What are the current DMARC adoption rates and future expectations?

Summary

DMARC adoption is steadily increasing globally, driven by growing awareness of email security threats like phishing and spoofing, the need to protect brand reputation, and the incentive of BIMI adoption. While DMARC might not become a strict requirement soon, aligning with SPF and DKIM for DMARC readiness is a best practice. Benefits include improved deliverability and protection from fraudulent emails. However, implementation costs and business process changes can be significant barriers. Future expectations involve stricter enforcement by mailbox providers and increased importance of DMARC reporting. Starting with DMARC on new domains is easier than retrofitting existing ones. Organizations should aim for full DMARC compliance, even if gradually, and proactively monitor their DMARC reports. Domains with properly configured DMARC records achieve better delivery rates, crucial for domain reputation and sender trust.

Key findings

  • Growing Adoption: DMARC adoption is rising, protecting a significant portion of email traffic.
  • Key Drivers: Security concerns, brand protection, and BIMI are driving DMARC adoption.
  • Best Practice: Aligning with SPF/DKIM for DMARC readiness is a recommended best practice.
  • Phishing Protection: DMARC effectively reduces phishing attacks and spoofing.
  • Future Enforcement: Expect stricter enforcement of DMARC policies by mailbox providers in the future.

Key considerations

  • Implementation Costs: Consider the costs and complexity of DMARC implementation and maintenance.
  • New Domains: Implementing DMARC is easier on new domains.
  • Gradual Rollout: A gradual implementation, starting with monitoring and quarantine, is advisable.
  • Full Compliance: Aim for full DMARC compliance to avoid deliverability issues.
  • Proactive Monitoring: Regularly monitor DMARC reports for insights and issue resolution.

What email marketers say
11Marketer opinions

DMARC adoption is growing due to increasing awareness of email security threats, the desire to protect brand reputation, and the rise of BIMI. It's becoming increasingly necessary for email marketing, with mailbox providers expected to enforce stricter DMARC policies. While adoption is on the rise, many organizations hesitate to implement a 'reject' policy due to concerns about blocking legitimate emails, preferring a gradual approach. DMARC reporting is crucial for understanding email handling and identifying issues. Failing DMARC authentication will likely result in email rejection, impacting deliverability. Starting with DMARC on new domains is easier than implementing it later. DMARC plays a vital role in domain reputation and maintaining sender trust.

Key opinions

  • Growing Adoption: DMARC adoption is steadily increasing across industries.
  • Driving Factors: Adoption is driven by email security threats, brand protection, and BIMI.
  • Policy Trends: Organizations are gradually moving towards stricter DMARC policies.
  • Reporting Importance: DMARC reporting is crucial for understanding email deliverability issues.
  • Future Impact: Failing DMARC authentication will likely result in email rejection.

Key considerations

  • New vs. Existing Domains: Implementing DMARC is easier on new domains than existing ones.
  • Gradual Implementation: Consider a gradual implementation approach, starting with 'monitor' and 'quarantine' before 'reject'.
  • Compliance: Ensure full DMARC compliance to avoid future deliverability issues.
  • Domain Reputation: DMARC is critical for managing and protecting your domain's reputation.
  • Monitoring is Key: Proactive monitoring is crucial to prevent deliverability problems.
Marketer view

Email marketer from LinkedIn user EmailSecurityExpert shares that DMARC adoption is being driven by the growing interest in BIMI (Brand Indicators for Message Identification). To use BIMI, senders must have DMARC in place, encouraging wider adoption.

May 2024 - LinkedIn
Marketer view

Email marketer from ReturnPath (now Validity) stated that the expectation is DMARC becomes critical for managing and protecting domain reputation, ensuring that only legitimate emails are delivered and maintaining sender trust.

March 2024 - ReturnPath
Marketer view

Email marketer from Validity notes that DMARC adoption has seen considerable growth in recent years, driven by increased awareness of email security threats and the need to protect brand reputation. Many organizations are moving towards stricter DMARC policies (p=quarantine or p=reject).

July 2024 - Validity
Marketer view

Email marketer from Mailhardener shares the future expectation is stricter enforcement of DMARC policies by mailbox providers, which means companies need to make sure their email setups are fully compliant to avoid deliverability issues.

April 2024 - Mailhardener
Marketer view

Email marketer from EmailToolTester highlights that DMARC adoption is beneficial not only for security but also for improving email deliverability. As more mailbox providers prioritize DMARC compliance, senders without DMARC records may face deliverability challenges.

July 2024 - EmailToolTester
Marketer view

Email marketer from an email security forum states that while DMARC adoption is increasing, many organizations are still hesitant to move to a 'reject' policy due to concerns about blocking legitimate emails. The trend is towards gradual implementation, starting with 'monitor' and then 'quarantine'.

March 2024 - Email Security Forums
Marketer view

Email marketer from SendForensics highlights that future expectations are that failing DMARC authentication will increasingly lead to emails being rejected by mailbox providers, significantly impacting deliverability. proactive monitoring is key.

December 2024 - SendForensics
Marketer view

Email marketer from SparkPost notes that DMARC reporting is crucial for understanding how your emails are being handled and identifying potential issues. Increased focus on DMARC reporting is expected in the future.

August 2024 - SparkPost
Marketer view

Email marketer from Reddit user EmailMarketingPro states that DMARC is becoming increasingly necessary for any business that relies on email marketing. They believe that mailbox providers will eventually require DMARC compliance, making it essential for future deliverability.

