July 28, 2026

Inbox security? More like inbox chaos

DMARC Has Been Public Since 2012. 68.4% of Domains Still Don't Enforce It

Companies had 14 years to lock down email, and the comments are absolutely not calm

TLDR: A new analysis says over two-thirds of company domains still don’t fully use a long-available tool meant to stop fake emails impersonating them. Commenters were split between blaming understaffed admins, mocking copy-paste setups, and raging that big email companies ignore abuse while everyone else gets lectured about security.

A new CipherCue analysis just dropped a stat that sounds like a collective IT homework fail: 68.4% of company domains still don’t fully enforce email anti-spoofing rules. In plain English, that means a huge chunk of businesses still haven’t told inbox providers to actually block fake emails pretending to be from them. Even wilder, many did the digital equivalent of buying a security system and never turning it on: they published a record, then left it in “watch only” mode for years.

But the real fireworks were in the comments, where the crowd split into two camps: “Why is this still so hard?” and “Maybe email itself is the problem.” One self-hoster basically shrugged and asked what extra benefit this adds if basic protections already seem to work. Another commenter blamed tiny organizations and copy-paste tech culture, saying plenty of companies set this stuff up without understanding it, then leave the default setting forever. And then came the scorched-earth hot takes: some argued the biggest spam offenders are the giant email platforms themselves, accusing them of ignoring abuse because nobody dares block them. That escalated into full “email is broken, fork it” energy, with one user dreaming of a community-run alternative that keeps the corporate giants out.

So yes, the article is about an old email safety tool. But the comment section turned it into a familiar internet drama: lazy admins, overwhelmed small teams, Big Tech rage, and a side of homelab procrastination comedy.

Key Points

  • CipherCue checked DNS records for 67,336 domains in its tracked dataset between 2026-04-14 and 2026-07-28 and found that 45.1% had no DMARC record.
  • Among domains with a DMARC record, 42.5% were set to `p=none`, 27.7% to `p=quarantine`, and 29.7% to `p=reject`.
  • CipherCue counts only `p=quarantine` and `p=reject` as enforcing policies; `p=none` is treated as non-enforcing monitoring mode.
  • Overall, 68.4% of all domains checked either had no DMARC record or had a non-enforcing `p=none` policy.
  • The article says a major barrier to moving from `p=none` to enforcement is the work of reviewing `rua=` aggregate reports to identify legitimate sending sources.

Hottest takes

"Probably because it was in the example" — tgv
"I gave up even trying to send abuse reports because they just get ignored" — jwr
"email is f*ked and needs to be forked" — talkingtab
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.