The DMARC Adoption vs. Enforcement Gap and the Risk It Leaves
In our 2026 Cyberthreat Report: DMARC & The Identity Reckoning, we found that complying with email providers’ sender mandates requiring a p=none policy was the easy part. Enforcing DMARC is where most organizations still fall short.
Adoption keeps climbing, but enforcement at p=reject, the only policy that blocks phishing and spoofing, is lagging, and the gap continues to expand.
DMARC Adoption vs. Enforcement Gap
In a group of 34,212 domains tracked over three annual checkpoints from 2024 to 2026, 71.5% of domains adopted DMARC, but only 26.6% enforced it at p=reject, leaving a 44.9-point gap by 2026
90%
Of 1.65 million domains scanned, nearly 90% are exposed to outbound phishing and spoofing

Get the full report
Fill in the form below to get your copy of the report.
Key Findings
Top Threats to Email Identity
$4.99 million
Record global average cost of a data breach in 2026
$3 billion+
BEC losses in 2025, making it the second most expensive cybercrime overall
56%
Year-over-year increase in AI-driven attacks
#1
Phishing/spoofing was the top reported cybercrime in 2025
AI Breaches Cost $1M More
Breaches involving AI-driven attacks cost roughly $1 million more than the average, with AI enabling attackers to accelerate and scale attacks.
The State of DMARC
Portion of the domains within the dataset that have reached full DMARC enforcement with a p=reject policy¹
The percentage of domains that remained exposed with a p=none policy across three annual checkpoints²
DMARC Enforcement Results
192.2 million
Unauthenticated emails blocked by Sendmarc-protected domains enforcing p=reject, June 2025 to June 2026
64.6 days
Average time for a Sendmarc customer to reach p=reject, across 1,207 implementation projects
- Based on Sendmarc's scan of 1.65 million domains (February 2024-June 2026): Sendmarc's own observed data, not a study of the entire internet. Absolute figures may differ from other studies, but the trends and pace of change are believed to be broadly representative.
- Adoption and enforcement trends are based on a balanced cohort of 34,212 domains tracked at three annual checkpoints. This cohort skews toward more actively monitored domains, so results may run more optimistic than the full population would show.
DMARC Policy Distribution
p=reject:
The only policy that blocks outbound phishing and spoofing before it reaches an inbox.
p=none:
Monitoring-only remains the most common policy among domains that have adopted DMARC at all. It is also the state that does nothing to stop phishing and spoofing.
The Adoption vs. Enforcement Gap
Overall trends in Sendmarc's data suggest that the challenge has shifted from encouraging organizations to publish DMARC records to progressing them from monitoring to enforcement.
More DMARC Records But Lagging Protection
To accurately evaluate DMARC adoption versus enforcement, we tracked the same 34,212 domains across three annual checkpoints in June 2024, June 2025, and June 2026. Over those two years, adoption climbed 22.9 percentage points. Encouragingly, p=reject enforcement increased as well, though at a slower pace, rising by just 14 percentage points.
The gap between DMARC adoption and enforcement has widened from 36 percentage points in June 2024 to 44.9 percentage points in June 2026, which may reflect domain owners' hesitancy to enforce DMARC.
The trend above is likely a more optimistic picture of adoption and enforcement than the full landscape would show.
2026 Email Threat Trends
What lands in an inbox doesn't necessarily look different from a year ago. What's changed is the mechanism behind it and who can produce it - executing a convincing email impersonation scam used to take real skill. AI has erased that requirement, and attacks are now more easily calibrated to the target: tuned to a company's size, industry, and the role of the person on the receiving end, rather than fired out at scale.
PhaaS Kits Lower Attack Cost
Attackers now use phishing-as-a-service (PhaaS) kits that can generate a unique link and attachment for every send, defeating the deny-list approach that has anchored email security for two decades.
Criminals Are Adopting DMARC
Phishing domains are increasingly configured with a fully enforced DMARC record, using the same protocol legitimate senders rely on to verify sender identity to make a spoofed domain appear more credible.
Attackers Target Authority
Criminals go after individuals with financial authority, data access, or administrative control. Executives sense this: the WEF's Global Cybersecurity Outlook 2026 found cyber-enabled fraud and phishing became CEOs' top concern this 2026.
Distribution of Cyberattacks Across Worldwide Industries in 2025
In 2025, manufacturing and the finance and insurance sector were most targeted, absorbing 27.7% and 27% of worldwide cyberattacks, respectively - more than five times the average share across the other eight sectors, and roughly three times the next-highest sector.
Source: Statista
Cybercrime, Region by Region
Risk doesn't look the same everywhere.
United Kingdom
United States
Europe
Australia
South Africa
Latin America and the Caribbean
India
DMARC Mandates

