Think of DMARC as a “bouncer” for your inbox: it
validates the legitimacy of the “From” address to ensure the email is
genuinely from who it claims to be. Every time you receive an email, your mail server
has to decide whether it is really from who it says. SPF and
DMARC are two small settings that a domain owner (like
yourbank.com) adds to their domain so mail servers around the world can
verify that messages are genuine and reject impersonators. Without them, scammers can
more easily forge the “From” address in phishing emails.
This map shows, for each country, how many websites hosted there actually use these protections, giving you a snapshot of the global state of email security. Greener countries are better protected; while orange and red ones are more exposed.
Email is still the front door to almost every business and government service in the world. SPF and DMARC are the locks on that door. The picture on this map shows that, across the top 1 million most-visited domains, most of those locks are either missing or never engaged, on websites that millions of people trust every day.
Roughly 9 in 10 of the world's most-visited domains can still be impersonated. They publish no DMARC policy, or they publish one that only monitors without blocking. A well-crafted phishing email pretending to be from those brands will, in most cases, still land in the inbox.
More than half publish no DMARC record at all. If someone is impersonating these domains right now, sending fake invoices, fake HR notices, fake delivery confirmations, the real owner has no way to see it happening. No reports, no alerts, no trace.
The risk is not theoretical. Spoofed email is the starting point for invoice fraud, credential phishing, payroll redirection, and most ransomware campaigns. When a customer or supplier acts on a fake message wearing your logo, the financial and reputational loss falls on your brand, not on the attacker.
The good news: this is one of the most fixable problems in cybersecurity. A properly configured SPF, DKIM, and enforced DMARC policy can usually be deployed in a few hours, without disrupting legitimate mail, when it is done carefully.
Enter any domain name to see its SPF and DMARC status right now.
The percentage of scanned domains that publish an SPF record. SPF helps mail servers confirm which systems are allowed to send email for a domain, reducing spoofing.
The percentage of scanned domains that publish a DMARC policy. DMARC tells receiving mail servers how to handle suspicious mail and provides reporting for domain owners.
Each domain's hosting provider is derived from the ASN (Autonomous System Number) stored in the IPinfo Lite response. Domains are grouped into one of these buckets: Cloudflare, Amazon, Google, Microsoft, Akamai, Fastly, OVH, Hetzner, DigitalOcean, Alibaba, Other, Unknown. "Other" covers all providers not in the top-10 list. "Unknown" means no hosting data was available for that domain.