DMARC Benchmark · April 2026
How well is your domain protected against email fraud?
We analysed the DMARC configuration of 10,833 domains across 15 industries. The results are alarming: more than three quarters of all domains are not fully protected against email spoofing, phishing and business email compromise (BEC).
With the NIS2 audit deadline approaching (June 2026), a proper DMARC configuration is no longer optional for many organisations.
Download the full report
Get the complete benchmark analysis with detailed breakdowns per industry, country and DMARC policy level, including actionable recommendations.
Download report (PDF)No registration required. The report is free to download.
Industry insights
- Finance leads with 35.7% of domains at p=reject, but even here nearly two thirds remain vulnerable.
- Transport (15.3%) and Legal (16.7%) are most at risk, with the lowest adoption of strict DMARC policies.
- Only 22.4% of all scanned domains enforce the recommended p=reject policy.
About this research
This benchmark was conducted by Guardian360 in collaboration with DMARC Advisor B.V. The scan was performed in April 2026 and covers organisations across the Netherlands, Germany, Belgium and France.
Need help securing your domains?
Our specialists help you implement DMARC, SPF and DKIM correctly, and monitor your configuration over time to prevent drift. Want future DMARC insights and to discuss how we can help? Leave your details and we will be in touch.