DMARC World Map

Latest snapshot of SPF/DMARC coverage by hosting country.

What is this map?

Think of DMARC as a “bouncer” for your inbox: it validates the legitimacy of the “From” address to ensure the email is genuinely from who it claims to be. Every time you receive an email, your mail server has to decide whether it is really from who it says. SPF and DMARC are two small settings that a domain owner (like yourbank.com) adds to their domain so mail servers around the world can verify that messages are genuine and reject impersonators. Without them, scammers can more easily forge the “From” address in phishing emails.

This map shows, for each country, how many websites hosted there actually use these protections, giving you a snapshot of the global state of email security. Greener countries are better protected; while orange and red ones are more exposed.

-
-
-
-
-
-

Map view

Why this matters

Email is still the front door to almost every business and government service in the world. SPF and DMARC are the locks on that door. The picture on this map shows that, across the top 1 million most-visited domains, most of those locks are either missing or never engaged, on websites that millions of people trust every day.

Roughly 9 in 10 of the world's most-visited domains can still be impersonated. They publish no DMARC policy, or they publish one that only monitors without blocking. A well-crafted phishing email pretending to be from those brands will, in most cases, still land in the inbox.

More than half publish no DMARC record at all. If someone is impersonating these domains right now, sending fake invoices, fake HR notices, fake delivery confirmations, the real owner has no way to see it happening. No reports, no alerts, no trace.

The risk is not theoretical. Spoofed email is the starting point for invoice fraud, credential phishing, payroll redirection, and most ransomware campaigns. When a customer or supplier acts on a fake message wearing your logo, the financial and reputational loss falls on your brand, not on the attacker.

The good news: this is one of the most fixable problems in cybersecurity. A properly configured SPF, DKIM, and enforced DMARC policy can usually be deployed in a few hours, without disrupting legitimate mail, when it is done carefully.

~89% of top domains can be impersonated
~57% can be impersonated without the owner ever knowing

Check your own domain

Enter any domain name to see its SPF and DMARC status right now.

How we measure this

SPF coverage (metric)

The percentage of scanned domains that publish an SPF record. SPF helps mail servers confirm which systems are allowed to send email for a domain, reducing spoofing.

DMARC coverage (metric)

The percentage of scanned domains that publish a DMARC policy. DMARC tells receiving mail servers how to handle suspicious mail and provides reporting for domain owners.

Methodology & limitations

  • Domain list source: Tranco (top domains in this snapshot).
  • SPF/DMARC data gathered via DNS lookups.
  • Registrant country (RDAP) is a best-effort field and not always available.
  • Hosting country derived from IPinfo geolocation (best-effort).
  • Rate limits and network timeouts can reduce coverage in some regions.
  • About ~14% of scanned domains are not placed on the map because their hosting IP is unrouted, returned a 403 from IPinfo (typically Cloudflare or CloudFront anycast edge IPs), or had no A/AAAA record. Those domains still contribute to the global KPIs but not to per-country shading.

Hosting provider data

Each domain's hosting provider is derived from the ASN (Autonomous System Number) stored in the IPinfo Lite response. Domains are grouped into one of these buckets: Cloudflare, Amazon, Google, Microsoft, Akamai, Fastly, OVH, Hetzner, DigitalOcean, Alibaba, Other, Unknown. "Other" covers all providers not in the top-10 list. "Unknown" means no hosting data was available for that domain.