email authentication, 2026 scan finds
A June 2026 analysis of the Tranco top 10,000 domains found that 33.4% publish no DMARC record, leaving them without any published policy for handling email authentication failures. Even among domains that do have DMARC, only 46.5% are set to the strictest enforcement level, p=reject, while 26% remain at p=none, which monitors but does not block suspicious email. One in four domains also had no SPF record, and 1.7% published SPF records that exceed the DNS lookup limit, causing silent authentication failures. MTA-STS, a standard that enforces TLS encryption during email delivery, was almost entirely absent, with 97.8% of domains lacking a policy. The findings suggest that while awareness of email authentication standards has grown — especially after Google and Yahoo mandated DMARC for bulk senders in 2024 — most deployments stall before reaching meaningful protection.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in