The State of Email Security 2026 · Live report
We run live SPF, DMARC, and DNSSEC checks on 5,727 domains, from the Fortune 500 and federal agencies to universities, all 50 state governments, and the web's most-visited sites. Right now, 34% can be spoofed by anyone.
If a domain doesn't enforce DMARC, anyone can send email that looks like it came from that organization, whether to its students, citizens, customers, or staff. It's the single most important defense against email impersonation and phishing, and it's free to turn on. So we check who actually has, continuously.
Every domain is scanned with the same public DNS checks that power our free checker. For each one we record whether it enforces DMARC (a policy of quarantine or reject), merely monitors (p=none, which stops nothing), or has no DMARC at all. Across the whole dataset, 66% enforce, 20% only monitor, and 14% publish no DMARC record.
% of scanned domains that actually block spoofed mail (policy = quarantine or reject). Higher is better.
n = 5,727 domains; sectors with fewer than 20 domains are omitted from this chart. “Popular websites” are high-traffic, mail-enabled domains from the Tranco top-sites list. Source: Email Posture, emailposture.com (October 3, 2026).
While Banking & Finance (98%) and Tech / SaaS (96%) have largely locked their doors, higher education sits at just 59% enforcement and government at 70%. These institutions send financial-aid notices, tax and benefits messages, and password resets to millions of people.
39% of the university domains we scan publish a DMARC record set to p=none. They receive reports showing exactly who is spoofing them, but they've told the world's mail servers to deliver those messages anyway.
We check every primary domain each state uses, and give each state credit if any of them enforces DMARC. Even on that generous measure, 23 states leave every one of their main domains open to impersonation.
⚑ States with no DMARC enforcement on any primary domain
New York and Wyoming publish no DMARC record at all. The rest publish one but leave it at p=none, which provides no protection.
The federal government is the contrast. Under CISA Binding Operational Directive 18-01, federal civilian agencies must enforce DMARC, and 31 of the 33 federal domains we track do. The exceptions: house.gov, army.mil. States face no such mandate, and it shows.
One protection is neglected almost everywhere: DNSSEC, which cryptographically signs DNS records so they can't be forged in transit. Just 13% of all scanned domains are signed. Cybersecurity leads at 43%, while sports & entertainment, nonprofit and real estate trail at 0%. And only 4% publish MTA-STS, which forces encryption on mail sent to them.
Every result comes from live, public DNS lookups over DNS-over-HTTPS, the same checks behind the free Email Posture checker, so anyone can reproduce them. For each domain we read the DMARC record at _dmarc.<domain> and classify its policy (reject, quarantine, none, or missing), and check for DNSSEC and MTA-STS. Domains are rescanned on a rolling two-week cycle; lookups that fail to resolve are excluded rather than counted as insecure.
The dataset combines a curated list of well-known organizations (large companies across more than a dozen sectors, universities, federal agencies, all 50 state governments, and major cities) with 4,582 high-traffic, mail-enabled domains from the Tranco top-sites list, and grows every day. It is a sample of prominent domains, not a census. DKIM is not part of these figures because its selector can't be discovered by an external scan. We never publish an individual company's results; only government domains are named. The first edition of this report (June 20, 2026) covered 218 domains, of which 23% could be spoofed.
Source: Email Posture, emailposture.com. Figures reflect public DNS records scanned between September 19, 2026 and October 3, 2026, and change as organizations update their configuration. If you represent a named government domain and have updated your records, contact us and we'll re-check. Free to cite with attribution and a link.
Find out in ten seconds. Email Posture checks your SPF, DKIM, DMARC, and DNSSEC, grades your setup, and tells you exactly what to fix, in plain English, with no signup.
Check your domain free →