October 2017
CISA BOD 18-01 orders federal agencies to enforce SPF, DKIM, and DMARC at p=reject

2018
UK government departments required to implement DMARC at p=reject

February 2024
Google and Yahoo's bulk sender mandate takes effect (p=none)

March 2025
PCI DSS v4.0/v4.0.1 recommends DMARC

April 2025
Yahoo tightens enforcement, moving to domain-based reputation scoring. Non-compliant senders see sharp deliverability drops

May 2025
Microsoft mandates DMARC for bulk senders (p=none)

July 2025
Cloudflare requires all emails sent through its Email Routing platform to pass SPF or DKIM and strongly recommends DMARC

November 2025
Google escalates to permanent rejections for non-compliant emails

May 2026
GMX, WEB.DE, and mail.com announce a DMARC mandate and phased rollout to p=reject
Expert Point of View on the DMARC Shift
"A lot of domains never adopted authenticated email because they were getting their mail accepted, and now we're at a point where certain classes of senders aren't getting their mail accepted because they're not authenticating properly."

Todd Herr
Co-editor of DMARCbis | Principal Solution Architect, Green Arrow
The report also includes perspectives from Sean Remnant, Chief Strategy Officer at Ignition Technology, on what should top every CISO's priority list right now; Mike Britton, Chief Information Officer at Abnormal AI, on modern email attacks; Kieran Frost, Chief Operations Officer at Sendmarc, on the DMARC adoption and enforcement gap risk; and Keith Thompson, Co-Founder and Chief Technology Officer at Sendmarc, on where authentication is headed.
DKIM's Next Chapter: DKIM2
The original DKIM standard has several structural weaknesses. Most notably, a signed, legitimate email can be replayed to recipients it was never meant for, pass verification, and be used to deliver malicious content - even on domains enforcing a strict p=reject DMARC policy, since the replayed email still carries a genuinely valid signature. DKIM2, a proposed IETF update, closes that gap.
Major mailbox providers, including Google and Yahoo, plan to begin experimental DKIM2 verification in the fourth quarter of 2026, with production rollouts expected in the first quarter of 2027.

