Skip to content

US DMARC adoption: 5,000 domains ranked by state

Red Sift analyzed DMARC adoption across 5,000 US domains in 49 states and D.C. Only 38.4% block spoofed email. See the full state ranking and sector data.

Jack Lilley·Sr. Comms & Content Marketing Manager
Published: August 26, 2026·17 min read

Executive summary: Red Sift analyzed DMARC adoption across 5,000 domains belonging to the largest organizations in 49 US states and the District of Columbia. Only 1,919 domains (38.4%) have reached full DMARC enforcement. 89.5% have published a DMARC record, which means awareness is not the constraint. The gap between those two figures is the state of US email security in 2026.

Key takeaways:

  • Red Sift's 2026 analysis of 5,000 US domains found 38.4% at DMARC enforcement (p=reject), the policy level that blocks spoofed email
  • 1,454 US domains (29.1%) run p=none, which reports impersonation without blocking it, and 1,101 (22.0%) sit at p=quarantine
  • 526 domains (10.5%) have no DMARC record at all, and 14 states account for 284 of them
  • North Carolina leads the 49 ranked states at 55% DMARC enforcement. Montana and New Mexico trail at 25%
  • New York City reaches 73% DMARC enforcement and Washington D.C. 57%, the two highest rates in the research and both measured as city-level studies
  • Moving the 1,101 quarantine domains to p=reject would raise US DMARC enforcement from 38.4% to 60.4% with no new deployments

What this US DMARC report measures

DMARC (Domain-based Message Authentication, Reporting and Conformance) is the email authentication protocol that tells receiving mail servers what to do with messages failing SPF and DKIM (Sender Policy Framework and DomainKeys Identified Mail) checks. DMARC has three policy levels. p=none monitors and takes no action. p=quarantine routes suspicious mail to spam. p=reject blocks it outright. Only p=reject is considered full DMARC enforcement.

Between March and June 2026, Red Sift measured the DMARC policy of the top 100 organizations in 49 US states and the District of Columbia. That is 5,000 domains across 50 jurisdictions, grouped into seven regions, using consistent sample sizes and methodology throughout.

New York is the one state not included in the 50 jurisdictions. Red Sift measured it earlier as a city-level study of New York City's top 100 organizations rather than a state-level sample. Because the large majority of New York State's biggest companies are headquartered in New York City, that sample is a close proxy for what a state-level study would capture, and it is reported throughout this report as a benchmark. It is excluded from national totals so that every figure in the US total rests on identical sampling rules.

This report combines all seven regional datasets into a single national picture of US DMARC adoption.

US DMARC adoption by policy level

DMARC policy

Domains

Share of US sample

Effect

p=reject

1,919

38.4%

Blocks spoofed email

p=quarantine

1,101

22.0%

Routes spoofed email to spam

p=none

1,454

29.1%

Reports spoofing, blocks nothing

No DMARC record

526

10.5%

No authentication policy published

Total

5,000

100%

Three figures carry the finding.

  • 89.5% of top US organizations have published a DMARC record. Awareness is not the problem. Almost every large organization in the country has started.
  • 57.1% of US organizations that have published a DMARC record still do not block spoofed email. They completed the DNS work, they receive the aggregate reports, and they stopped before the policy change that protects them. That is 2,555 organizations nationally.
  • 60.4% of US domains have already configured authentication. Combine p=reject and p=quarantine and you get 3,020 domains that have identified their senders and configured SPF and DKIM. Moving from quarantine to reject typically takes 6 to 8 weeks. If every US quarantine domain finished, national DMARC enforcement would reach 60.4% without a single new project starting anywhere.

