
Last week Microsoft published its Q2 2026 email threat report. Buried under the headline number — 7.6 billion phishing emails in a single quarter — is the detail that should worry every developer who has ever copy-pasted a DMARC record from Stack Overflow:
On June 1, a single actor reached 67,000+ users across 42,000 organizations in under three hours. The messages passed DKIM alignment — sent from Slovakia-registered domains, routed through Amazon SES.
Read that again. The attack didn't bypass email authentication. It used email authentication. SPF passed. DKIM aligned. The mail was, cryptographically speaking, perfectly legitimate.
So if attackers can pass SPF and DKIM on their own throwaway domains, the last line of defense is DMARC on your domain — the policy that tells Gmail and Outlook what to do when someone spoofs you.
Here's the problem: at internet scale, DMARC mostly doesn't do anything.
The data: 666,803 domains, rebuilt daily
To put numbers on that claim I'm using the email infrastructure statistics of the Tranco top-1M — an open dataset by Live Direct Marketing that rebuilds MX, SPF and DMARC stats for ~667k mail-enabled domains every day from OpenINTEL DNS measurements, published under CC BY 4.0. Snapshot: July 28, 2026.
The topline funnel looks like adoption is going great:
Layer | Domains | Share of mail-enabled |
|---|---|---|
MX (can receive mail) | 666,803 | 100% |
SPF (authorises senders) | 630,030 | 94.5% |
DMARC (publishes a policy) | 466,119 | 69.9% |
DMARC actually enforced | — | 47.22% of publishers |
Two-thirds of the top million domains publish DMARC. Sounds healthy — until you check what those records actually say.
Half of DMARC records are decoration
A DMARC record only changes receiver behavior if it says p=quarantine or p=reject. Everything else is monitoring at best. The dataset splits DMARC publishers three ways:
Enforcing (
p=quarantine/p=reject): 49.6%Monitoring (
p=nonewith a workingrua=reporting address — a legitimate rollout phase, someone is at least reading reports): 25.6%Inert (
p=none, norua=at all): 24.8% — 115,525 domains where the record enforces nothing and reports to no one
That last bucket is the one that gets me. A quarter of all DMARC records on the top million domains are pure cargo cult: a TXT record that exists because a deliverability checklist said "add DMARC", and does literally nothing. 35.3% of publishers (164,386 domains) have no working reporting address at all — they will never even find out they're being spoofed.
And the trend is going the wrong way: enforcement is down 0.10 pp over the last 30 days. DMARC adoption grew by 5,765 domains in that window, but 61% of that net growth was p=none. We're adding decoration faster than protection.
You can see the copy-paste in the data
The dataset publishes the top 100 DMARC records verbatim, and it's a beautiful archaeology of copy-pasted snippets:
Record | Domains |
|---|---|
| 58,163 |
| 32,568 |
| 9,020 |
| 5,064 |
| 3,906 |
Over 90,000 domains share the exact same two "starter" strings — the DNS equivalent of // TODO: fix later, except it's been in production since 2019.
Enforcement is a function of how big you are
The single most interesting cut in the dataset is DMARC enforcement by Tranco rank:
Tier | DMARC enforced |
|---|---|
Top 1k | 73.1% |
1k–10k | 56.4% |
10k–100k | 43.4% |
100k–1M | 29.9% |
The top of the internet has mostly solved this — because they have deliverability teams, security reviews, and BIMI logos to protect. The long tail, where most SaaS products, side projects and startups live (i.e., where your domain probably lives), enforces at 30%. That's exactly the population attackers spoof, because nobody's watching the reports and nothing gets rejected.
Why the SES detail matters
One more number from the same scan: Amazon SES is the most-authorised sending platform on the internet — 6.18% of all SPF-publishing domains include it, ahead of SendGrid (4.75%) and Mailgun (4.11%). Shared sending infrastructure is now the default, which is precisely what made Microsoft's June campaign work: attacker traffic and legitimate traffic exit the same IPs, signed with valid DKIM. IP reputation is dead as a primary signal. Domain-level policy — DMARC on the From: domain — is what's left. And as we've just seen, half of it is switched off.
The 20-minute fix (do this today)
If you own a domain that sends mail, here's the actual path, not the checklist-theater version:
Check what you have.
dig TXT _dmarc.yourdomain.com— or look your domain up in the same dataset to see your mailbox provider, ESPs and current policy as external scanners see them.If you have
p=nonewith norua=, you're in the inert 24.8%. Add a reporting address first:v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. Free tiers of most DMARC report processors are fine for a small domain.Read the reports for 2–4 weeks. You'll find senders you forgot about — the CRM, the status page, that one Zapier automation.
Move to
p=quarantine, thenp=reject. Withpct=100or nopctat all (DMARCbis is killing thepcttag anyway).Domains that send no mail at all get the full lockdown:
v=spf1 -all, empty DKIM,p=reject. Parked domains are the easiest spoofing targets on the internet.
None of this is new advice. What's new is that in 2026 the excuses are gone: attackers demonstrably pass SPF/DKIM at scale, the tooling is free, and a daily-updated public dataset will show you — and everyone else — exactly whether your record is protection or decoration.
47.22% of the internet has done the work. The other half is one TXT record away.
Data: Live Direct Marketing — Email infrastructure of the Tranco top-1M (CC BY 4.0, snapshot 2026-07-28), built from OpenINTEL forward-DNS measurements. Threat numbers: Microsoft Security, Email threat landscape Q2 2026.
Comments (0)
Login to post a comment.