Do small businesses have SPF and DMARC set up?

53% of 2,528 scanned domains had SPF. Only 35% had DMARC. Both are one DNS record each.

Mostly not both. Across the 2,528 small-business domains in our scan corpus, 53% had an SPF record and only 35% had a DMARC record. SPF without DMARC is a policy nobody is instructed to enforce — so roughly two thirds of the small-business domains we measured have not told receiving mail servers what to do with mail that fails authentication.

Adoption in 2,528 scanned domains

The spread between groups is as wide as it is for schema markup. Travel businesses led SPF adoption at 87%; movers had the lowest DMARC adoption at 13%. Regions vary too — in the Chelsea, Manhattan cut only 25% of domains had SPF and 15% had DMARC, against 63% and 41% in the neighbouring East Village cut. Each cut's table is in the directory.

What SPF, DKIM and DMARC each do

SPF is a TXT record on the domain beginning v=spf1, listing which servers may send mail as you. DKIM is a published signing key — our scan looks for one at six common selectors, and a key at any one of them counts as present. DMARC is a TXT record at _dmarc. on the domain beginning v=DMARC1, telling receivers what to do when the first two fail. All three are public DNS records; checking them sends no mail and touches no server of yours.

Why a website scan checks your email at all

Because the domain is the business. A domain without authentication records can be spoofed in mail that looks like it came from you, and that costs trust with the same customers a website exists to win. The checks are also free to run honestly: DNS is public, so our scan resolves the records without sending anything. The free scan reports all three for your domain, and treats a missing DKIM key at the six common selectors as exactly that — no key there, not proof you have none.

Straight answers

Is SPF without DMARC worth much?

Less than most owners assume. SPF says who may send as you; DMARC is the record that tells receiving servers what to do when a message fails. In our corpus 53% of domains had SPF but only 35% had DMARC, so most of the SPF that exists is a policy nobody has been told to enforce.

Does checking my records involve sending me email?

No. SPF, DKIM and DMARC live in public DNS. The scan resolves TXT records through a public resolver and never sends mail or touches your server.

Which businesses are best at this?

In our 2,528-domain corpus, travel businesses led SPF adoption at 87%. The weakest DMARC adoption we measured was movers at 13%.

My provider set up my email — am I covered?

Sometimes for SPF and DKIM, rarely for DMARC, which usually has to be added deliberately. It is one DNS TXT record, and the scan will tell you in about a minute whether your domain has it.

Related

Where does your site stand? The scan is free, takes about 60 seconds, and needs no account. It fetches your homepage exactly the way GPTBot, ClaudeBot and PerplexityBot do and tells you what they receive.