US DMARC enforcement by region

Rank

Region

Domains

Reject

Quarantine

None

No record

1

Mid-Atlantic

700

44.1%

19.4%

27.3%

9.1%

2

North Central

1,000

41.2%

21.0%

28.3%

9.5%

3

Southwest

500

40.2%

22.8%

27.6%

9.4%

4

Southeast

600

39.3%

24.2%

26.2%

10.3%

5

Heartland

900

36.4%

22.4%

31.9%

9.2%

6

Northeast

700

35.0%

22.6%

30.9%

11.6%

7

Northwest

600

31.3%

22.7%

30.3%

15.7%

US total

5,000

38.4%

22.0%

29.1%

10.5%

Note: Washington D.C.'s 100 domains are included in the Mid-Atlantic and US totals above. New York City was measured separately and is excluded from all totals. Both cities are compared directly further down.

The spread between the strongest and weakest US region is 12.8 points. That narrowness makes the finding harder to dismiss rather than easier. No region of the United States is well protected. The Mid-Atlantic, which contains the federal government and the country's second-largest banking center, still leaves 56% of its top organizations unable to block email claiming to come from them.

DMARC adoption by state, ranked

Rank

State

Reject

Quarantine

None

No record

Region

1

North Carolina

55%

20%

21%

4%

Mid-Atlantic

2

California

53%

20%

27%

0%

Southwest

3

Iowa

49%

21%

24%

6%

North Central

4

Michigan

48%

21%

24%

7%

North Central

5

Pennsylvania

48%

23%

27%

2%

Mid-Atlantic

6

Ohio

47%

26%

23%

4%

North Central

7

Minnesota

46%

18%

28%

8%

North Central

8

Nebraska

46%

22%

24%

8%

Heartland

9

New Jersey

46%

19%

26%

9%

Northeast

10

Arizona

45%

20%

32%

3%

Southwest

11

Georgia

45%

20%

28%

7%

Southeast

12

Illinois

45%

27%

23%

5%

North Central

13

Tennessee

45%

20%

26%

9%

Southeast

14

Texas

45%

18%

34%

3%

Heartland

15

Virginia

45%

16%

37%

2%

Mid-Atlantic

16

Wisconsin

45%

19%

31%

5%

North Central

17

Washington

44%

23%

28%

5%

Northwest

18

Kansas

42%

25%

28%

5%

Heartland

19

Kentucky

42%

21%

29%

8%

North Central

20

Massachusetts

42%

26%

28%

4%

Northeast

21

Connecticut

40%

26%

27%

7%

Northeast

22

Delaware

40%

18%

19%

23%

Mid-Atlantic

23

Florida

40%

32%

19%

9%

Southeast

24

Missouri

40%

20%

34%

6%

Heartland

25

Nevada

39%

25%

24%

12%

Southwest

26

Indiana

37%

26%

33%

4%

North Central

27

Oklahoma

37%

23%

34%

6%

Heartland

28

Alabama

36%

26%

29%

9%

Southeast

29

Oregon

36%

26%

34%

4%

Northwest

30

Mississippi

35%

22%

26%

17%

Southeast

31

South Carolina

35%

25%

29%

11%

Southeast

32

Utah

35%

33%

18%

14%

Southwest

33

West Virginia

34%

17%

25%

24%

Mid-Atlantic

34

Colorado

33%

21%

39%

7%

Heartland

35

Louisiana

32%

30%

23%

15%

Heartland

36

Rhode Island

31%

24%

31%

14%

Northeast

37

Maryland

30%

22%

41%

7%

Mid-Atlantic

38

Maine

30%

18%

37%

15%

Northeast

39

New Hampshire

30%

21%

33%

16%

Northeast

40

Hawaii

29%

16%

37%

18%

Southwest

41

Idaho

29%

19%

33%

19%

Northwest

42

Alaska

28%

31%

28%

13%

Northwest

43

Arkansas

28%

22%

37%

13%

Heartland

44

North Dakota

27%

14%

38%

21%

North Central

45

South Dakota

26%

17%

30%

27%

North Central

46

Vermont

26%

24%

34%

16%

Northeast

47

Wyoming

26%

17%

27%

30%

Northwest

48

Montana

25%

20%

32%

23%

Northwest

49

New Mexico

25%

21%

34%

20%

Heartland

The ranking covers the 49 US states measured at state level. Washington D.C. and New York City are held out because both were measured as city-level studies, and comparing a city sample against a state sample flatters the city. Both are compared against each other in the next section, where 57% and 73% would otherwise rank first and second.

