21 email authentication statistics that matter: 2026 edition
SPF, DKIM, and DMARC are now the price of admission to the inbox - these 21 sourced statistics show exactly how far adoption has come, where the enforcement gaps still are, and why it works.
Email authentication is how a mailbox provider decides whether an email that claims to come from your domain actually did. Three protocols do the work: SPF authorizes which servers may send for your domain, DKIM signs each message so it cannot be tampered with, and DMARC ties the two together and tells receivers what to do when a message fails. Get them right and you are trusted; get them wrong and you are indistinguishable from a spoofer.
In 2024 and 2025 authentication stopped being optional. Gmail and Yahoo made SPF, DKIM, and DMARC mandatory for bulk senders, adoption climbed past the halfway mark among major domains, and the volume of spoofed mail reaching inboxes fell by hundreds of billions of messages. But the headline adoption numbers hide a stubborn gap: a large share of domains publish authentication records that they never actually enforce.
Here are 21 sourced email authentication statistics for 2026 - covering SPF, DKIM, and DMARC adoption, the enforcement gap, the impact on spoofing and inbox trust, the Gmail and Yahoo mandate, and BIMI - with what each one means for your program.
Key takeaways
- SPF is the most-published protocol, on 56% of domains - rising to 77% of the top 1,000.
- DKIM is the least adopted, published by just 22.7% of domains, despite surviving forwarding.
- DMARC adoption reached 52.1% of the top 1.8M domains in 2026, up from 47.7% a year earlier.
- But 57.9% of DMARC domains sit at p=none - published, but not enforcing.
- Gmail and Yahoo now require bulk senders (5,000+/day) to use SPF, DKIM, and DMARC.
- Authentication works: Gmail users got 265 billion fewer unauthenticated messages in 2024, a 65% drop.
SPF adoption: the most-published protocol
1. 56% of domains publish an SPF record
DMARCGuard's analysis of 5.5 million domains found 3.08 million (56.0%) publish an SPF record - making SPF the most widely adopted of the three core protocols. It is the easiest to deploy (a single TXT record), which is exactly why it leads. But SPF alone breaks on forwarding, so it is a floor, not a finish line.
2. 59% of the top 1 million domains have a valid SPF record
Among the most-visited domains, adoption climbs. DMARCChecker's 2024 study found 59% of the top 1 million domains have a valid SPF record. The more traffic a domain carries, the more likely it is to have taken the first authentication step.
3. 77% of the top 1,000 domains publish valid SPF
At the very top, SPF is close to universal: 77% of the top 1,000 domains publish a valid SPF record. Adoption scales tightly with prominence - the biggest brands, and the biggest targets for spoofing, are the most likely to authenticate.
4. Over 93% of messages passed SPF authentication in live mail
Publishing a record is one thing; passing on real traffic is another. Cloudflare's February 2024 telemetry found over 93% of messages passed SPF authentication - the highest pass rate of the three protocols. SPF is the most-checked and most-passed signal in the inbound stream.
Check whether your SPF, DKIM & DMARC pass →
DKIM adoption: the overlooked signature
5. Only 22.7% of domains publish a DKIM record - the least-adopted protocol
DMARCGuard found just 22.7% of domains publish a DKIM record, making it the least adopted of the three. That is a costly gap: DKIM is the cryptographic signature that survives forwarding and mailing lists, and it is often the only way DMARC can pass with alignment when SPF breaks. Sendaloft configures and monitors DKIM alongside SPF and DMARC precisely because this is the layer most senders skip.
6. 88.5% of messages passed DKIM evaluation
Where DKIM is deployed, it holds up well. Cloudflare's February 2024 data shows 88.5% of messages passed DKIM evaluation. The gap between SPF and DKIM pass rates largely reflects that fewer senders sign in the first place - not that the signatures fail.
DMARC adoption: past the halfway mark
7. DMARC adoption reached 52.1% of the top 1.8 million domains in 2026
EasyDMARC's 2026 report found DMARC records on 52.1% of the top 1.8 million domains, up from 47.7% in 2025 and just 29.1% in 2023. Among major domains, DMARC has crossed the halfway line - so senders without it increasingly stand out to filters as the exception.
8. 30.4% of a 5.5 million domain sample have adopted DMARC
Across the broader web the picture is more modest. DMARCGuard found 30.4% of 5.5 million domains have adopted DMARC - about half the rate seen among top domains. The long tail of the internet is still largely unauthenticated at the DMARC layer.
9. 2.32 million organizations adopted DMARC in a single year
Red Sift found 2.32 million organizations adopted DMARC between February and December 2024 - more than double the growth of 2023. The Gmail and Yahoo mandate triggered the largest single-year surge in DMARC adoption on record.
10. 86.5% of messages passed DMARC authentication
On live inbound mail, DMARC pass rates are strong. Cloudflare's February 2024 telemetry shows 86.5% of messages passed DMARC authentication. Combined with the SPF and DKIM figures, this shows the mainstream mail stream is now overwhelmingly authenticated - the problem is concentrated in the domains that never set it up.
The enforcement gap: published, not protecting
11. 57.9% of DMARC domains sit at p=none - monitoring only
A published record is not the same as protection. Among domains with DMARC, DMARCGuard found 57.9% use p=none, 22.4% use p=quarantine, and 19.6% use p=reject - meaning only about 42% enforce. The majority monitor and report but never actually block spoofed mail, so they remain spoofable.
