SPF & DMARC Adoption Among 214 Major Companies
We ran live DNS TXT lookups against 214 well-known public company domains to measure how many publish SPF and DMARC records, and how strictly those policies are enforced.
Methodology
We compiled a list of 214 well-known public company domains spanning technology, finance, retail, healthcare, media, airlines, hospitality, education, and SaaS. For each domain, we ran dig TXT <domain> to locate an SPF record and dig TXT _dmarc.<domain> to locate a DMARC record, using standard public DNS resolution with no caching bypass tricks. No SMTP connections were made to any domain — this is a DNS-record-only study.
SPF enforcement was classified by the qualifier on the trailing all mechanism (-all hard fail, ~all soft fail, ?all neutral, +all/bare all effectively disables the check). DMARC policy was read directly from the p= tag in the published record.
Sampling caveat: this is a convenience sample of large, well-resourced organizations, not a random sample of the general domain population. Published industry-wide studies of all registered domains typically find substantially lower DMARC adoption than we measured here — our 98.6% figure should be read as "among major companies," not "across the internet."
Raw per-domain results, including the exact SPF and DMARC record text for every domain checked, are available as a CSV: download dmarc-spf-adoption-2026.csv.
Results
SPF enforcement level (of 198 domains with SPF)
| Qualifier | Domains | Share |
|---|---|---|
Hard fail (-all) | 89 | 44.9% |
Soft fail (~all) | 98 | 49.5% |
Neutral (?all) | 2 | 1% |
No "all" mechanism | 9 | 4.5% |
DMARC policy (of 211 domains with DMARC)
| Policy | Domains | Share |
|---|---|---|
p=reject | 164 | 77.7% |
p=quarantine | 31 | 14.7% |
p=none (monitor only) | 16 | 7.6% |
What this means
Among large, well-resourced organizations, SPF and DMARC adoption is now close to universal — but a meaningful minority (7.6% of those with a DMARC record) are still sitting at p=none or p=quarantine rather than the fully-enforced p=reject, meaning their domain can still be spoofed in a way that passes authentication checks at many receivers. 14 domains (6.5%) have DMARC but no SPF record at all, relying entirely on DKIM alignment, which is unusual and worth flagging for anyone auditing a domain's setup.
For a smaller company or a domain just getting started with authentication, these numbers are a reasonable target: publish SPF with -all, publish DMARC starting at p=none to monitor without disruption, then graduate to p=quarantine and eventually p=reject once reporting confirms no legitimate mail is being caught. See our DMARC explainer for the step-by-step reasoning.
Check Your Own Domain's Authentication
Free, no signup — scores your SPF/DKIM/DMARC setup in seconds.
Check My Domain