email-auth · severity medium

DMARC reporting

Share of DMARC-protected domains that receive no aggregate reports — none requested, or an external destination that never authorised them.

Measured every Monday · last updated

How it is measured

Tier 0. Read the rua= tag from the _dmarc TXT record already fetched for dmarc-policy. Where a destination mailbox sits on another domain, RFC 9990 requires that domain to publish <policy-domain>._report._dmarc.<destination> (or a * wildcard at the same name) before a conforming receiver will send anything. Denominator: domains that have a DMARC record — a domain with no policy has nothing to report on and is excluded rather than counted as receiving nothing.

Why it matters

The reporting half of the p=none story, and the same shape: the record is valid, the checker is green, a reporting address is configured, and not one report has ever arrived. Without the feedback loop nobody ever learns which mail is failing, so the rollout from none to reject — the thing the policy exists to reach — never starts. unauthorised is the quieter of the two: the owner did everything visible correctly and the consent record is on a domain they may not control.

Limits of this measurement

Aggregate (rua) only; ruf uses the same consent mechanism but is rarely honoured and is not counted. Reporting is orthogonal to policy strength — a domain can enforce reject and still be blind, or sit at p=none and receive reports perfectly — so this is not a second reading of dmarc-policy. A destination that authorises the domain but silently drops the mail is indistinguishable from one that delivers it; consent is observable from outside, delivery is not.

The base rate

Two independent populations. The global, domain-anchored figure is unbiased; the company-anchored figures are built by matching company names to domains and skew toward more digitally-mature firms. Both are published, so the gap is visible.

Global (all domains) 71.89% fail · n=6,632
reports arriving: 28.11%no rua set: 66.66%destination not authorised: 5.23%
France companies 58.12% fail · n=394
reports arriving: 41.88%no rua set: 47.97%destination not authorised: 10.15%
UK companies 54.58% fail · n=1,288
reports arriving: 45.42%no rua set: 48.21%destination not authorised: 6.37%
Norway companies 53.28% fail · n=625
reports arriving: 46.72%no rua set: 48.64%destination not authorised: 4.64%
reports arriving · 46.72%no rua set · 48.64%destination not authorised · 4.64%

By company size band

Company-anchored cuts (national registries with a size proxy), split by size band. Right-hand figure is the share not meeting the control.

France
smalln=114
reports arriving: 32.46%no rua set: 61.4%destination not authorised: 6.14%
67.54%
UK
smalln=437
reports arriving: 40.5%no rua set: 53.55%destination not authorised: 5.95%
59.5%
medium/largen=593
reports arriving: 53.46%no rua set: 38.11%destination not authorised: 8.43%
46.54%
Norway
micron=153
reports arriving: 39.87%no rua set: 56.21%destination not authorised: 3.92%
60.13%
smalln=147
reports arriving: 33.33%no rua set: 61.22%destination not authorised: 5.44%
66.67%
mediumn=186
reports arriving: 52.69%no rua set: 43.55%destination not authorised: 3.76%
47.31%
largen=139
reports arriving: 60.43%no rua set: 33.81%destination not authorised: 5.76%
39.57%

Every segment

Pick one to see the citable answer for a company like yours, with its trend and methodology.

Show the remaining 36 segments

Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.