Dev.to
7/2/2026

The original title is 10 words: "The DMARC enforcement gap: 64.6% publish it, only 22.7% enforce it"
Original: The DMARC enforcement gap: 64.6% publish it, only 22.7% enforce it
Short summary
Analysis of 50,000 domains shows DMARC's critical enforcement gap: while 64.6% publish records, only 22.7% enforce with p=reject policy. Most domains set p=none (monitoring-only), announcing protection without preventing spoofing. Effective DMARC requires progression from p=none → p=quarantine → p=reject; 77% of domains stay at monitoring, leaving email vulnerable.
- •64.6% of top domains publish DMARC, but only 22.7% enforce it (p=reject policy)
- •Most organizations stuck on p=none (monitoring-only) without actual spoofing protection
- •DMARC security requires progression p=none → p=quarantine → p=reject; most stop at step one
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