Reaching p=reject Depends on Who's Managing DMARC Implementation
Having a DMARC record doesn't mean you're protected. It means you've started monitoring. Most organizations stall before reaching p=reject, and how far they get depends on who's running the process.
We compared current domain states across three groups drawn from a broader dataset: Sendmarc-managed domains, other DMARC providers, and self-managed, showing where each group's DMARC journey progresses, stalls, or breaks down.
Monitoring rates are almost identical for DIY domains and other providers, at roughly 43%. The real divergence shows up later. DIY environments accumulate at p=quarantine, while Sendmarc-managed domains are far more likely to progress all the way to p=reject.
The report also details an error rate and journey completion rate comparison.
Lookalike Domain Attacks:
Technique Distribution
DMARC stops exact domain spoofing. Criminals get around it by registering a domain that looks close enough to yours that people trust it at a glance. This donut chart shows a breakdown of the lookalike techniques cybercriminals used over three years.
Dictionary word substitution
Replacing part of a brand name with a common word or misspelling, like "yourbank-support.com" instead of "yourbank.com."
Font-obscure
Swapping in a character that renders almost identically to another, such as a capital "I" standing in for a lowercase "l".
TLD swap
Registering the same brand name under a different domain ending, like ".net" or ".co" instead of ".com."
Homoglyph
Swapping in a character from a different alphabet that looks identical to the human eye, like a Cyrillic "а" in place of a Latin "a."
All remaining techniques
Lookalike Domains Are Getting Harder to Spot
Dictionary-based substitution remained dominant across three years, though its share has declined slightly. The clearest shift is homoglyph-based lookalikes, which nearly tripled. These domains are nearly indistinguishable from the real ones at a glance, making them especially effective at deceiving employees into clicking a malicious link or approving a fraudulent invoice before anyone notices something is wrong.
The report also breaks down the volume of lookalike domains with active websites and email sending infrastructure.
The Cost of Leaving Email Unprotected
Costs multiply
Recovery costs add up fast: legal fees, regulatory fines, even ransom payments, on top of stalled deals and customers walking. It can be enough to end a business.
Trust erodes
One impersonation email can undo years of goodwill in days. IBM found that 41% of ransomware attacks now threaten to damage the organization's reputation.
Communication stalls
A blocklisted domain, or legitimate mail that starts bouncing, cuts the line to customers, suppliers, and partners who rely on it.
Operations halt
A fraudulent payment, hijacked vendor conversation, or ransomware lockout can stall core processes as staff pivot their effort to remediation.
Scrutiny intensifies
Authentication rules keep tightening, and non-compliance leaves you exposed to attacks and invites regulatory and legal consequences too.
From p=none to Protection
Closing the gap between DMARC adoption and enforcement takes a sequence of deliberate steps, not one switch.
1
Start with the fundamentals
SPF and DKIM need to be set up correctly before anything else. Rushing past this step is exactly what breaks legitimate email later.
2
Move up in stages, deliberately
Go from p=none to p=quarantine to p=reject, checking reports at each stage. Skip a stage, or rush the timeline, and that's what breaks legitimate email.
3
Don't stop at your exact domain
Full enforcement locks down your exact domain, but it doesn't stop lookalikes. A swapped letter or a different extension is enough to pass at a glance.
4
Revisit authentication as the company evolves
Every new sending tool changes who's authorized to use your domain and letting that list get stale creates a sprawling, unmanageable environment.
5
Pick the route that gets you there fastest
The right DMARC partner supports this journey, replacing manual overhead with continuous visibility, guided steps, and ongoing monitoring at every stage.

Where Sendmarc Comes In
Sendmarc provides enterprise-grade DMARC management, backed by expert support and a guaranteed path to full protection. Our team helps security teams roll out, scale, and reach full DMARC enforcement across complex, multi-domain environments, without adding to the operational load.
Lookalike Domain Defense and Breach Detection extend that coverage further, closing gaps enterprise security teams would otherwise have to watch for on their own.
DMARC FAQs
Does DMARC filter spam out of my inbox?
No, DMARC doesn't filter inbound email. It governs how other servers treat messages claiming to be from your domain, which protects your identity in outbound emails and the people receiving them.
Is DMARC a one-time setup?
No, DMARC isn't a one-time setup. Organizations add new vendors and sending tools constantly, so an unmonitored DMARC record drifts out of date. Ongoing monitoring keeps protection in place and legitimate email flowing.
Does a DMARC provider route my email through its servers?
No, a DMARC provider never touches your email stream. The entire mechanism runs through the DNS, and the reports only contain authentication details.
Does publishing a DMARC record protect my domain?
No, publishing a DMARC record doesn't protect your domain on its own. Enforcement only works if the receiving server evaluates DMARC and honors your policy. At p=none, there's nothing for a receiver to enforce. Protection depends on two things lining up: your organization publishing an enforcement record of p=quarantine or p=reject, and receivers honoring it.
Can I read DMARC reports without a dedicated tool?
Technically, yes, but DMARC reports come in as raw XML, pulled from dozens of different sources. Parsing that volume of raw data without the right tooling is one of the biggest reasons enforcement projects stall.
Do I need DMARC if I already have SPF and DKIM?
Yes, you need DMARC even if you already have SPF and DKIM. SPF and DKIM each verify one mechanism in isolation. DMARC tells receiving servers how to handle email that failed authentication and provides reporting.
Will enforcing DMARC break my email delivery?
Enforcing DMARC blocks legitimate email when a sender hasn't been authenticated first. The risk comes from moving to enforcement before every legitimate sender is identified. A monitored rollout reduces that risk.
Does a DMARC record guarantee inbox placement?
No, a DMARC record doesn't guarantee inbox placement. Authentication improves the odds that your email reaches the inbox. It works alongside sound sending practices.