DMARC reporting · Norway micro companies

What share of Norway micro companies have dmarc-reporting?

60.13%

60.13% of Norway micro companies (95% CI 52.22–67.55%), measured across 153 companies on 2026-10-01.

reports arriving: 39.87%no rua set: 56.21%destination not authorised: 3.92%
reports arriving · 39.87%no rua set · 56.21%destination not authorised · 3.92%
Trend

Measured every Monday since 2026-08-01 — 1 observation to date. Last measured 2026-10-01.

How this is measured

Tier 0. Read the rua= tag from the _dmarc TXT record already fetched for dmarc-policy. Where a destination mailbox sits on another domain, RFC 9990 requires that domain to publish <policy-domain>._report._dmarc.<destination> (or a * wildcard at the same name) before a conforming receiver will send anything. Denominator: domains that have a DMARC record — a domain with no policy has nothing to report on and is excluded rather than counted as receiving nothing.

Passive measurement: a single DNS lookup, TLS handshake, or homepage GET per domain. Aggregate-only; no individual company is named. 95% Wilson confidence intervals. Population: national company registries (Companies House, Brreg, SIRENE), sampled by size band and resolved to email-active domains. Parked domains excluded. Snapshot: brreg-norway-per600-seed20260730.

Licensed CC BY 4.0 — reuse with attribution to Quiet Failures. Download: JSON · CSV.

Check a specific domain against this control with the free Email authentication audit.

Why it matters

The reporting half of the p=none story, and the same shape: the record is valid, the checker is green, a reporting address is configured, and not one report has ever arrived. Without the feedback loop nobody ever learns which mail is failing, so the rollout from none to reject — the thing the policy exists to reach — never starts. unauthorised is the quieter of the two: the owner did everything visible correctly and the consent record is on a domain they may not control.

Limits of this measurement

Aggregate (rua) only; ruf uses the same consent mechanism but is rarely honoured and is not counted. Reporting is orthogonal to policy strength — a domain can enforce reject and still be blind, or sit at p=none and receive reports perfectly — so this is not a second reading of dmarc-policy. A destination that authorises the domain but silently drops the mail is indistinguishable from one that delivers it; consent is observable from outside, delivery is not.

The same check, other segments

Show the remaining 39 segments

Share or cite this figure

Reuse is free under CC BY 4.0 — attribution to Quiet Failures is all we ask.

Post on X

Embed this stat

Free to reuse under CC BY 4.0 — the card links back and updates as the data does.

<iframe src="https://quietfailures.com/embed/dmarc-reporting/no-micro" width="380" height="210" style="border:0;max-width:100%" loading="lazy" title="What share of Norway micro companies have dmarc-reporting?"></iframe>