Executive summary: Red Sift analyzed DMARC adoption across 5,000 domains belonging to the largest organizations in 49 US states and the District of Columbia. Only 1,919 domains (38.4%) have reached full DMARC enforcement. 89.5% have published a DMARC record, which means awareness is not the constraint. The gap between those two figures is the state of US email security in 2026.
Key takeaways:
- Red Sift's 2026 analysis of 5,000 US domains found 38.4% at DMARC enforcement (p=reject), the policy level that blocks spoofed email
- 1,454 US domains (29.1%) run p=none, which reports impersonation without blocking it, and 1,101 (22.0%) sit at p=quarantine
- 526 domains (10.5%) have no DMARC record at all, and 14 states account for 284 of them
- North Carolina leads the 49 ranked states at 55% DMARC enforcement. Montana and New Mexico trail at 25%
- New York City reaches 73% DMARC enforcement and Washington D.C. 57%, the two highest rates in the research and both measured as city-level studies
- Moving the 1,101 quarantine domains to p=reject would raise US DMARC enforcement from 38.4% to 60.4% with no new deployments
What this US DMARC report measures
DMARC (Domain-based Message Authentication, Reporting and Conformance) is the email authentication protocol that tells receiving mail servers what to do with messages failing SPF and DKIM (Sender Policy Framework and DomainKeys Identified Mail) checks. DMARC has three policy levels. p=none monitors and takes no action. p=quarantine routes suspicious mail to spam. p=reject blocks it outright. Only p=reject is considered full DMARC enforcement.
Between March and June 2026, Red Sift measured the DMARC policy of the top 100 organizations in 49 US states and the District of Columbia. That is 5,000 domains across 50 jurisdictions, grouped into seven regions, using consistent sample sizes and methodology throughout.
New York is the one state not included in the 50 jurisdictions. Red Sift measured it earlier as a city-level study of New York City's top 100 organizations rather than a state-level sample. Because the large majority of New York State's biggest companies are headquartered in New York City, that sample is a close proxy for what a state-level study would capture, and it is reported throughout this report as a benchmark. It is excluded from national totals so that every figure in the US total rests on identical sampling rules.
This report combines all seven regional datasets into a single national picture of US DMARC adoption.
US DMARC adoption by policy level
DMARC policy | Domains | Share of US sample | Effect |
p=reject | 1,919 | 38.4% | Blocks spoofed email |
p=quarantine | 1,101 | 22.0% | Routes spoofed email to spam |
p=none | 1,454 | 29.1% | Reports spoofing, blocks nothing |
No DMARC record | 526 | 10.5% | No authentication policy published |
Total | 5,000 | 100% |
Three figures carry the finding.
- 89.5% of top US organizations have published a DMARC record. Awareness is not the problem. Almost every large organization in the country has started.
- 57.1% of US organizations that have published a DMARC record still do not block spoofed email. They completed the DNS work, they receive the aggregate reports, and they stopped before the policy change that protects them. That is 2,555 organizations nationally.
- 60.4% of US domains have already configured authentication. Combine p=reject and p=quarantine and you get 3,020 domains that have identified their senders and configured SPF and DKIM. Moving from quarantine to reject typically takes 6 to 8 weeks. If every US quarantine domain finished, national DMARC enforcement would reach 60.4% without a single new project starting anywhere.
US DMARC enforcement by region
Rank | Region | Domains | Reject | Quarantine | None | No record |
1 | 700 | 44.1% | 19.4% | 27.3% | 9.1% | |
2 | 1,000 | 41.2% | 21.0% | 28.3% | 9.5% | |
3 | 500 | 40.2% | 22.8% | 27.6% | 9.4% | |
4 | 600 | 39.3% | 24.2% | 26.2% | 10.3% | |
5 | 900 | 36.4% | 22.4% | 31.9% | 9.2% | |
6 | 700 | 35.0% | 22.6% | 30.9% | 11.6% | |
7 | 600 | 31.3% | 22.7% | 30.3% | 15.7% | |
US total | 5,000 | 38.4% | 22.0% | 29.1% | 10.5% |
Note: Washington D.C.'s 100 domains are included in the Mid-Atlantic and US totals above. New York City was measured separately and is excluded from all totals. Both cities are compared directly further down.
The spread between the strongest and weakest US region is 12.8 points. That narrowness makes the finding harder to dismiss rather than easier. No region of the United States is well protected. The Mid-Atlantic, which contains the federal government and the country's second-largest banking center, still leaves 56% of its top organizations unable to block email claiming to come from them.
