DMARC Benchmark · April 2026

How well is your domain protected against email fraud?

We analysed the DMARC configuration of 10,833 domains across 15 industries. The results are alarming: more than three quarters of all domains are not fully protected against email spoofing, phishing and business email compromise (BEC).

77.6%of domains are not fully protected
25.8%have no DMARC record at all
15industries analysed
10,833domains scanned

With the NIS2 audit deadline approaching (June 2026), a proper DMARC configuration is no longer optional for many organisations.

Download the full report

Get the complete benchmark analysis with detailed breakdowns per industry, country and DMARC policy level, including actionable recommendations.

Download report (PDF)

No registration required. The report is free to download.

Industry insights

  • Finance leads with 35.7% of domains at p=reject, but even here nearly two thirds remain vulnerable.
  • Transport (15.3%) and Legal (16.7%) are most at risk, with the lowest adoption of strict DMARC policies.
  • Only 22.4% of all scanned domains enforce the recommended p=reject policy.

About this research

This benchmark was conducted by Guardian360 in collaboration with DMARC Advisor B.V. The scan was performed in April 2026 and covers organisations across the Netherlands, Germany, Belgium and France.

Need help securing your domains?

Our specialists help you implement DMARC, SPF and DKIM correctly, and monitor your configuration over time to prevent drift. Want future DMARC insights and to discuss how we can help? Leave your details and we will be in touch.

I am reaching out as a…