DMARC Adoption Among 200 SaaS Companies (October 2026 Data)
Almost every SaaS company publishes a DMARC record, but far fewer enforce one. Of 200 SaaS companies we checked on 2 October 2026, 97% had a valid DMARC record, 27.5% were still on monitoring-only p=none, and 63.5% enforced quarantine or reject on all of their mail. S&P 500 companies were markedly stricter.
The gap between those numbers is the story. DMARC that is published but not enforced tells receivers what you would like to happen and then asks them not to do it.
How we built the sample
The SaaS sample is the 200 largest SaaS companies in Y Combinator's public company directory, by listed team size. We used the open mirror of that directory at yc-oss.github.io and filtered to companies tagged "SaaS", in the B2B industry, with a status of Active or Public and a website listed. We sorted by team size and took the first 200 unique domains. The largest were Deel, Flexport, Fivetran, Podium and Flock Safety; the smallest had 24 people listed.
For comparison we used a second, very different sample: the S&P 500. We took the constituent list from Wikipedia's "List of S&P 500 companies" and the official website of each company from Wikidata, which gave 496 unique domains (duplicate domains such as Alphabet's two share classes merged, and three companies with no website recorded dropped).
For each domain we queried the TXT record at _dmarc.<domain> with dnspython against public resolvers (1.1.1.1, 8.8.8.8, 9.9.9.9). We counted only records beginning v=DMARC1 and parsed the tags as RFC 7489 describes. Measurement time: 03:38 UTC, 2 October 2026.
The headline numbers
97% of the SaaS sample publishes DMARC; 69.5% sets an enforcing policy.
| Policy | SaaS (n=200) | Share | S&P 500 (n=496) | Share |
|---|---|---|---|---|
| p=reject | 55 | 27.5% | 348 | 70.2% |
| p=quarantine | 84 | 42.0% | 96 | 19.4% |
| p=none | 55 | 27.5% | 45 | 9.1% |
| No DMARC record | 5 | 2.5% | 7 | 1.4% |
| Two DMARC records (invalid) | 1 | 0.5% | 0 | 0% |
A domain with two DMARC records is treated as having none, because RFC 7489 tells receivers to ignore the result when more than one record comes back. So the effective "no DMARC" figure for the SaaS sample is six domains, or 3%.
Two patterns jump out.
SaaS companies prefer quarantine; large companies prefer reject. Quarantine is the most common policy in the SaaS sample, at 42%. In the S&P 500, reject is the clear default, at 70.2%. Reject is the stronger signal, since a receiver is asked to refuse failing mail outright rather than file it as spam.
One in four SaaS companies is still monitoring. 27.5% of the SaaS sample sits on p=none, three times the S&P 500 rate. p=none is the right first step, because it starts the aggregate reports flowing without affecting delivery. It is not meant to be where a domain stays.
Enforcement is weaker than the policy suggests
Sixteen SaaS companies that enforce do so on only part of their mail. The pct tag scales the policy, and anything below 100 lets some failing mail through.
| Policy and pct in the SaaS sample | Companies |
|---|---|
| p=quarantine; pct=90 | 3 |
| p=reject; pct=90 | 2 |
| p=quarantine; pct=10 | 2 |
| p=quarantine; pct=1 | 1 |
| p=quarantine; pct=20 | 1 |
| p=quarantine; pct=50 | 1 |
| p=quarantine; pct=80 | 1 |
| p=reject; pct=50 | 1 |
pct is a rollout tool: you raise it in steps while watching reports. A domain sitting at pct=1 applies quarantine to one failing message in a hundred.
Counting only domains that enforce on 100% of mail, the picture is:
| Fully enforced (quarantine or reject, pct=100) | Count | Share |
|---|---|---|
| SaaS (n=200) | 127 | 63.5% |
| S&P 500 (n=496) | 440 | 88.7% |
The subdomain gap
Seventeen SaaS companies enforce on their main domain but set sp=none for subdomains. The S&P 500 had 20 such domains.
The sp tag sets the policy for subdomains. If it is none, an attacker can send as billing.yourcompany.com and receivers will be told not to act on the failure, even though yourcompany.com itself is protected. Sometimes this is deliberate while a team finds every subdomain that sends mail. Often it is a leftover.
Strict alignment is rare
Only 14 SaaS companies set adkim=s (strict DKIM alignment) and 12 set aspf=s. Relaxed alignment is the default and is fine for most organisations, so this is not a weakness, just a note that almost nobody opts into the stricter mode.
Who receives the reports
86.6% of the SaaS companies with a valid record ask for aggregate reports. 168 of the 194 single valid records include a rua address. In the S&P 500 it is 477 of 489, or 97.5%.
