← Learn

Email authentication census

Email deliverability records across the web: a live census of 5,000 domains

We measured the email authentication records of the top 5,000 domains on the Tranco ranking, live, with dig — one DNS query batch per domain, no estimates, no vendor surveys. The short answer: SPF is near-universal but not complete (75.1%), DMARC is at 68.5% and most adopters enforce it, MX records are missing from roughly one domain in four that should have them, and MTA-STS is almost nowhere (2.8%). BIMI sits at 11.3%, concentrated in the biggest brands. A fifth of the web's most-visited domains (22.2%) publish neither SPF nor DMARC at all.

Every number below comes from our own dig measurements run on September 6, 2026. Nothing is modeled, extrapolated, or borrowed from another report.

Methodology

  • Corpus: Tranco list XN6XN, created 2026-09-05 22:00 UTC. We took the top 5,000 entries.
  • Measurement: For each domain, dig against Cloudflare's 1.1.1.1 resolver (fallback 8.8.8.8 on timeout) queried five names: apex TXT (SPF), _dmarc TXT, MX, _mta-sts TXT, and default._bimi TXT. Queries ran 20 in parallel, 2026-09-06 ~09:30–09:45 UTC.
  • Classification: A record counts as present only if the answer carries the right version tag (v=spf1, v=DMARC1, v=STSv1, v=BIMI1) at the right name. Wildcard TXT mirrors of SPF at unrelated names do not count as MTA-STS or BIMI. DMARC records published via CNAME to a vendor are followed and counted.
  • Response validity: 16 of 5,000 domains returned NXDOMAIN or SERVFAIL at the apex and were excluded, leaving 4,984 measured domains.

Percentages are of the 4,984 measured domains unless stated otherwise. DNS is live data; rerunning this census on another day will shift numbers by fractions of a percent.

Overall adoption

RecordWhat it doesDomainsAdoption
SPFAuthorizes sending IPs3,74375.1%
DMARCPolicy + reporting for SPF/DKIM3,41368.5%
MXDesignates mail servers3,57371.7%
MTA-STSEnforces TLS for inbound SMTP1382.8%
BIMIVerified logo in inboxes56311.3%

The ordering is the story. The two records required by bulk-sender rules at Google and Microsoft since 2024 — SPF and DMARC — have clearly pulled ahead. The two records that are optional, newer, and operationally harder lag by an order of magnitude.

DMARC: present, and mostly enforced

Among the 3,413 domains publishing a DMARC record, the policy split is:

DMARC policyDomainsShare of adopters
p=reject1,76851.8%
p=quarantine90626.5%
p=none73021.4%
no p tag90.3%

Just over half of DMARC adopters are at full enforcement, and 78.3% are at quarantine or stricter. The monitor-only cohort is 21.4% of adopters — 14.6% of the entire corpus.

  • 85.9% of DMARC records include a rua= reporting address. The remaining 14.1% are enforcing blind, with no feedback loop.
  • 24.3% set an sp= subdomain policy and 34.2% set pct=, both signs of deliberately configured rather than copy-pasted records.

SPF: widespread, often soft

SPF endingMeaningDomainsShare of adopters
-allHard fail1,95652.3%
~allSoft fail1,55141.4%
?allNeutral832.2%
no allOpen-ended1534.1%

Nearly half of SPF publishers still use ~all, which at most receivers lands unauthorized mail in spam rather than blocking it. And 53 domains publish two SPF records at the apex, which is a protocol violation: RFC 7208 says multiple SPF records make the check return a permanent error.

The rank effect: bigger sites authenticate more

MetricTop 1,000 (n=998)Ranks 1,001–5,000 (n=3,986)
SPF76.7%74.7%
DMARC72.9%67.4%
MTA-STS3.4%2.6%
BIMI16.6%10.0%
p=reject share of DMARC60.9%—

The largest sites are about 5.5 points ahead on DMARC, and BIMI adoption in the top 1,000 is two-thirds higher than in the rest of the corpus. If the biggest mail senders on the internet behave this way, the baseline your recipients expect is set by this table, not by average-domain behavior.

Notable findings

  • 22.2% publish neither SPF nor DMARC. Even among the most-visited 5,000 domains, over a fifth have no sender authentication at all. Anyone can spoof these domains with a trivially forged return-path.
  • 9.3% have SPF but no DMARC — the half-done configuration. DMARC without SPF is rarer (2.7%).
  • MTA-STS is the missing layer. Only 138 domains publish it. The names are the expected ones — google.com, microsoft.com, cloudflare.com — a big-operators' game so far.
  • Only 46 domains (0.9%) publish all five records. cloudflare.com, ikea.com, jetbrains.com, crowdstrike.com, and 42 others. Full email authentication maturity is under one percent of the web's most-visited domains.
  • DMARC-via-CNAME is common enough to matter. 179 of 3,413 records (5.2%) are CNAMEs at a DMARC vendor. Any census that only matches TXT at _dmarc undercounts by about three and a half points — we followed the CNAMEs.

Check your own domain

The gap between “has SPF” and “has a correctly enforced, monitored setup” is where most deliverability problems live. Our free email checker runs these exact checks against any domain, the same way this census did: live DNS, version-tag matching, CNAME-following. For a grounding in what each record does, see SPF, DKIM, and DMARC explained, and if mail is authenticating but still landing in junk, why emails land in spam covers the usual suspects.

Frequently asked questions

Which email DNS records did you measure, exactly?

Five per domain: SPF (apex TXT starting v=spf1), DMARC (_dmarc TXT with v=DMARC1, CNAME-published records followed), MX, MTA-STS (_mta-sts TXT with v=STSv1), and BIMI (default._bimi TXT with v=BIMI1).

Why do your numbers differ from other DMARC adoption reports?

Corpus, date, and method. We measured the Tranco top 5,000 (list XN6XN) on September 6, 2026; other reports use different domain sets, different dates, and — critically — many count any TXT at _dmarc without following CNAMEs or requiring the v=DMARC1 tag, which shifts results by several points either way.

Is 68.5% DMARC adoption good or bad?

Both. It reflects the 2024 enforcement deadlines at Gmail and Microsoft. But it means roughly one in three of the most-visited domains can still be spoofed with no receiver-side policy, and 22.2% of the corpus has no authentication records at all.

Can I reproduce this census?

Yes. Download the Tranco list (ID XN6XN, or the current daily list), take the top 5,000, and run dig TXT, dig _dmarc TXT, dig MX, dig _mta-sts TXT, and dig default._bimi TXT per domain against a public resolver. Parallelizing 20-wide, the full run takes under ten minutes.

Corpus: Tranco list XN6XN (top 5,000; created 2026-09-05). Measured 2026-09-06 via dig against 1.1.1.1 with 8.8.8.8 fallback; n = 4,984 valid domains of 5,000. All figures are live measurements; rerun results will vary slightly with DNS churn.

Related