12. Only 8.9% of top domains combine p=reject with reporting
Full protection is rarer still. EasyDMARC found just 8.9% of the top 1.8 million domains combine a p=reject policy with active reporting, with 22.9% at any enforcement level. The gold standard - reject plus the reports that let you catch legitimate mail before it is blocked - is still the exception even among leaders.
13. 95% of the Fortune 500 have valid DMARC, and 80%+ enforce it
At the top of the market, enforcement is the norm. EasyDMARC found 95% of the Fortune 500 have valid DMARC and more than 80% are at enforcement. The largest companies - the most impersonated brands - have largely closed the gap between publishing and protecting.
14. 4,066 Inc. 5000 companies have valid DMARC - but more than half stay at p=none
A step down in size, the enforcement gap reopens. EasyDMARC found 4,066 Inc. 5000 companies have valid DMARC, yet more than half remain at p=none. Fast-growing mid-market firms have adopted the record but not the enforcement - leaving their domains open to impersonation.
15. 57.2% of top-1M domains with DMARC used p=none in 2024
The pattern is consistent across studies. DMARCChecker found 57.2% of top-1M domains with a DMARC record used p=none in 2024 - almost identical to the broad-sample figure. Wherever you look, roughly six in ten DMARC records are monitoring-only.
See if your DMARC is actually enforcing →
The payoff: spoofing that stops
16. Gmail users received 265 billion fewer unauthenticated messages in 2024
After the mandate took effect, Valimail reported Gmail users received 265 billion fewer unauthenticated messages over 2024 - a 65% reduction. This is the clearest evidence that authentication requirements work at scale: force senders to authenticate, and the flood of spoofable mail drops by hundreds of billions of messages.
17. Gmail blocks ~15 billion unwanted emails a day and stops over 99.9% of spam, phishing, and malware
Google reports that Gmail blocks roughly 15 billion unwanted emails a day and stops more than 99.9% of spam, phishing, and malware. Authentication is the signal that keeps your legitimate mail on the right side of that filter - unauthenticated mail is exactly what the 15-billion-a-day machine is built to catch.
18. 86.62% of domains still lacked adequate DMARC protection in early 2025
The job is far from done. Red Sift found 86.62% of sampled domains still lacked adequate DMARC protection in early 2025 - whether because they had no record or sat at p=none. Record adoption is rising fast, but the vast majority of domains are still not protected against impersonation.
The mandate, and what comes after it
19. Gmail and Yahoo require bulk senders (5,000+/day) to use SPF, DKIM, and DMARC
Since February 2024, Google requires anyone sending more than 5,000 messages a day to Gmail to authenticate with SPF, DKIM, and DMARC, offer one-click unsubscribe, and keep spam rates low. Yahoo matches the rules. For bulk senders, all three protocols are now a hard gate to the inbox - not a recommendation.
20. Only 0.4% of domains publish a BIMI record
BIMI - which displays your verified logo next to authenticated mail - remains nascent. DMARCGuard found just 0.4% of domains publish a BIMI record. Because BIMI requires DMARC at enforcement first, its low adoption is a direct downstream symptom of the enforcement gap: you cannot get the logo until you enforce the policy.
21. 33,924 valid BIMI records were observed through mid-2024 - only ~3,450 with a VMC
DMARC.org's tracking counted 33,924 valid BIMI records through mid-2024, of which only about 3,450 carried a Verified Mark Certificate. The VMC is the credential that actually unlocks the logo in Gmail and other major clients - so the number of domains getting the full branded-inbox benefit is smaller still. BIMI is the reward at the end of the authentication road, and very few senders have reached it.
What this means: the authentication playbook
Deploy all three protocols, not just the easy one. SPF leads at 56% adoption because it is a single record - but SPF alone breaks on forwarding, and DKIM, the signature that survives it, sits at just 22.7%. The gap between the two is where most authentication failures live. Publish SPF, sign with DKIM, and wrap both in DMARC so every send carries the full set of trust signals.
Publishing DMARC is not protecting with DMARC. Roughly six in ten DMARC records sit at p=none - monitoring only, still spoofable. A p=none record earns you the box-checking credit without the anti-abuse benefit. The whole point of DMARC is to move to p=quarantine and then p=reject once your reports show only legitimate mail is passing.
Enforcement is a size problem you can beat. 95% of the Fortune 500 enforce DMARC, but more than half of Inc. 5000 companies stay at p=none - and 86.62% of all domains still lack adequate protection. Enterprises got there with dedicated teams; smaller senders stall at p=none because moving safely to enforcement requires reading DMARC reports and fixing alignment first. That work is exactly what tooling and monitoring exist to automate.
Authentication is now a gate, and it works. Gmail and Yahoo require SPF, DKIM, and DMARC from bulk senders, Gmail blocks ~15 billion unwanted emails a day, and the mandate cut unauthenticated mail to Gmail users by 265 billion messages in one year. If you send at any volume, unauthenticated mail is not a reputation risk - it is a delivery failure waiting to happen.
Get to enforcement, then reach for the reward. BIMI's branded logo - and the trust that comes with it - is only available once DMARC is enforcing, which is why just 0.4% of domains have it. The path is the same for everyone: authenticate with all three protocols, align them, enforce DMARC, then layer BIMI on top. Before you scale, test how your domain authenticates so you fix gaps while they are still cheap.