Check your own domain

Use Red Sift Investigate to see your DMARC, SPF, and DKIM configuration in 30 seconds, using your real business email.

Run a free check

New York City against Washington D.C.

Red Sift measured two US cities directly, the country's commercial capital and its political one. Both are dense, heavily regulated, and full of organizations that would be obvious impersonation targets. They are the only two places in this research where a majority of top organizations block spoofed email, and they are 16 points apart.

Metric

New York City

Washington D.C.

p=reject

73%

57%

p=quarantine

15%

20%

p=none

12%

21%

No DMARC record

1%

2%

New York City is the strongest result Red Sift has recorded anywhere in the United States. 73 of its 100 largest organizations block spoofed email, and a single domain has no DMARC record at all. Washington D.C. is second at 57%, which beats every state in the ranking but leaves 43 of its top organizations unable to stop an email claiming to come from them.

The gap is worth sitting with, because the expectation runs the other way. Federal agencies have operated under a CISA binding operational directive requiring DMARC at p=reject since 2017, which is longer and more explicit than any obligation facing a New York bank. Yet the city with a mandate trails the city with a market.

Sample composition explains part of it. Washington D.C.'s top organizations are not only federal agencies. The sample spans lobbying firms, think tanks, trade associations, membership bodies, and nonprofits, none of which fall under federal directives. New York City's spans financial services, insurance, media, real estate, and professional services, where NYDFS cybersecurity rules, PCI DSS obligations, and customer and counterparty due diligence all push the same way. Red Sift did not segment either sample by organization type, so this is a reading of the data rather than a measured finding, and it is the obvious next study to run.

The practical point stands either way. New York City proves that a majority of large organizations reaching enforcement is achievable, in the same threat environment and under the same mailbox provider rules as the 25% states. Nothing about the bottom of the table is inevitable.

Three patterns hold across the whole dataset

DMARC enforcement tracks commercial and regulatory density

New York City's 73% and Washington D.C.'s 57% are the two highest rates in the research, and both are dense, heavily regulated urban centers. The top of the state ranking follows the same logic, with banking North Carolina, technology California, and insurance and agriculture Iowa. The bottom is Montana, New Mexico, Wyoming, and South Dakota. States where regulators, auditors, payment networks, and large corporate security teams concentrate move faster on DMARC. States whose largest employers are energy producers, agricultural cooperatives, and regional healthcare systems move slower, and they move slower even when they host infrastructure of obvious national importance.

The last mile is where US organizations stall

2,555 US organizations have a DMARC record that does not block spoofed email. Maryland has 41 of its top 100 domains at p=none, the highest count in the country, in a state hosting the NSA, US Cyber Command, and the NIH. Colorado has 39 and hosts NORAD and US Space Command. Virginia has 37 alongside the densest cluster of defense contractors in the United States. Each of these organizations receives DMARC aggregate reports showing impersonation attempts in near real time. The data arrives. Nobody acts on it.

Two failure modes need two different fixes

Coastal and commercial states publish records almost universally and stall at policy. California has a 0% no-record rate and still leaves 47% of its top organizations unprotected. Oregon has a 4% no-record rate and 60 of its top 100 domains parked at none or quarantine.

Interior and rural states fail earlier. Wyoming carries a 30% no-record rate, South Dakota 27%, West Virginia 24%, and Montana 23%. Fourteen states hold 284 of the country's 526 no-record domains, more than half the national total from just over a quarter of the sample. One group needs to finish a project. The other needs to start one.

Which US sectors carry the most email security exposure

The seven regional studies surfaced the same industries repeatedly. Combined, they map a national risk picture that follows the money rather than the state line.

