Blog · Industry research
The State of Email Security Across the Top Million Domains
How does your domain's email security setup compare to everyone else?
That question sounds simple, but most domain owners have no way to answer it. You can configure DMARC, MTA-STS, DANE, and BIMI correctly for your own domain and still have no sense of whether you are ahead of or behind your peers.
A monthly research project has been measuring exactly that across the top one million domains for two months running. Here is what the data shows.
Why Benchmarking Email Security Matters
Email security is not a one-time configuration. DMARC policies shift, DNS records change, and mail providers introduce or remove security features without domain owners noticing. The practitioner who set up email authentication correctly twelve months ago may now be behind the curve because the field moved.
Benchmarks serve two purposes. First, they tell you whether your domain's posture is improving or slipping relative to others. Second, the patterns in aggregate adoption data reveal where the biggest gaps are and which protocols need more attention.
The numbers below come from a researcher who runs an email infrastructure company and has been publishing monthly measurements since June 2026.
What the Data Shows Across the Top Million Domains
The researcher measured four email security standards across the top one million domains: DMARC, MTA-STS, DANE-for-SMTP, and BIMI. Here is what month two of the dataset reveals.
DMARC Adoption and Policy Distribution
DMARC continues to show the strongest adoption trajectory of the four protocols. In month two, the count of valid DMARC records increased by 2,282 domains compared to month one. More significantly, domains tightening their policy outnumbered those loosening them by 2,488 to 567.
This means the ecosystem is not just adding DMARC records. It is enforcing them. The ratio of domains moving toward p=quarantine or p=reject outpaces those retreating to p=none by more than four to one.
If the current pace held, DMARC could reach near-universal adoption across the top million domains by the early 2030s. That projection comes with the usual caveats about real adoption curves flattening near the top, but the direction is clear.
MTA-STS Adoption: The Large Gap
MTA-STS (Mail Transfer Agent Strict Transport Security) encrypts the connection between mail servers. It is the protocol that protects email in transit, not just at the endpoint.
Month two data shows MTA-STS valid policy records increasing by only 163 domains across the top million. Of those, 76 domains graduated from testing mode to enforce mode, while 10 domains went the opposite direction.
MTA-STS adoption is growing, but at a pace that projects toward the 2040s and beyond before meaningful coverage. There is no major receiver mandate requiring MTA-STS the way there is for sender authentication via DMARC, and that absence shows in the numbers.
One telling detail: ALDI Sud switched on MTA-STS for eleven of its country domains in a single coordinated change. Email security at the provider level moves in blocks, not one domain at a time.
DANE Adoption: Minimal Uptake and One Provider's Impact
DANE (DNS-based Authentication of Named Entities) for SMTP binds TLS certificates to DNS records, preventing man-in-the-middle attacks on mail delivery. It is the strongest transport security option available.
Month two is the only month where DANE went backward. The measured count dropped by 249 domains.
The reason is a single provider, Migadu, which removed TLSA records for its entire customer fleet sometime in June. Around 500 domains lost DANE without any action on their part, and most likely without their knowledge. When the Migadu deletions are removed from the calculation, DANE actually grew by 258 domains.
The takeaway is that DANE adoption is largely inherited from mail provider defaults, not actively configured by domain operators. Of the 488 domains that gained DANE in month two, 466 got it simply by moving to a mail host that publishes DANE by default, mostly Cloudflare Email Routing. Around 60 of those domains were clearly low-effort setups that never intentionally touched a DNS record.
Provider decisions drive DANE adoption more than operator expertise.
BIMI Adoption: Early Days
BIMI (Brand Indicators for Message Identification) displays sender logos in supporting mail clients. It is the newest of the four standards and has the smallest footprint.
BIMI gained 346 domains in month two. That is real growth, but against a top one million base, it represents a tiny fraction of one percent. BIMI adoption is genuinely early stage and will require both receiver support and certificate infrastructure to scale in any meaningful way.
What This Means for Your Domain
The data reveals a structural gap in how email security is spreading.
DMARC adoption is being pushed by major receivers like Microsoft and Google enforcing it as a baseline requirement for good deliverability. Domain owners did not always choose DMARC; their mail providers often made the decision for them through default configurations.
MTA-STS and DANE have no equivalent forcing function. There is no major receiver mandate requiring them, and the operational complexity of MTA-STS policy files and DANE TLSA records means they are unlikely to spread through defaults alone. The projection that these two protocols stay a decade behind DMARC is not pessimistic; it reflects the absence of any catalyst that would accelerate adoption.
For domain owners, the practical implication is clear. If you are only doing DMARC, you are securing who sent the mail but leaving the transport unprotected. MTA-STS and DANE are the missing half of email security.
A domain that has p=reject on DMARC but no MTA-STS or DANE is still sending unencrypted mail between servers, vulnerable to interception. The protocols that protect the connection are lagging far behind the protocol that authenticates the sender.
The other pattern worth noting: most domain operators did not consciously choose their email security posture. They inherited it from their provider. The 500 domains that lost DANE when Migadu removed TLSA records never made that decision. The 466 domains that picked up DANE by switching to Cloudflare Email Routing never configured it themselves. Email security for most domains is a provider default, not an operator choice.
This means monitoring your own domain posture matters more than the aggregate numbers suggest. The field is not just moving slowly. It is moving in provider-sized blocks, which means a single hosting decision can jump your security forward or backward without you knowing.
How to Monitor Your Domain Email Security Posture Over Time
This is where ongoing monitoring changes the picture. The aggregate data tells you what the field looks like. Your own monitoring tells you what your domain actually looks like, and it surfaces changes before they become problems.
DMARCFlow monitors your domain across all four protocols: DMARC, MTA-STS, DANE, and BIMI. It tracks policy changes, record status, and aggregate statistics over time so you can see whether your domain is improving, slipping, or holding steady relative to the benchmarks described above.
Without monitoring, the Migadu-style deletion would go unnoticed until legitimate mail started failing. With monitoring, you see the change the day it happens and can respond.
The top million domain data gives you the field context. Your own monitoring gives you the specific picture for your domain. Both are necessary to understand where you actually stand.
FAQ
What percentage of domains have a DMARC record?
Based on month two data across the top million domains, valid DMARC records increased by roughly 2,282 domains in a single month. The absolute percentage depends on the measurement methodology, but adoption is growing at a pace that projects toward the majority of domains within the next several years.
What percentage of domains have p=reject policy?
DMARC p=reject is the strongest policy level. Month two data shows domains tightening their policy outnumbering those loosening it by more than four to one, indicating steady movement toward enforcement. The exact percentage varies by study methodology, but the trend is clearly toward stronger policies.
How many domains have MTA-STS?
MTA-STS has the lowest adoption rate of the four protocols measured. Month two showed only 163 net new valid policy records. Projecting the current pace, meaningful MTA-STS coverage across the top million domains is more than a decade away without a forcing function.
What is the BIMI adoption rate across the top million domains?
BIMI is in the earliest stages of adoption. Month two added 346 domains with BIMI records out of a top million base. BIMI requires both receiver support and Certificate Authority accreditation, which limits its current reach.
How can I check my own domain email security posture?
You can check your domain DMARC record by querying DNS. For MTA-STS, look for an MTA-STS policy file at mta-sts.yourdomain.com. For DANE, check for TLSA records at _25._tcp.yourmailserver.com. For a continuous view of all four protocols and how they change over time, use a monitoring tool that tracks email security statistics.
---
The data across the top million domains tells a consist