June 2024 - Reddit
Marketer view

Email marketer from Port25 states that DMARC is increasingly crucial in email authentication and that the trend is for more stringent policies, potentially impacting deliverability if DMARC compliance isn't maintained.

April 2022 - Port25
Marketer view

Marketer from Email Geeks shares that if you're deploying a new domain, start with DMARC as its easier than trying to implement it later.

April 2021 - Email Geeks

What the experts say
5Expert opinions

DMARC adoption is considered vital for improving email security and protecting against phishing attacks. While not a mandatory requirement in the foreseeable future, aligning with SPF and DKIM for DMARC readiness is seen as a best practice. Cost and complexity in implementation are significant barriers to wider adoption, often requiring changes to existing business processes. Domains with correctly configured DMARC records passing alignment checks are more likely to experience better delivery rates, emphasizing the benefits of full adoption. Starting a new domain with DMARC in place is easier than retrofitting an existing one.

Key opinions

  • DMARC Security Importance: DMARC is vital for improving email security and protecting against phishing attacks.
  • Not a Requirement: DMARC is unlikely to become a mandatory requirement in the near future.
  • Best Practice: Aligning with SPF and DKIM is a recommended best practice for DMARC readiness.
  • Implementation Costs: Cost and complexity are major barriers to DMARC adoption.
  • Improved Delivery: Domains with correctly configured DMARC are more likely to have better delivery rates.

Key considerations

  • Cost-Benefit Analysis: Carefully weigh the costs and benefits of DMARC implementation, considering the potential return on investment.
  • Start from Scratch: For new domains, implement DMARC from the beginning for easier setup.
  • Alignment: Ensure proper SPF and DKIM alignment for DMARC to function effectively.
  • Business Process Changes: Be prepared to make potentially significant changes to existing business processes to support DMARC.
  • Stricter Enforcement: Future expectations involve stricter enforcement of DMARC policies by mailbox providers.
Expert view

Expert from Email Geeks shares that starting from scratch is easy compared to trying to work out all the folks legitimately sending your mail.

December 2024 - Email Geeks
Expert view

Expert from Email Geeks shares that Google announced they would be moving all their mail to p=reject in 2016 and then didn’t, indicating that DMARC is unlikely to become a requirement in the foreseeable future. However, she still believes that it is best practice for mail to align with both SPF and DKIM to be DMARC ready.

December 2023 - Email Geeks
Expert view

Expert from SpamResource explains that DMARC adoption is vital for improving email security and protecting against phishing attacks. The site stresses the importance of implementing DMARC and reports that future expectations involve stricter enforcement of DMARC policies by mailbox providers.

June 2021 - SpamResource
Expert view

Expert from Word to the Wise shares the trend in the industry is that domains which have DMARC setup correctly and pass alignment checks are more likely to see better delivery rates. The site emphasizes the benefits of fully adopting DMARC for all sending domains to ensure future delivery success.

September 2023 - Word to the Wise
Expert view

Expert from Email Geeks explains that one of the biggest things holding back DMARC adoption is its cost to implement and maintain. She continues to state that there are places where whole business processes need to be changed in order to support DMARC and there is no clear incentive to invest millions of dollars in a technology that doesn’t have a clear million dollar upside.

July 2022 - Email Geeks

What the documentation says
5Technical articles

DMARC adoption is steadily increasing, protecting a significant portion of global email traffic. Implementing DMARC helps reduce phishing attacks and domain spoofing. Major email providers like Google and Microsoft emphasize the importance of DMARC for email security and anti-spoofing protection. RFC7489 defines DMARC's technical specifications and sees it as a future requirement for email security.

Key findings

  • Increasing Adoption: DMARC adoption is growing, protecting a significant portion of global email.
  • Reduces Phishing: DMARC implementation helps reduce phishing attacks and spoofing.
  • Recommended by Providers: Google and Microsoft recommend DMARC for email security.
  • Technical Standard: RFC7489 provides the technical specifications for DMARC.
  • Future Requirement: DMARC is seen as a future requirement for email security.

Key considerations

  • Implement DMARC: Organizations should implement DMARC to improve email security.
  • Reduce Phishing: Implementing DMARC helps protect domains and recipients from phishing attacks.
  • Follow Standards: Adhere to the technical specifications outlined in RFC7489 when implementing DMARC.
  • Anti-Spoofing: Use DMARC with SPF and DKIM for comprehensive anti-spoofing protection.
  • Ongoing Monitoring: Monitor DMARC reports regularly to identify and address potential issues.
Technical article

Documentation from Google states that having a DMARC record is important for protecting your domain from spoofing and phishing. Google encourages all domain owners to implement DMARC to improve email security for everyone.

March 2024 - Google
Technical article

Documentation from Proofpoint (formerly Agari) reports DMARC implementation helps reduce phishing attacks and domain spoofing. They mention statistics showing a significant decrease in fraudulent emails for organizations that have fully implemented DMARC.

December 2021 - Proofpoint
Technical article

Documentation from dmarc.org shares that DMARC adoption is steadily increasing, with a significant portion of global email traffic now protected by DMARC. They state specific percentages for different sectors but emphasize ongoing growth.

January 2025 - dmarc.org
Technical article

Documentation from Microsoft shares that DMARC, along with SPF and DKIM, is an important email authentication method that helps prevent spoofing and phishing attacks. Microsoft emphasizes the importance of using these methods for anti-spoofing protection in Exchange Online Protection (EOP).

December 2021 - Microsoft
Technical article

Documentation from the RFC Editor states that RFC7489 defines DMARC and provides the technical specifications for its design and implementation and is seen as a future requirement for email security.

December 2021 - RFC Editor