email-auth · severity high
SPF policy
Share of email-active domains with no enforcing SPF record (absent, ~all soft-fail, or +all).
Measured every Monday · last updated
How it is measured
Tier 0. TXT at the apex; find v=spf1, read the all qualifier, count direct lookups. Denominator: has_mx.
Why it matters
~all is the SPF equivalent of p=none and overwhelmingly the most common configuration — it asks receivers to accept-but-mark, so spoofed mail still arrives. +all authorises the entire internet to send as you. Exceeding the 10-lookup limit makes the record fail permanently and silently, because receivers abort evaluation.
Limits of this measurement
The lookup count is non-recursive (it does not expand include:), so it is a lower bound and catches only egregiously over-limit records.
The base rate
Two independent populations. The global, domain-anchored figure is unbiased; the company-anchored figures are built by matching company names to domains and skew toward more digitally-mature firms. Both are published, so the gap is visible.
By company size band
Company-anchored cuts (national registries with a size proxy), split by size band. Right-hand figure is the share not meeting the control.
Every segment
Pick one to see the citable answer for a company like yours, with its trend and methodology.
Show the remaining 62 segments
From the newsletter
Where this base rate turned up as a real, fixable exposure.
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.