DMARC adoption by state, ranked
Rank | State | Reject | Quarantine | None | No record | Region |
1 | North Carolina | 55% | 20% | 21% | 4% | Mid-Atlantic |
2 | California | 53% | 20% | 27% | 0% | Southwest |
3 | Iowa | 49% | 21% | 24% | 6% | North Central |
4 | Michigan | 48% | 21% | 24% | 7% | North Central |
5 | Pennsylvania | 48% | 23% | 27% | 2% | Mid-Atlantic |
6 | Ohio | 47% | 26% | 23% | 4% | North Central |
7 | Minnesota | 46% | 18% | 28% | 8% | North Central |
8 | Nebraska | 46% | 22% | 24% | 8% | Heartland |
9 | New Jersey | 46% | 19% | 26% | 9% | Northeast |
10 | Arizona | 45% | 20% | 32% | 3% | Southwest |
11 | Georgia | 45% | 20% | 28% | 7% | Southeast |
12 | Illinois | 45% | 27% | 23% | 5% | North Central |
13 | Tennessee | 45% | 20% | 26% | 9% | Southeast |
14 | Texas | 45% | 18% | 34% | 3% | Heartland |
15 | Virginia | 45% | 16% | 37% | 2% | Mid-Atlantic |
16 | Wisconsin | 45% | 19% | 31% | 5% | North Central |
17 | Washington | 44% | 23% | 28% | 5% | Northwest |
18 | Kansas | 42% | 25% | 28% | 5% | Heartland |
19 | Kentucky | 42% | 21% | 29% | 8% | North Central |
20 | Massachusetts | 42% | 26% | 28% | 4% | Northeast |
21 | Connecticut | 40% | 26% | 27% | 7% | Northeast |
22 | Delaware | 40% | 18% | 19% | 23% | Mid-Atlantic |
23 | Florida | 40% | 32% | 19% | 9% | Southeast |
24 | Missouri | 40% | 20% | 34% | 6% | Heartland |
25 | Nevada | 39% | 25% | 24% | 12% | Southwest |
26 | Indiana | 37% | 26% | 33% | 4% | North Central |
27 | Oklahoma | 37% | 23% | 34% | 6% | Heartland |
28 | Alabama | 36% | 26% | 29% | 9% | Southeast |
29 | Oregon | 36% | 26% | 34% | 4% | Northwest |
30 | Mississippi | 35% | 22% | 26% | 17% | Southeast |
31 | South Carolina | 35% | 25% | 29% | 11% | Southeast |
32 | Utah | 35% | 33% | 18% | 14% | Southwest |
33 | West Virginia | 34% | 17% | 25% | 24% | Mid-Atlantic |
34 | Colorado | 33% | 21% | 39% | 7% | Heartland |
35 | Louisiana | 32% | 30% | 23% | 15% | Heartland |
36 | Rhode Island | 31% | 24% | 31% | 14% | Northeast |
37 | Maryland | 30% | 22% | 41% | 7% | Mid-Atlantic |
38 | Maine | 30% | 18% | 37% | 15% | Northeast |
39 | New Hampshire | 30% | 21% | 33% | 16% | Northeast |
40 | Hawaii | 29% | 16% | 37% | 18% | Southwest |
41 | Idaho | 29% | 19% | 33% | 19% | Northwest |
42 | Alaska | 28% | 31% | 28% | 13% | Northwest |
43 | Arkansas | 28% | 22% | 37% | 13% | Heartland |
44 | North Dakota | 27% | 14% | 38% | 21% | North Central |
45 | South Dakota | 26% | 17% | 30% | 27% | North Central |
46 | Vermont | 26% | 24% | 34% | 16% | Northeast |
47 | Wyoming | 26% | 17% | 27% | 30% | Northwest |
48 | Montana | 25% | 20% | 32% | 23% | Northwest |
49 | New Mexico | 25% | 21% | 34% | 20% | Heartland |
The ranking covers the 49 US states measured at state level. Washington D.C. and New York City are held out because both were measured as city-level studies, and comparing a city sample against a state sample flatters the city. Both are compared against each other in the next section, where 57% and 73% would otherwise rank first and second.
Check your own domain
Use Red Sift Investigate to see your DMARC, SPF, and DKIM configuration in 30 seconds, using your real business email.
New York City against Washington D.C.
Red Sift measured two US cities directly, the country's commercial capital and its political one. Both are dense, heavily regulated, and full of organizations that would be obvious impersonation targets. They are the only two places in this research where a majority of top organizations block spoofed email, and they are 16 points apart.
