The countries where email is easiest to fake
Our weekly data measures how many domains enforce DMARC by country — and where spoofing meets no resistance. How to read the pattern and check your own domain.
Whether a stranger can send email that looks convincingly like it came from your domain isn’t really a matter of how clever they are. It’s a matter of whether your domain has bothered to say no. The checks that stop spoofing — SPF, DKIM and, above all, DMARC set to actually enforce — are free and well understood. Yet whether they’re switched on varies enormously, and one of the sharpest ways that variation shows up is by country.
Each week we measure the domains behind a large slice of the web and record how many have DMARC in place and, crucially, how many have it set to enforce rather than merely watch. The overall picture is sobering: across domains worldwide that actually run mail, 86% have DMARC either absent or set only to monitor — meaning barely one in seven turns a forged sender away. The quiet failure here isn’t one misconfigured domain; it’s whole regions where “we set up email authentication” quietly means “we set up the part that enforces nothing”, and nobody’s looking at the aggregate to notice.
Grouped by country, the variation is real but nowhere comfortable — no country we measure enforces on more than a large minority of its domains. When we last measured (10 August 2026), Germany stood out among the larger economies, with roughly 29% of its mail-carrying domains set to quarantine or reject — driven by an unusually high share on full p=reject. Most others clustered far lower: around 15% in Brazil, 13% in India, and roughly one in ten in the UK and Sweden. At the soft end sat Japan and Russia, where only about 5% of domains enforce, so a forged sender meets almost no resistance. A caveat worth stating plainly: these are per-country samples of a few hundred domains each, so treat them as a snapshot and a broad ordering rather than a precise ranking — the direction is trustworthy, the second decimal place isn’t.
Why it stays invisible
DMARC’s weakness is that its most common setting looks exactly like protection while providing none. A domain can publish a DMARC record — the checkers go green, the box is ticked — with a policy of p=none, which tells receiving servers to notice forged mail and then deliver it anyway. To anyone glancing at whether authentication “exists”, that domain counts as done. Only when you look at what the policy actually instructs does the gap appear.
At the level of a whole country, this compounds. Enforcement tends to spread through pressure — regulators requiring it, large mailbox providers refusing unauthenticated bulk mail, industry norms — and where that pressure is weaker or newer, domains stall at the monitor-only stage in vast numbers. No individual domain owner feels a problem, because nothing breaks: their mail still flows, and the absence of enforcement is only visible to the person forging their name. The regional pattern is invisible from inside any single organisation; it only emerges when you measure the aggregate, which is the whole reason we publish it.
The reason it matters to you, wherever you are, is that attackers read this map too. If your domain sits in a region — or an industry — where enforcement is rare, you’re both a softer target and surrounded by softer targets, and a spoofed message from any of them is likelier to reach a real inbox.
Find it yourself
You can’t change your country’s average, but you can make sure your own domain isn’t part of the soft majority. Ten minutes, nothing to install.
- Read your DMARC policy. On a Mac or Linux machine, open Terminal and run
dig +short txt _dmarc.yourdomain.com. On Windows, runnslookup -type=txt _dmarc.yourdomain.com. Prefer not to touch a command line? An online checker such as MxToolbox does the same — search “DMARC record lookup”. - Read the policy word. Find
p=.p=noneis monitor-only — it enforces nothing, and it’s the setting the data shows most stalled domains are stuck on.p=quarantinesends failing mail to spam;p=rejectturns it away. Only the last two actually stop a spoof. - Check you’re collecting reports. Look for a
rua=tag with an email address. Without it, even your monitoring goes nowhere. - Confirm the foundations. DMARC only bites if SPF and DKIM are in place and aligned. Check SPF with
dig +short txt yourdomain.comand look forv=spf1; a record ending-allis a hard fail,~alla softer one.
The usual reaction to step 2 is a small, deflating “oh” — the domain that felt protected turns out to say none.
The fix
Moving from a policy that watches to one that acts is a deliberate, staged change — never a single flip.
Start collecting reports if you aren’t, by adding a rua= address, and point them at a report reader so a fortnight of data tells you which of your services actually send mail and whether they pass. Fix alignment before you tighten — get every legitimate sender (your invoicing tool, CRM, mailing platform) authenticated so it passes before you start rejecting, or you’ll bin your own newsletters. Then move up one step at a time, from p=none to p=quarantine, watch for a week or two, then to p=reject. Each step is reversible; the only mistake is never making the move. Our companion issue on DMARC walks through this in full.
Do that, and you’ve quietly moved yourself out of the soft majority — regardless of what the rest of your country’s domains decide to do. And if you run more than one domain, don’t forget the ones you don’t send mail from: a parked or brand-protection domain with no enforcement is a free identity for a forger, and it’s the same one-line check to close.
The base rate behind this issue
Check it yourself
Read next
One real, fixable exposure every week. Free.