Blog · Dmarc
Why 37% of DMARC-Protected Domains Still Sit at p=none — and What the Data Actually Tells Us
Most domains with a DMARC record are not actually using it to enforce anything.
That sounds surprising until you look at the numbers. Mimecast's email security reports have consistently shown that roughly 37% of domains that have adopted DMARC are still running at `p=none` - monitoring mode, where the policy only requests reports and takes no action against unauthenticated email.
The other 63% are split between `p=quarantine` (mark suspicious mail) and `p=reject` (block it outright). But that split is uneven. `p=reject` remains the minority policy, even among domains that have technically "adopted" DMARC.
This post breaks down what the 37% figure actually means, why so many domains stop at monitoring mode, and what risks that leaves open.