Metric | New York City | Washington D.C. |
p=reject | 73% | 57% |
p=quarantine | 15% | 20% |
p=none | 12% | 21% |
No DMARC record | 1% | 2% |
New York City is the strongest result Red Sift has recorded anywhere in the United States. 73 of its 100 largest organizations block spoofed email, and a single domain has no DMARC record at all. Washington D.C. is second at 57%, which beats every state in the ranking but leaves 43 of its top organizations unable to stop an email claiming to come from them.
The gap is worth sitting with, because the expectation runs the other way. Federal agencies have operated under a CISA binding operational directive requiring DMARC at p=reject since 2017, which is longer and more explicit than any obligation facing a New York bank. Yet the city with a mandate trails the city with a market.
Sample composition explains part of it. Washington D.C.'s top organizations are not only federal agencies. The sample spans lobbying firms, think tanks, trade associations, membership bodies, and nonprofits, none of which fall under federal directives. New York City's spans financial services, insurance, media, real estate, and professional services, where NYDFS cybersecurity rules, PCI DSS obligations, and customer and counterparty due diligence all push the same way. Red Sift did not segment either sample by organization type, so this is a reading of the data rather than a measured finding, and it is the obvious next study to run.
The practical point stands either way. New York City proves that a majority of large organizations reaching enforcement is achievable, in the same threat environment and under the same mailbox provider rules as the 25% states. Nothing about the bottom of the table is inevitable.
Three patterns hold across the whole dataset
DMARC enforcement tracks commercial and regulatory density
New York City's 73% and Washington D.C.'s 57% are the two highest rates in the research, and both are dense, heavily regulated urban centers. The top of the state ranking follows the same logic, with banking North Carolina, technology California, and insurance and agriculture Iowa. The bottom is Montana, New Mexico, Wyoming, and South Dakota. States where regulators, auditors, payment networks, and large corporate security teams concentrate move faster on DMARC. States whose largest employers are energy producers, agricultural cooperatives, and regional healthcare systems move slower, and they move slower even when they host infrastructure of obvious national importance.
The last mile is where US organizations stall
2,555 US organizations have a DMARC record that does not block spoofed email. Maryland has 41 of its top 100 domains at p=none, the highest count in the country, in a state hosting the NSA, US Cyber Command, and the NIH. Colorado has 39 and hosts NORAD and US Space Command. Virginia has 37 alongside the densest cluster of defense contractors in the United States. Each of these organizations receives DMARC aggregate reports showing impersonation attempts in near real time. The data arrives. Nobody acts on it.
Two failure modes need two different fixes
Coastal and commercial states publish records almost universally and stall at policy. California has a 0% no-record rate and still leaves 47% of its top organizations unprotected. Oregon has a 4% no-record rate and 60 of its top 100 domains parked at none or quarantine.
Interior and rural states fail earlier. Wyoming carries a 30% no-record rate, South Dakota 27%, West Virginia 24%, and Montana 23%. Fourteen states hold 284 of the country's 526 no-record domains, more than half the national total from just over a quarter of the sample. One group needs to finish a project. The other needs to start one.
Which US sectors carry the most email security exposure
The seven regional studies surfaced the same industries repeatedly. Combined, they map a national risk picture that follows the money rather than the state line.
Defense and national security
This is the most uncomfortable finding in the series. Four of the five lowest-scoring US jurisdictions host strategic military or national laboratory infrastructure. Montana (25%) and Wyoming (26%) operate two of the three US land-based Minuteman III nuclear missile wings. New Mexico (25%) hosts Sandia National Laboratories and Los Alamos National Laboratory. South Dakota (26%) hosts Ellsworth Air Force Base. Add North Dakota's Minot Air Force Base at 27%, Hawaii's US Indo-Pacific Command at 29%, and Alaska's Ground-based Midcourse Defense system at 28%, and the pattern is clear. Defense contractors and research partners in these states send procurement, logistics, and program email daily. A spoofed domain in that supply chain is a national security exposure, and CMMC and NIST frameworks already recommend DMARC as a baseline control.
Energy and natural resources
Texas, Oklahoma, Louisiana, Colorado, New Mexico, Wyoming, North Dakota, and Alaska produce the majority of US oil, gas, coal, and renewables. Royalty payments, drilling contracts, pipeline right-of-way agreements, and joint venture settlements all move by email in six and seven-figure amounts. The FBI's IC3 logged $3.04 billion in business email compromise losses in 2025, with 86% of that money moving by wire transfer or ACH. Of those eight energy states, only Texas and Oklahoma clear 35% DMARC enforcement.
