Skip to content

BuildNot yet confirmed elsewhere1 publisher2 min readPublished

Fewer than half of the 1,000 most popular websites reject spoofed email

Just 474 of the 1,000 most popular websites set DMARC to reject spoofed mail, a dev.to survey of their DNS found. Thirty-two months after Google and Yahoo began requiring DMARC from bulk senders, 84.5% of the sites publish a record, but only 69.4% apply an enforcing policy to all their mail.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Fewer than half of the 1,000 most popular websites reject spoofed email
Generated illustration

What happened

  • 136 domains, about one in seven, publish p=none, which only monitors, and 85% of them ask receivers for aggregate reports.
  • Some 24 domains, 2.8% of those with a record, reject spoofs of their main domain but apply a weaker policy to its subdomains.
  • Domains on Google Workspace enforce DMARC more often than those on Microsoft 365, and domains behind a security gateway enforce it most often.

Why it matters

  • exposure Forged mail using the From domain of 291 of these sites meets no quarantine or reject instruction in DNS, so stopping it is left to each receiver's own filtering.
  • exposure At the 24 domains with a weaker subdomain policy, a spoofer who forges a subdomain address gets the weaker treatment, so an apex reject overstates what those domains block.
  • constraint Tightening SPF from ~all to -all mostly affects receivers that skip DMARC; at receivers that check it, the p= value is still the setting that decides what forged mail meets.

A DMARC record's p= value decides what a receiver does with mail that fails the checks: p=none does nothing, p=quarantine sends it to spam, and p=reject refuses it [18]. Add the 235 quarantine records to the rejecters and the survey has 709 domains with an enforcing value [4][22]. It counts only 694 as enforcing, because its definition requires the policy to cover 100% of mail [16]. Fifteen of the 845 records cover less than that [5]. Take them out and 709 becomes 694 [22].

A p=none record is meant as a staging step. According to the survey, a domain watches the aggregate reports, finds its legitimate senders, then tightens the policy [8]. About 20 of the monitor-only domains publish p=none without asking for those reports [26].

Some large names sit in that group: samsung.com, yandex.ru, and Microsoft's consumer mail domains outlook.com, live.com and msn.com [9]. We agree with the authors on where the excuse for staying there ends. For consumer mailbox domains, they argue, p=none is often deliberate, because mailing lists and forwarding break authentication and a strict policy would bounce real mail [10]. "A company domain doesn't have that excuse," they wrote [19].

The rank figures are a claim about this list. Outside the top 100, 412 of 900 domains reject [25]. Enforcement already drops between the top 100 and the rest [7], and the scan stopped at rank 1,000 [2]. We'd expect ordinary company domains to reject spoofed mail less often than these sites do. The list also includes entries that never receive mail: 125 of the 1,000 have no MX record, and the survey says they are mostly link shorteners, download hosts and developer infrastructure [28][17].

Mail hosting at this tier is concentrated. Of the 875 domains that accept mail, 37.3% use Google Workspace, 17.4% use Microsoft 365, and Proofpoint filters 9.0% before delivery [13]. In all, 124 domains put a security gateway in front of the mailbox. SPF names the mailbox host behind it in only 43 of those cases [14][20]. The authors call their enforcement-by-host comparison a correlation, not a cause [15]. They wrote that "buying Proofpoint and setting p=reject both point to a company with a dedicated email-security team" [21].

What to watch

  • A repeat of the Tranco top-1,000 scan showing how many of the 136 p=none domains have moved to quarantine or reject.
  • Any change by Google or Yahoo to what their bulk-sender DMARC requirement demands of the policy value itself.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence62
Adoption68
Hype gap0
Incentives
Insufficient
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Since February 2024, Google and Yahoo have required DMARC from anyone sending them bulk mail.

    ReportedSupportedSource: dev.to survey authors (locaihost_data)View cited source
  2. [2]

    On 10 October 2026 the survey authors looked up the email DNS of the 1,000 most popular websites on the Tranco list (list 8PX5V) and recorded their policies and mail hosts.

    ReportedSupportedSource: dev.to survey authorsView cited source
  3. [3]

    84.5% of the 1,000 domains have a DMARC record; 69.4% set it to quarantine or reject for all mail; 47.4% reject outright; 13.6% publish p=none, which only monitors.

    ReportedSupportedSource: dev.to survey authorsView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 10, 2026

    How the top 1,000 websites handle email security in 2026: DMARC, SPF, BIMI and who hosts their email

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories