Two-Thirds of Top Million Domains Can Still Be Spoofed

Study reveals 67% of top-1M domains lack enforced DMARC. Learn why compliance stats hide real spoofing risk.

domingo, 26 de julio de 2026 • 4 min read • Q2BSTUDIO Team

DMARC: la mayoría de dominios no impiden la suplantación

Email identity spoofing remains one of the most persistent and costly threats for businesses of all sizes. A recent analysis of the most visited domains worldwide reveals that approximately two-thirds lack an effective policy to prevent attackers from sending forged messages in their name. This finding reflects not just a technical gap but a strategic problem: many organizations rely on minimal measures that offer no real protection. The majority of domains that publish a DMARC record do so with the p=none policy, which blocks nothing and often lacks a reporting address. Meanwhile, losses from business email compromise (BEC) continue to grow, exceeding billions of dollars annually according to FBI data.

The DMARC protocol allows domain owners to tell mail servers how to handle messages that fail authentication. The options are p=none (monitoring), p=quarantine (mark as spam), and p=reject (reject). However, the most common option today is p=none, which offers no blocking. In many cases, it does not even include the rua tag to receive reports. This is like installing a security camera with no storage or screen: the appearance of protection with no utility. Attackers exploit this configuration to send fraudulent emails that appear legitimate, causing financial and reputational damage. Sectors such as finance, healthcare, and legal are most affected, but no company is immune.

Why do so many domains remain vulnerable? The answer lies in the difference between compliance and security. Since 2024, major providers like Google and Microsoft have required bulk senders to publish a DMARC record, but they accept p=none as the minimum requirement. This has boosted apparent adoption but turned the regulatory floor into a practical ceiling. Many companies copy and paste the same record without customizing it, forgetting to add the rua tag. Thus, thousands of domains have a DMARC that does nothing and alerts no one. This false sense of security is dangerous because IT teams believe they are protected when they are not. Additionally, the consolidation of email market share in Google Workspace and Microsoft 365 means that the decisions of these providers affect the majority of domains.

For companies that want to go beyond mere compliance, the solution is clear: implement p=quarantine or p=reject policies with a 100% percentage and correctly configure reporting addresses. However, email security is not limited to DMARC. It is part of a comprehensive cybersecurity strategy that includes perimeter protection, continuous monitoring, and incident response. At Q2BSTUDIO, as a software development and technology company, we offer cybersecurity services ranging from DMARC policy audits to penetration testing and infrastructure hardening. We help close the gaps that attackers exploit, tailoring our approach to each client’s needs.

Cloud migration is another key factor. Many companies host their mailboxes on AWS or Azure, requiring precise DNS and authentication configuration. At Q2BSTUDIO, we integrate Business Intelligence tools like Power BI to monitor spoofing attempts in real time and generate dashboards that facilitate decision-making. The combination of cloud, BI, and cybersecurity gives companies full visibility of their attack surface. Furthermore, custom software development is essential for personalizing domain management systems, incident response automation, and regulatory compliance. We create custom applications that integrate DMARC policy control with other security systems, enabling management without sacrificing agility.

Artificial intelligence and autonomous agents are transforming cybersecurity. AI agents can detect anomalous patterns in email traffic, identify phishing attempts before they reach users, and recommend DMARC policy changes based on historical data. At Q2BSTUDIO we work with artificial intelligence to offer predictive and adaptive solutions. Likewise, process automation through AI agents allows DNS record updates and key rotations to be performed without manual intervention, minimizing human errors and freeing up IT resources.

In summary, the finding that two-thirds of top domains can still be spoofed is a wake-up call. It is not enough to meet the minimum requirements of email providers; a proactive security posture is necessary. Reviewing DMARC configuration, adding a real rua address, migrating to restrictive policies, and complementing with cybersecurity, cloud, BI, and AI solutions are essential steps. At Q2BSTUDIO we are committed to helping companies transform their security posture, combining custom software development, cloud services, and the latest AI technologies. If your domain is still at p=none, do not wait: a single DNS change can make the difference between being attacked or being protected.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.