BuildNot yet confirmed elsewhere1 publisher2 min readPublished
Fewer than half of the 1,000 most popular websites reject spoofed email
Just 474 of the 1,000 most popular websites set DMARC to reject spoofed mail, a dev.to survey of their DNS found. Thirty-two months after Google and Yahoo began requiring DMARC from bulk senders, 84.5% of the sites publish a record, but only 69.4% apply an enforcing policy to all their mail.
The Engineer · Build desk

What happened
- 136 domains, about one in seven, publish p=none, which only monitors, and 85% of them ask receivers for aggregate reports.
- Some 24 domains, 2.8% of those with a record, reject spoofs of their main domain but apply a weaker policy to its subdomains.
- Domains on Google Workspace enforce DMARC more often than those on Microsoft 365, and domains behind a security gateway enforce it most often.
Why it matters
- exposure Forged mail using the From domain of 291 of these sites meets no quarantine or reject instruction in DNS, so stopping it is left to each receiver's own filtering.
- exposure At the 24 domains with a weaker subdomain policy, a spoofer who forges a subdomain address gets the weaker treatment, so an apex reject overstates what those domains block.
- constraint Tightening SPF from ~all to -all mostly affects receivers that skip DMARC; at receivers that check it, the p= value is still the setting that decides what forged mail meets.
A DMARC record's p= value decides what a receiver does with mail that fails the checks: p=none does nothing, p=quarantine sends it to spam, and p=reject refuses it [18]. Add the 235 quarantine records to the rejecters and the survey has 709 domains with an enforcing value [4][22]. It counts only 694 as enforcing, because its definition requires the policy to cover 100% of mail [16]. Fifteen of the 845 records cover less than that [5]. Take them out and 709 becomes 694 [22].
A p=none record is meant as a staging step. According to the survey, a domain watches the aggregate reports, finds its legitimate senders, then tightens the policy [8]. About 20 of the monitor-only domains publish p=none without asking for those reports [26].
Some large names sit in that group: samsung.com, yandex.ru, and Microsoft's consumer mail domains outlook.com, live.com and msn.com [9]. We agree with the authors on where the excuse for staying there ends. For consumer mailbox domains, they argue, p=none is often deliberate, because mailing lists and forwarding break authentication and a strict policy would bounce real mail [10]. "A company domain doesn't have that excuse," they wrote [19].
The rank figures are a claim about this list. Outside the top 100, 412 of 900 domains reject [25]. Enforcement already drops between the top 100 and the rest [7], and the scan stopped at rank 1,000 [2]. We'd expect ordinary company domains to reject spoofed mail less often than these sites do. The list also includes entries that never receive mail: 125 of the 1,000 have no MX record, and the survey says they are mostly link shorteners, download hosts and developer infrastructure [28][17].
Mail hosting at this tier is concentrated. Of the 875 domains that accept mail, 37.3% use Google Workspace, 17.4% use Microsoft 365, and Proofpoint filters 9.0% before delivery [13]. In all, 124 domains put a security gateway in front of the mailbox. SPF names the mailbox host behind it in only 43 of those cases [14][20]. The authors call their enforcement-by-host comparison a correlation, not a cause [15]. They wrote that "buying Proofpoint and setting p=reject both point to a company with a dedicated email-security team" [21].
What to watch
- A repeat of the Tranco top-1,000 scan showing how many of the 136 p=none domains have moved to quarantine or reject.
- Any change by Google or Yahoo to what their bulk-sender DMARC requirement demands of the policy value itself.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption68
- Hype gap0
- Incentives
- Insufficient
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Since February 2024, Google and Yahoo have required DMARC from anyone sending them bulk mail.
- [2]
On 10 October 2026 the survey authors looked up the email DNS of the 1,000 most popular websites on the Tranco list (list 8PX5V) and recorded their policies and mail hosts.
- [3]
84.5% of the 1,000 domains have a DMARC record; 69.4% set it to quarantine or reject for all mail; 47.4% reject outright; 13.6% publish p=none, which only monitors.
- [4]
Across all 1,000 domains the DMARC policy split was 474 at reject, 235 at quarantine and 136 at none; 155 had no record.
- [5]
Only 15 of the 845 DMARC records (1.8%) applied their policy to less than 100% of mail.
- [6]
24 domains (2.8%) rejected spoofs of the main domain but used a weaker policy for its subdomains.
- [7]
62% of the top 100 domains reject spoofed mail, against 46% of domains ranked 101-1,000.
- [8]
A p=none record is usually a first step: a domain watches the reports, finds its legitimate senders, then tightens the policy. 85% of the 136 p=none domains ask for aggregate reports.
- [9]
Large names still at p=none include samsung.com, yandex.ru and Microsoft's consumer mail domains outlook.com, live.com and msn.com.
- [10]
For consumer mailbox domains, p=none is often deliberate: mailing lists and forwarding break authentication, and a strict policy would bounce real mail.
- [11]
89.6% of the domains publish SPF; of those, 53.8% end it with -all (hard fail) and 40.4% with ~all (soft fail).
- [12]
Under DMARC a receiver judges a message by the DMARC result, so -all versus ~all mostly matters to receivers that don't check DMARC.
- [13]
Of the 1,000 domains, 875 have an MX record and accept mail; of those, 37.3% use Google Workspace and 17.4% Microsoft 365, and Proofpoint filters 9.0% before the mail reaches the mailbox.
- [14]
124 domains (14.2% of those accepting mail) use a security gateway that filters inbound mail first.
- [15]
Domains on Google Workspace enforce DMARC more often than those on Microsoft 365, and domains behind a gateway enforce it most often; the authors say this is a correlation, not a cause.
- [16]
The survey defines 'enforced' as quarantine or reject, applied to 100% of mail.
- [17]
The domains without an MX record are mostly link shorteners, download hosts and developer infrastructure.
- [18]
DMARC tells receivers what to do when a message fails the checks: nothing (p=none), send it to spam (p=quarantine) or refuse it (p=reject).
- [19]
"A company domain doesn't have that excuse."
ReportedSupportedSource: dev.to survey authors, writing about p=none on company domainsView cited source - [20]
Behind the 124 gateways, SPF identifies the mailbox in 43 cases: 24 use Microsoft 365 and 19 Google Workspace.
- [21]
"buying Proofpoint and setting p=reject both point to a company with a dedicated email-security team"
- [22]
Reject plus quarantine records total 709 domains; removing the 15 records that cover less than 100% of mail leaves 694, matching the 69.4% of 1,000 the survey counts as enforced.
- [23]
136 p=none domains out of 1,000 is about one domain in seven.
- [24]
February 2024 to the October 2026 scan is about 32 months.
- [25]
Outside the top 100, 412 of the 900 domains ranked 101-1,000 reject spoofed mail (45.8%).
- [26]
About 116 of the 136 p=none domains request aggregate reports, leaving about 20 that do not.
- [27]
291 of the 1,000 domains give receivers no quarantine or reject instruction: 155 with no DMARC record plus 136 at p=none.
- [28]
125 of the 1,000 domains have no MX record and do not accept mail.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toHow the top 1,000 websites handle email security in 2026: DMARC, SPF, BIMI and who hosts their email
1 article · October 10, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.