DACH MSP Email Security Benchmark · July 2026
How protected are DACH MSPs against email spoofing?
Together with DMARC Advisor we scanned the public DMARC configuration of 1,311 Managed Service Providers across Germany, Austria and Switzerland. Applying a strict test in which only a policy of p=reject counts as protected, nearly three quarters fall short. Because MSPs run email and IT for thousands of downstream customers, an unprotected provider domain is a credible attack path into its entire client base.
The single largest group, 30.4% of providers, sits on p=quarantine, a policy that routes spoofed mail to the spam folder rather than blocking it, and does not count as protected.
Download the full benchmark
The complete report with the country breakdown, a Nordrhein-Westfalen spotlight, protection by company size and market segment, the specialist paradox, and RUA reporting visibility.
Download report (PDF)No registration required. The report is free to download.
Key findings
- Only 1 in 4 is protected. 334 of 1,311 MSPs enforce p=reject; the largest group (30.4%) sits on p=quarantine, which does not stop spoofing.
- Nearly 1 in 5 has no DMARC record at all (19.6%), leaving the domain fully open to impersonation.
- The gap is structural, not national: protection sits at 27.7% in Switzerland, 25.2% in Germany and 22.4% in Austria.
- The specialist paradox: MSPs that sell cyber or email security (26.4% protected) barely beat the average and fail to protect their own domain in almost three out of four cases.
- Reporting is a blind spot: 42.0% have no DMARC aggregate reporting (RUA), so they have zero visibility into who sends mail in their name.
About this benchmark
The data analysis was performed by DMARC Advisor and the report was produced by Guardian360, based on a non-intrusive external scan of public DNS and DMARC records for 1,311 DACH MSPs, collected on 8 July 2026. It was prepared for the Cross-border Cybersecurity Networking Event for MSPs and IT system houses (TopGolf Oberhausen, 2 September 2026), organised by the Netherlands government and InnovationQuarter, with Passguard, SecuMailer, SecureMe2, DMARC Advisor and Guardian360.
Need help reaching p=reject safely?
Guardian360 and DMARC Advisor help you move from no protection to full enforcement: continuous scanning and monitoring, automated interpretation of RUA reports, and expert guidance to reach p=reject without disrupting legitimate mail. Leave your details and we will be in touch.