Blog · Dmarc

Why 37% of DMARC-Protected Domains Still Sit at p=none — and What the Data Actually Tells Us

Most domains with a DMARC record are not actually using it to enforce anything.

That sounds surprising until you look at the numbers. Mimecast's email security reports have consistently shown that roughly 37% of domains that have adopted DMARC are still running at `p=none` - monitoring mode, where the policy only requests reports and takes no action against unauthenticated email.

The other 63% are split between `p=quarantine` (mark suspicious mail) and `p=reject` (block it outright). But that split is uneven. `p=reject` remains the minority policy, even among domains that have technically "adopted" DMARC.

This post breaks down what the 37% figure actually means, why so many domains stop at monitoring mode, and what risks that leaves open.