Original Research · 2026-10-02

SPF & DMARC Adoption Among 214 Major Companies

We ran live DNS TXT lookups against 214 well-known public company domains to measure how many publish SPF and DMARC records, and how strictly those policies are enforced.

92.5%
Publish an SPF record
98.6%
Publish a DMARC record
92.4%
Of those, enforce it (quarantine/reject)
77.7%
Have gone all the way to p=reject

Methodology

We compiled a list of 214 well-known public company domains spanning technology, finance, retail, healthcare, media, airlines, hospitality, education, and SaaS. For each domain, we ran dig TXT <domain> to locate an SPF record and dig TXT _dmarc.<domain> to locate a DMARC record, using standard public DNS resolution with no caching bypass tricks. No SMTP connections were made to any domain — this is a DNS-record-only study.

SPF enforcement was classified by the qualifier on the trailing all mechanism (-all hard fail, ~all soft fail, ?all neutral, +all/bare all effectively disables the check). DMARC policy was read directly from the p= tag in the published record.

Sampling caveat: this is a convenience sample of large, well-resourced organizations, not a random sample of the general domain population. Published industry-wide studies of all registered domains typically find substantially lower DMARC adoption than we measured here — our 98.6% figure should be read as "among major companies," not "across the internet."

Raw per-domain results, including the exact SPF and DMARC record text for every domain checked, are available as a CSV: download dmarc-spf-adoption-2026.csv.

Results

SPF enforcement level (of 198 domains with SPF)

QualifierDomainsShare
Hard fail (-all) 89 44.9%
Soft fail (~all) 98 49.5%
Neutral (?all) 2 1%
No "all" mechanism 9 4.5%

DMARC policy (of 211 domains with DMARC)

PolicyDomainsShare
p=reject 164 77.7%
p=quarantine 31 14.7%
p=none (monitor only) 16 7.6%

What this means

Among large, well-resourced organizations, SPF and DMARC adoption is now close to universal — but a meaningful minority (7.6% of those with a DMARC record) are still sitting at p=none or p=quarantine rather than the fully-enforced p=reject, meaning their domain can still be spoofed in a way that passes authentication checks at many receivers. 14 domains (6.5%) have DMARC but no SPF record at all, relying entirely on DKIM alignment, which is unusual and worth flagging for anyone auditing a domain's setup.

For a smaller company or a domain just getting started with authentication, these numbers are a reasonable target: publish SPF with -all, publish DMARC starting at p=none to monitor without disruption, then graduate to p=quarantine and eventually p=reject once reporting confirms no legitimate mail is being caught. See our DMARC explainer for the step-by-step reasoning.

Check Your Own Domain's Authentication

Free, no signup — scores your SPF/DKIM/DMARC setup in seconds.

Check My Domain