← All guides

Only 20% of small organisations actually enforce DMARC

In August 2026 we ran read-only DNS checks on 1,685 US small-business and nonprofit domains. Gmail and Yahoo have required a DMARC record from bulk senders since February 2024. Two and a half years later, 44% of these domains publish no DMARC record at all — and of those that do, most are only watching, not enforcing.

Published 10 August 2026 · Method and limitations are at the bottom · Data is free to reuse with attribution

1,685domains checked
44.0%no DMARC record
20.4%actually enforcing
38.6%have all three records

The headline number is not "no DMARC" — it's "no enforcement"

A DMARC record has a policy attached, and the policy is what decides whether anything happens. p=none means "tell me about failures but deliver the mail anyway" — a monitoring mode, and the correct place to start. p=quarantine and p=reject are the settings that actually stop someone sending mail that appears to come from your domain.

Most organisations that have adopted DMARC never left monitoring mode. Counting them as protected is the mistake almost every adoption statistic makes.

No DMARC record at all44.0%
DMARC, monitoring only (p=none)35.5%
DMARC, enforcing (quarantine or reject)20.4%

n = 1,444 domains with working mail routing. Percentages sum to 99.9% through rounding.

Four out of five small organisations that can receive email are not enforcing DMARC. Their domain can be spoofed today, and their own bulk mail is at growing risk of being filtered by the two providers that carry most consumer inboxes.

Churches and faith organisations are meaningfully worse

We segmented the set by whether the domain name contains a faith-related term. That is a conservative test — it misses initialisms like fbcnt.org (First Baptist Church) — so the faith group is an undercount rather than a precise split. Even so, the gap is consistent across all three records.

 Churches & faith orgsOther small orgs
Domains measured3691,075
No DMARC record50.1%42.0%
Enforcing DMARC14.6%22.3%
No SPF record21.4%16.6%
No DKIM signature53.1%47.3%
All three records present32.5%40.7%

Exactly half of church and ministry domains have no DMARC record, and only one in seven enforces a policy. This matters more for congregations than the raw numbers suggest, because the mail a church sends is precisely the mail that gets impersonated: giving appeals, event changes, and messages that appear to come from a pastor. A domain with no enforced DMARC policy offers no structural defence against any of that.

DKIM is the most neglected record

Nearly half of all domains — 48.8% — have no DKIM signature on any of the common selectors we check. That is higher than the share missing SPF (17.8%), and the reason is straightforward: SPF is a single text record someone copies from a setup guide, whereas DKIM has to be generated and switched on inside the mail platform.

Google Workspace and Microsoft 365 can both sign outbound mail, and neither does so by default. It is a deliberate step in an admin console that many organisations were never told to take. So a domain can be fully migrated to a professional platform and still be sending unsigned mail years later.

Missing DKIM48.8%
Missing DMARC44.0%
Missing SPF17.8%

One in seven domains cannot receive email at all

Of the 1,685 domains checked, 241 (14.3%) have no MX record — no mail routing whatsoever. These are organisations with a live website whose domain cannot accept a message. Some have deliberately moved communication elsewhere; many simply lost mail service at some point and never noticed, because nothing visibly breaks on your own end when your domain stops accepting mail.

We excluded all 241 from the authentication percentages above. Including them would have inflated every "missing record" figure by about 14 points, which is how this kind of statistic usually gets overstated.

What we would tell any of these organisations

The three records take an afternoon and cost nothing but attention:

You can see where your own domain stands in about a second, free and without giving us an email address: run the check.

Method, and what this data is not

Every figure above comes from read-only public DNS lookups — MX, SPF (TXT), DKIM selectors and DMARC — the same records any receiving mail server queries before deciding what to do with a message. No email was sent, no mailbox was contacted, and no credentials were used. All 1,685 domains were re-checked on 10 August 2026 so the finding carries a single date.

The domains come from our own discovery process: web research and public directory listings across a grid of business verticals and US metropolitan areas, gathered while looking for organisations that might need our services. Crucially, this is every domain we discovered — not the subset we judged to be broken. Reporting from the filtered set would have described our own selection criteria rather than the population.

What this is not: a random sample of US organisations. Every domain here belongs to an organisation with a website that appears in some public listing, which skews toward the more established end of small business and away from organisations with no web presence at all. Treat it as a well-defined slice, not a national estimate. The faith segment is identified by domain name and therefore undercounts.

No individual domain is published, and we will not share the list. Only aggregates leave our systems. If you are a researcher or journalist who wants the aggregate broken down differently, email tyler@switchmyemail.com and we will run it.

Citing this

Free to reuse with a link. Suggested wording:

SwitchMyEmail checked 1,685 US small-business and nonprofit domains in August 2026 and found that 44% publish no DMARC record, and only 20.4% enforce one.

Check your own domain — free →
Free instant checkSee your grade in ~1 second Check my domain