Defense and national security

This is the most uncomfortable finding in the series. Four of the five lowest-scoring US jurisdictions host strategic military or national laboratory infrastructure. Montana (25%) and Wyoming (26%) operate two of the three US land-based Minuteman III nuclear missile wings. New Mexico (25%) hosts Sandia National Laboratories and Los Alamos National Laboratory. South Dakota (26%) hosts Ellsworth Air Force Base. Add North Dakota's Minot Air Force Base at 27%, Hawaii's US Indo-Pacific Command at 29%, and Alaska's Ground-based Midcourse Defense system at 28%, and the pattern is clear. Defense contractors and research partners in these states send procurement, logistics, and program email daily. A spoofed domain in that supply chain is a national security exposure, and CMMC and NIST frameworks already recommend DMARC as a baseline control.

Energy and natural resources

Texas, Oklahoma, Louisiana, Colorado, New Mexico, Wyoming, North Dakota, and Alaska produce the majority of US oil, gas, coal, and renewables. Royalty payments, drilling contracts, pipeline right-of-way agreements, and joint venture settlements all move by email in six and seven-figure amounts. The FBI's IC3 logged $3.04 billion in business email compromise losses in 2025, with 86% of that money moving by wire transfer or ACH. Of those eight energy states, only Texas and Oklahoma clear 35% DMARC enforcement.

Manufacturing and automotive

Michigan (48%), Ohio (47%), Illinois (45%), Tennessee (45%), Wisconsin (45%), Kentucky (42%), Indiana (37%), Alabama (36%), and South Carolina (35%) form a manufacturing belt running from the Great Lakes to the Gulf. Just-in-time supply chains mean a single plant draws on hundreds of vendors, and purchase orders, tooling contracts, and delivery confirmations all travel by email. A spoofed Tier 1 supplier domain can redirect a large payment or halt a production line before anyone notices.

Financial services, insurance, and payments

North Carolina (55%) holds the second-largest US banking center. Illinois (45%) holds CME Group and CBOE. Iowa (49%) and Nebraska (46%) anchor major insurance clusters. Georgia (45%) processes a large share of US card payments through the fintech cluster known as Transaction Alley. This sector performs best in the study, which is what regulatory pressure looks like in data, and it still leaves roughly half its top organizations short of enforcement. South Dakota is the outlier that proves the point, sitting at 26% despite a credit card processing cluster in Sioux Falls.

Healthcare, biotech, and higher education

Massachusetts (42%), Pennsylvania (48%), Tennessee (45%), Minnesota (46%), and Maryland (30%) concentrate hospital systems, medical device manufacturers, research institutions, and the densest university cluster in the country. Patient data, clinical trial coordination, insurance claims, and referral networks all run on email. A spoofed hospital or .edu domain can compromise protected health information, trigger HIPAA exposure, and harvest credentials from large rotating user populations.

Logistics, ports, and agriculture

Tennessee holds FedEx's global hub, Georgia holds UPS and the Port of Savannah, and Kentucky holds UPS Worldport. Washington, Louisiana, South Carolina, and Florida hold major ports. Iowa, Kansas, Nebraska, Arkansas, and the Dakotas anchor grain, dairy, and livestock supply chains. Freight booking, customs documentation, commodity contracts, and carrier invoicing are email-driven processes involving large sums and tight timelines, which is exactly the profile attackers look for.

The enforcement deadline already passed

Google and Yahoo began requiring DMARC for bulk senders in February 2024. Microsoft followed in May 2025 for high-volume senders to Outlook, Hotmail, and Live.com addresses. Non-compliant messages are now rejected outright rather than filtered.

That changes what the 526 no-record US domains are risking. They are not only exposed to impersonation, they are increasingly unable to reach their own customers. The 1,454 domains at p=none face the same pressure as enforcement tightens across every major mailbox provider.