Where those reports go reveals which tools teams use to read them. Counting each company once per reporting provider:
| Most common rua destinations, SaaS | Companies |
|---|---|
| cloudflare.net (Cloudflare's DMARC management) | 21 |
| postmarkapp.com | 17 |
| vali.email (Valimail) | 11 |
| dmarcian.com | 10 |
| dmarcdigests.com | 9 |
| Most common rua destinations, S&P 500 | Companies |
|---|---|
| proofpoint.com | 212 |
| vali.email (Valimail) | 72 |
| dmarcian.com | 34 |
| agari.com | 21 |
| ondmarc.com | 16 |
The SaaS companies spread their reports across Cloudflare, Postmark and dedicated DMARC tools. In the S&P 500, 212 of the 496 domains send them to Proofpoint, which also handles inbound mail for 224 of the same domains. We cover that in our MX record study.
Why this matters for anyone sending email
DMARC is now a sending requirement, not just a security feature. Google's email sender guidelines require senders of 5,000 or more messages a day to Gmail to publish DMARC, and state that the policy can be set to none. So the 27.5% on p=none meet the letter of the bulk-sender rule.
What p=none does not do is protect the domain. A spoofed message claiming to come from a p=none domain is delivered on the receiver's normal judgement, and the domain owner only finds out from the reports. It also rules out BIMI: Google's BIMI setup page says the policy must be quarantine or reject with pct at 100. We counted how many brands meet that bar in a separate BIMI study.
If your domain is one of the 55 on p=none, the route forward is well established: read the aggregate reports until every legitimate source passes SPF or DKIM with alignment, then move to quarantine with a rising pct, then to reject. Our guide to moving DMARC from none to reject walks through it.
Check your own domain
The quickest check is a single DNS query:
dig +short TXT _dmarc.yourdomain.com
Then read three things in the answer:
p=: none, quarantine or reject.pct=: if present and below 100, your policy is only partly applied.sp=: if it is none whilepis enforcing, your subdomains are not covered.
If more than one v=DMARC1 line comes back, delete one; two records cancel each other out. The DMARC checker runs these checks in a browser, and the DMARC generator builds a record if you do not have one yet.
Limitations
- Two samples, neither random. The SaaS sample is weighted to larger, venture-backed companies from one accelerator. Team sizes are as listed in YC's directory and may be out of date. The S&P 500 sample is the largest US-listed companies. Smaller SaaS businesses are likely to have weaker adoption than either group.
- Website domain, not necessarily mail domain. We checked the domain of each company's listed website. A few companies send mail from a different domain, which we did not attempt to find.
- DNS only. We measured what each domain publishes, not how receivers act on it, and not whether the company's own mail actually passes.
- One snapshot, taken on 2 October 2026. DMARC records change often, especially during rollouts.
The short version
- 97% of 200 SaaS companies publish a valid DMARC record, but only 63.5% fully enforce it.
- 27.5% are on
p=none, against 9.1% of the S&P 500. - SaaS favours quarantine (42%); the S&P 500 favours reject (70.2%).
- Look for
pctbelow 100 andsp=none. Both quietly weaken a policy that looks enforced.
Raw data: download the full dataset as CSV. It is free to reuse with a link back to this page.
Common questions
What percentage of SaaS companies have DMARC?
In our October 2026 sample of 200 SaaS companies from Y Combinator's public directory, 194 (97%) published a single valid DMARC record. Publishing is not the same as enforcing, though: 55 of them (27.5%) were on p=none, which only monitors, and 127 (63.5%) enforced quarantine or reject on 100% of mail.
Is p=none enough for Gmail and Yahoo's bulk sender rules?
For the published bulk-sender requirement, yes. Google's sender guidelines say a DMARC record is required for senders of 5,000 or more messages a day and that the policy can be set to none. It does nothing to stop someone spoofing your domain, though, and BIMI logos need quarantine or reject at pct=100.
How do large companies compare with SaaS startups on DMARC?
They are stricter. Among the 496 S&P 500 domains we checked, 70.2% used p=reject and 88.7% enforced at full strength, against 27.5% and 63.5% for the SaaS sample. The SaaS companies favour quarantine (42%) where the large companies favour reject.
What does pct mean in a DMARC record?
The pct tag tells receivers what percentage of failing mail the policy applies to; the rest is treated one step more leniently. A record with p=reject; pct=10 rejects only a tenth of failing mail. Sixteen companies in our SaaS sample enforced with pct below 100, one of them at pct=1.
Verify unlimited addresses for $29.99/month
Real SMTP mailbox checks. No credits, no per-email fees.
Get Started