Manufacturing and automotive
Michigan (48%), Ohio (47%), Illinois (45%), Tennessee (45%), Wisconsin (45%), Kentucky (42%), Indiana (37%), Alabama (36%), and South Carolina (35%) form a manufacturing belt running from the Great Lakes to the Gulf. Just-in-time supply chains mean a single plant draws on hundreds of vendors, and purchase orders, tooling contracts, and delivery confirmations all travel by email. A spoofed Tier 1 supplier domain can redirect a large payment or halt a production line before anyone notices.
Financial services, insurance, and payments
North Carolina (55%) holds the second-largest US banking center. Illinois (45%) holds CME Group and CBOE. Iowa (49%) and Nebraska (46%) anchor major insurance clusters. Georgia (45%) processes a large share of US card payments through the fintech cluster known as Transaction Alley. This sector performs best in the study, which is what regulatory pressure looks like in data, and it still leaves roughly half its top organizations short of enforcement. South Dakota is the outlier that proves the point, sitting at 26% despite a credit card processing cluster in Sioux Falls.
Healthcare, biotech, and higher education
Massachusetts (42%), Pennsylvania (48%), Tennessee (45%), Minnesota (46%), and Maryland (30%) concentrate hospital systems, medical device manufacturers, research institutions, and the densest university cluster in the country. Patient data, clinical trial coordination, insurance claims, and referral networks all run on email. A spoofed hospital or .edu domain can compromise protected health information, trigger HIPAA exposure, and harvest credentials from large rotating user populations.
Logistics, ports, and agriculture
Tennessee holds FedEx's global hub, Georgia holds UPS and the Port of Savannah, and Kentucky holds UPS Worldport. Washington, Louisiana, South Carolina, and Florida hold major ports. Iowa, Kansas, Nebraska, Arkansas, and the Dakotas anchor grain, dairy, and livestock supply chains. Freight booking, customs documentation, commodity contracts, and carrier invoicing are email-driven processes involving large sums and tight timelines, which is exactly the profile attackers look for.
The enforcement deadline already passed
Google and Yahoo began requiring DMARC for bulk senders in February 2024. Microsoft followed in May 2025 for high-volume senders to Outlook, Hotmail, and Live.com addresses. Non-compliant messages are now rejected outright rather than filtered.
That changes what the 526 no-record US domains are risking. They are not only exposed to impersonation, they are increasingly unable to reach their own customers. The 1,454 domains at p=none face the same pressure as enforcement tightens across every major mailbox provider.
Compliance is moving the same way. PCI DSS 4.0.1 mandates DMARC for organizations handling payment card data. NIS2 applies to any US firm with EU operations or clients. NERC CIP standards increasingly touch email authentication for bulk power system operators. Cyber insurers are tightening terms, and some now exclude BEC payouts where basic email authentication is absent. The 61.6% of top US organizations without DMARC enforcement are not exempt from these requirements. They have not acted on them yet.
Frequently asked questions about US DMARC adoption
Closing the gap
Across seven regions and 5,000 US domains, the organizations that never reach p=reject rarely lack intent. They lack sender visibility, time, and a way to keep authentication intact as infrastructure changes. That is what Red Sift OnDMARC automates, compressing a rollout that routinely runs past seven months into a few weeks, keeping SPF valid past its ten-lookup limit with Dynamic SPF, and turning raw report XML into a live view of every service sending as your domain.
The United States sits at 38.4% DMARC enforcement. New York City at 73%, Washington D.C. at 57%, and North Carolina at 55% show what is achievable inside the same threat environment and the same regulatory system as everyone else. For the 3,081 US organizations that have not reached full enforcement, the distance between a published DMARC record and a protected domain is a short project rather than a new one.
Start by finding out where your own domain sits.
See your domain's DMARC status in 30 seconds
Methodology
Red Sift analyzed the published DMARC record of 100 domains belonging to the largest organizations by revenue and headcount in each of 49 US states and the District of Columbia, 50 jurisdictions and 5,000 domains in total, across seven regional studies published between March and June 2026.
Each domain was classified by its DMARC policy at time of measurement into one of four states, p=reject, p=quarantine, p=none, or no record found. Sample sizes and methodology are consistent across all seven studies. The state ranking lists the 49 states measured at state level. Washington D.C.'s 100 domains are included in the Mid-Atlantic and US totals but excluded from the state ranking, because D.C. is not a state. New York State was not sampled at state level. New York City was analyzed separately as a city-level study of 100 domains and is excluded from all regional and national totals. Regional and national figures in this report reconcile to the totals published in each original regional study.
Jack leads content, PR, GEO, and email security research at Red Sift.