Compliance is moving the same way. PCI DSS 4.0.1 mandates DMARC for organizations handling payment card data. NIS2 applies to any US firm with EU operations or clients. NERC CIP standards increasingly touch email authentication for bulk power system operators. Cyber insurers are tightening terms, and some now exclude BEC payouts where basic email authentication is absent. The 61.6% of top US organizations without DMARC enforcement are not exempt from these requirements. They have not acted on them yet.

Frequently asked questions about US DMARC adoption

Closing the gap

Across seven regions and 5,000 US domains, the organizations that never reach p=reject rarely lack intent. They lack sender visibility, time, and a way to keep authentication intact as infrastructure changes. That is what Red Sift OnDMARC automates, compressing a rollout that routinely runs past seven months into a few weeks, keeping SPF valid past its ten-lookup limit with Dynamic SPF, and turning raw report XML into a live view of every service sending as your domain.

The United States sits at 38.4% DMARC enforcement. New York City at 73%, Washington D.C. at 57%, and North Carolina at 55% show what is achievable inside the same threat environment and the same regulatory system as everyone else. For the 3,081 US organizations that have not reached full enforcement, the distance between a published DMARC record and a protected domain is a short project rather than a new one.

Start by finding out where your own domain sits.

See your domain's DMARC status in 30 seconds

Run a free check with Red Sift Investigate

Methodology

Red Sift analyzed the published DMARC record of 100 domains belonging to the largest organizations by revenue and headcount in each of 49 US states and the District of Columbia, 50 jurisdictions and 5,000 domains in total, across seven regional studies published between March and June 2026.

Each domain was classified by its DMARC policy at time of measurement into one of four states, p=reject, p=quarantine, p=none, or no record found. Sample sizes and methodology are consistent across all seven studies. The state ranking lists the 49 states measured at state level. Washington D.C.'s 100 domains are included in the Mid-Atlantic and US totals but excluded from the state ranking, because D.C. is not a state. New York State was not sampled at state level. New York City was analyzed separately as a city-level study of 100 domains and is excluded from all regional and national totals. Regional and national figures in this report reconcile to the totals published in each original regional study.

Jack Lilley
Jack Lilley
Sr. Comms & Content Marketing Manager

Jack leads content, PR, GEO, and email security research at Red Sift.

What percentage of US companies have DMARC?

89.5% of the largest US organizations have published a DMARC record, according to Red Sift's 2026 analysis of 5,000 domains across 49 states and the District of Columbia. Only 38.4% have reached full enforcement at p=reject.

Which US state has the highest DMARC adoption?

North Carolina leads the 49 ranked US states at 55% DMARC enforcement, followed by California at 53% and Iowa at 49%. Two cities score higher, New York City at 73% and Washington D.C. at 57%, both measured as separate city-level studies.

Which US state has the lowest DMARC adoption?

Montana and New Mexico tie at 25% DMARC enforcement. Wyoming has the highest no-record rate in the country at 30%, followed by South Dakota at 27%.

Which states does this US DMARC report cover?

The dataset covers 49 US states and the District of Columbia at 100 domains each, 5,000 domains in total. The state ranking lists the 49 states only. Washington D.C. and New York City are compared separately as city-level studies, and New York is the one state with no state-level sample.

What is the difference between p=none, p=quarantine, and p=reject?

p=none monitors email authentication failures and takes no action. p=quarantine routes failing messages to the spam folder. p=reject blocks them entirely. Only p=reject prevents a spoofed email from reaching a recipient, which is why it is treated as full DMARC enforcement.

How long does it take to move from p=quarantine to p=reject?

Moving from quarantine to reject typically takes 6 to 8 weeks. The time is spent confirming that every legitimate sender authenticates correctly before the blocking policy is applied.

Why do organizations stop at p=none?

p=none produces DMARC aggregate reports as dense XML that most teams lack the time to interpret. Without a clear view of which services send legitimately on their behalf, organizations hesitate to move to a blocking policy in case they block their own mail.