The most common DMARC policy does nothing.

When I scan Australian small business domains, the most common finding is not a missing DMARC record. It is a present one, published at p=none and unchanged since the day someone demanded it, usually a mail provider, sometimes a compliance checklist, occasionally an insurer. The record is there, the audit box is ticked, and the domain looks covered.

p=none is monitoring mode. It instructs every receiving mail server to take no action against mail that fails authentication, deliver it as if nothing happened, and send the domain owner a report afterwards. A domain at p=none is exactly as spoofable as a domain with no record at all. The record's entire function at that policy is to generate reports, and most owners have never opened one, many never published an address to receive them in the first place.

The scale of this is now measurable. EasyDMARC's 2026 DMARC Adoption Report analysed the top 1.8 million domains worldwide. 937,931 of them publish valid DMARC, 52.1 per cent, up from 27.2 per cent in 2023. Of those, 525,996 sit at p=none. Most of the growth in adoption has been growth in monitoring mode.

The gap sharpens when you sort by company size. The same report puts Fortune 500 adoption at 95 per cent, with 62.7 per cent enforcing at p=reject. The Inc. 5000, the high-growth businesses, reaches 76 per cent adoption but only 15.2 per cent at reject. Enterprises finish the job, growing businesses publish the record and stop.

That distribution is backwards from where the damage lands. When a domain gets spoofed, the enterprise has a security team, a comms plan and lawyers. The small operator finds out when a customer pays a fraudulent invoice that carried their name, and the customer does not blame the criminal, they blame the business whose domain was on the email.

In fairness, p=none is the correct first step, the protocol's designers built the ramp deliberately. Moving a domain straight to reject breaks real mail. The CRM sends on your behalf, so does the newsletter tool, the booking system, the accountant's practice software, and every one of them has to be found and aligned before enforcement is safe. Monitoring mode is how you find them. The caution is earned.

The problem is what the standard advice leaves out. Every checklist says publish a DMARC record, and the mailbox provider requirements that drove the adoption surge ask for exactly that, a record, minimum policy none. So the requirement is satisfied by the one configuration that provides no protection. Nothing in the checklist schedules the second step, reading the reports, aligning the senders, graduating the policy, because that part is work with no visible payoff until the day someone abuses the domain, at which point it is the only work that would have mattered.

The pattern is bigger than DMARC. Audit mode, report-only, monitor first. The industry is good at installing controls and slow at turning them on, because installation is a task and enforcement is a decision. A task can be handed to a checklist. A decision needs someone to read the data, own the risk and commit.

A DMARC record at p=none is a decision deferred. Most of the value in this work is not publishing records, it is finishing them.

Back to Writing