Skip to content

DMARC in Ireland: where the biggest companies stand

Red Sift checked DMARC across 200 of Ireland's biggest companies. Multinationals sit at 63% enforcement and Irish-founded firms at 39.6%. See the full data.

Jack Lilley·Sr. Comms & Content Marketing Manager
Published: July 22, 2026·7 min read

Red Sift analysed the DMARC records of 201 of Ireland's largest companies, in two groups: 100 multinationals that run major operations in Ireland, and 101 companies founded in Ireland. This is a snapshot of where each group stands on the control that decides whether a spoofed email carrying your domain reaches its target or gets stopped.

DMARC (Domain-based Message Authentication, Reporting and Conformance) is the protocol that decides what happens to an email that fails authentication checks on your domain. Set it to enforce, and a spoofed message claiming to come from your company gets blocked or sent to spam before it reaches the recipient. Leave it off, or set it to monitor only, and anyone can put your domain in the From field, and your customers have no technical reason to doubt it.

This study sits alongside the same analysis Red Sift has run in other European markets, including the UK's FTSE 250 at 60.8% enforcement and Germany's top 250 at 44.8%. Across every market we've measured, DMARC adoption is real and rising, and in most of them the work is well underway rather than finished.

Key takeaways

  • 63 of 100 multinationals operating in Ireland (63%) enforce DMARC at p=reject, the policy that blocks spoofed email outright
  • 40 of 101 Irish-founded companies (39.6%) enforce at p=reject, and another 34 (33.7%) sit at p=quarantine, one step short of full enforcement
  • 74 of 101 Irish-founded companies (73.3%) already have an active DMARC deployment running at quarantine or reject
  • An estimated 4,500 to 6,000 Irish entities come into scope as Ireland finishes transposing NIS2, expected by the end of 2026, and most companies in this study are on that list
  • Invoice redirection and CEO impersonation, both built on email spoofing, are the top fraud threats to Irish businesses, which makes DMARC a direct control against the way Irish companies are actually being attacked

The multinationals operating in Ireland

Among the 100 multinationals with major operations in Ireland, 63 enforce DMARC at p=reject. Here's the full breakdown.

Multinationals operating in Ireland

Policy

Companies

p=reject (enforced)

63 (63.0%)

p=quarantine

20 (20.0%)

p=none (monitor only)

13 (13.0%)

No DMARC record

4 (4.0%)

DMARC policy across 100 multinationals operating in Ireland

The strength of this group reflects what these companies are: global operations with dedicated security teams and reporting lines that reach the board. Many were already pushed to enforcement by Google and Yahoo's 2024 bulk-sender requirements, by SEC disclosure rules, or by their own customers' security reviews. By the time a global technology or pharmaceutical company opens a Dublin office, DMARC is usually already at p=reject on the parent domain. Email authentication is a global control, and these companies brought a finished version of it with them.

Ireland's home-grown companies

Among the 101 companies founded in Ireland, 40 enforce DMARC at p=reject, and a further 34 sit at p=quarantine. Here's the full breakdown.

Companies founded in Ireland

Policy

Companies

p=reject (enforced)

40 (39.6%)

p=quarantine

34 (33.7%)

p=none (monitor only)

17 (16.8%)

No DMARC record

10 (9.9%)

DMARC policy across 101 Irish-founded companies

The headline enforcement figure understates how much of the work is already done. Add the 40 companies at reject to the 34 at quarantine, and 74 of the 101 Irish-founded companies (73.3%) have a live DMARC deployment. These are the sectors the Irish economy was built on, from banking and building materials to food and agriculture, aviation, and gambling, and the great majority of them have already published a record, worked through their legitimate senders, and moved past monitor-only.

That leaves a clear, finishable picture. 34 companies are one policy change away from full protection, and 27 have room to begin. The direction of travel is the right one, and the last steps are the most straightforward.

The step from quarantine to enforcement

The 34 Irish-founded companies sitting at p=quarantine have done the hard part. A quarantine policy sends suspicious mail to spam rather than blocking it, so it already offers real protection, and reaching it means a company has published a record, authenticated its senders, and moved deliberately past monitoring. The remaining step, moving to p=reject, is usually a matter of confirming the reporting data is clean and turning the policy up.

Most companies at quarantine can reach full enforcement in weeks once someone owns the decision to complete it. For the 27 companies at p=none or with no record, the path is the standard one: publish a record, read the reporting data to find every legitimate sender, authenticate those senders, then tighten the policy in stages until p=reject is safe to switch on.

Why this matters now: NIS2 and the fraud numbers

Two things make this the year for Irish companies to move DMARC to the top of the list.

The first is regulation. Ireland missed the EU's October 2024 deadline to transpose the NIS2 Directive, and the delay has since escalated. The European Commission sent a letter of formal notice in November 2024, a reasoned opinion in May 2025, and in July 2026 referred Ireland to the Court of Justice of the EU, asking the court to impose financial penalties until transposition is complete.

The National Cyber Security Bill, Ireland's vehicle for NIS2, is still being drafted. The government expects to publish it in autumn 2026, begin its passage through the Oireachtas after that, and notify Brussels of transposition by the end of the year. When it lands, it widens the number of in-scope entities from a few hundred under the old rules to an estimated 4,500 to 6,000, with the National Cyber Security Centre as lead competent authority and personal liability for senior managers who fail to oversee cyber risk. Most of the companies in this study will be in scope, and DMARC is a basic, documentable control that maps directly to the risk-management obligations NIS2 introduces.

The second is fraud that's already happening. Invoice redirection and CEO impersonation are the top scams targeting Irish businesses, and both start with an email that looks like it came from a trusted party. FraudSMART, the awareness initiative run by Banking & Payments Federation Ireland, reported that Irish SMEs lost more than €17.4 million to email-related scams over two years, with invoice-redirection losses of €15.7 million between January 2023 and December 2024 and average losses of €11,500 per business. Research from ISME and BPFI found 68% of Irish SMEs had been targeted by scams in a single year.

Those figures cover smaller businesses, but the mechanism runs straight through the companies in this study. When a large Irish company enforces DMARC, it takes its own name out of the attacker's toolkit, protecting its customers, its suppliers, and the smaller firms in its supply chain from mail that spoofs its domain.

Reaching enforcement

The companies that stall on DMARC tend to be doing it by hand, chasing DNS changes and reading raw reports across dozens of sending services. The ones that finish treat the rollout as a managed process with the report data driving each decision. Red Sift OnDMARC automates that process, taking a domain from monitoring to enforcement in weeks by classifying senders automatically and showing exactly what each policy change will affect before you make it.

For Ireland's biggest companies, home-grown and international alike, the destination is the same: a domain that can't be used to impersonate them.

Not sure where your company stands? Run a free DMARC check using your real company email and gain clear insights into your current DMARC policy, MTA-STS, BIMI and more.

Run a free DMARC check
Jack Lilley
Jack Lilley
Sr. Comms & Content Marketing Manager

Jack leads content, PR, GEO, and email security research at Red Sift.