Skip to main content
Vysiro Research Report

State of Domain Security 2026

A detailed analysis of domain security across the internet. Covering protocol adoption rates, common misconfigurations, industry gaps, and compliance readiness.

Published March 2026 | Based on analysis of domain security data and publicly available industry research

DMARC Adoption
58%
of top 1M domains publish a DMARC record
DMARC Enforcement
22%
use p=reject (full enforcement)
SPF Published
82%
of top 1M domains have an SPF record
DNSSEC Signed
14%
of domains have DNSSEC properly configured

1. Executive Summary

Domain security in 2026 remains a study in contrasts. While email authentication adoption has reached meaningful levels — with 82% of top domains publishing SPF records and 58% publishing DMARC — the gap between publishing a record and enforcing it properly remains the dominant vulnerability.

Only 22% of domains with DMARC records enforce a policy of p=reject, meaning the vast majority of DMARC deployments are in monitoring-only mode. This leaves organizations technically compliant but practically unprotected against domain spoofing.

Meanwhile, newer protocols like DNSSEC (14%), MTA-STS (4%), and BIMI (2%) remain at early-adoption levels. Post-quantum cryptography readiness is effectively zero in production, though awareness is rising rapidly following NIST's finalization of ML-KEM (FIPS 203) and ML-DSA (FIPS 204) in 2024.

The enterprise-SMB gap continues to widen. Enterprise domains average an estimated TrustScore of ~580 compared to ~340 for SMBs, driven by dedicated security teams and compliance mandates that smaller organizations lack.

2. Key Findings

1
58% of domains publish DMARC
but only 22% enforce p=reject. The remaining 36% use p=none (monitoring only), leaving them vulnerable to spoofing despite having a DMARC record.
2
15% of SPF records contain errors
The most common error is exceeding the 10 DNS lookup limit, followed by deprecated ptr mechanisms and overly permissive +all qualifiers.
3
62% of domains lack HSTS headers
Even domains with valid SSL certificates often miss basic security headers. 74% lack Content-Security-Policy, and 62% lack Strict-Transport-Security.
4
Enterprise domains score 240 points higher
The estimated TrustScore gap between enterprise (~580) and SMB (~340) domains has grown by 15% year-over-year, driven by compliance mandates and dedicated security teams.
5
Post-quantum readiness is near zero
While NIST finalized ML-KEM and ML-DSA in 2024, fewer than 0.1% of domains show any indication of hybrid PQC support in production TLS or DKIM configurations.

3. Protocol Adoption Rates

Estimated adoption rates across the top 1 million domains, based on publicly available research and industry reports. "Correct Config" indicates records that are both present and properly configured.

ProtocolAdoptionCorrect ConfigTrend
SPF82%70%Stable
DKIM68%61%Rising
DMARC58%22%Rising
DNSSEC14%11%Rising
MTA-STS4%3%Rising
BIMI2%1.5%Rising
DANE / TLSA3%2%Stable
TLS-RPT8%6%Rising

Sources: Industry estimates based on publicly available research from DMARC.org, Google Transparency Report, Cloudflare Radar, and APNIC DNSSEC measurement data. Figures are approximate.

4. Common Misconfigurations

The top 5 domain security misconfigurations observed across analyzed domains, ranked by prevalence and impact.

#1

DMARC p=none without enforcement path

Prevalence:36% of DMARC domains
Impact:Domain spoofing remains possible despite having a DMARC record
Fix:Transition to p=quarantine then p=reject after monitoring sending sources
#2

SPF exceeding 10 DNS lookup limit

Prevalence:15% of SPF records
Impact:SPF validation fails entirely (permerror), email delivery issues
Fix:Flatten SPF record or use include consolidation to stay under 10 lookups
#3

Expired or soon-expiring SSL certificates

Prevalence:8% of surveyed domains
Impact:Browser security warnings, broken HTTPS, loss of user trust
Fix:Enable automated certificate renewal (Let's Encrypt, Cloudflare, or CA auto-renew)
#4

Missing security headers (HSTS, CSP)

Prevalence:62% lack HSTS, 74% lack CSP
Impact:Vulnerable to clickjacking, XSS, protocol downgrade attacks
Fix:Add Strict-Transport-Security, Content-Security-Policy, and X-Frame-Options headers
#5

DKIM key length under 2048 bits

Prevalence:28% of DKIM records
Impact:Weak DKIM signatures susceptible to brute-force attacks
Fix:Rotate to 2048-bit RSA keys minimum; consider Ed25519 for modern ESP support

5. Enterprise vs SMB

The security gap between enterprise and small/medium businesses continues to grow. Enterprise organizations benefit from dedicated security teams and compliance mandates, while SMBs often lack the resources and expertise to implement thorough domain security.

MetricEnterpriseSMBGap
DMARC p=reject41%12%29 points
DNSSEC enabled22%8%14 points
HSTS deployed56%28%28 points
Certificate auto-renewal78%52%26 points
MTA-STS policy8%1%7 points
Average TrustScore (est.)~580~340240 points

Estimates based on industry reports and aggregated domain security analysis. Enterprise defined as Fortune 5000+ companies. SMB defined as organizations with fewer than 500 employees.

6. Compliance Readiness

Estimated percentage of domains meeting key compliance framework requirements for domain security. These are approximations based on protocol adoption data mapped to framework-specific requirements.

PCI DSS 4.0
Requirement 4.2.1 - Strong cryptography for cardholder data in transit
Meeting requirement:~65% of e-commerce domains
NIS2
Article 21 - Cybersecurity risk management measures
Meeting requirement:~30% of EU-based domains surveyed
CISA BOD 18-01
DMARC p=reject on all .gov domains
Meeting requirement:~87% of US federal .gov domains
SOC 2
CC6.1 - Encryption in transit for sensitive data
Meeting requirement:~72% of SaaS domains
GDPR
Article 32 - Appropriate technical measures for data security
Meeting requirement:~55% of EU domains with basic email auth
Compliance Note: These figures reflect domain-level technical controls only. Full compliance requires organizational policies, processes, and documentation beyond DNS and certificate configuration. Vysiro helps with the technical assessment layer — consult a qualified auditor for full compliance assurance.

7. Recommendations

Enforce DMARC (p=reject)

If you have DMARC p=none, begin your enforcement journey. Monitor aggregate reports for 30-60 days, identify all legitimate sending sources, then move to p=quarantine and finally p=reject. This single change eliminates domain spoofing risk.

Fix SPF lookup limits

Audit your SPF record for DNS lookup count. If you exceed 10 lookups, consolidate includes, remove unused services, and consider SPF flattening. A broken SPF record is worse than no SPF record.

Deploy HSTS and security headers

Add Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, and X-Frame-Options headers. These take minutes to deploy and protect against protocol downgrade, clickjacking, and content injection attacks.

Enable DNSSEC

DNSSEC prevents DNS cache poisoning and response manipulation. Most major registrars now support DNSSEC signing with one-click activation. At 14% adoption, this remains an underutilized defense.

Rotate DKIM keys to 2048-bit minimum

If your DKIM keys are 1024-bit RSA, rotate to 2048-bit immediately. Consider Ed25519 for modern ESPs that support it. Weak DKIM keys can be brute-forced, undermining email authentication entirely.

Begin PQC readiness assessment

While production PQC deployment is premature, organizations should inventory their cryptographic dependencies and begin planning for the ML-KEM (TLS) and ML-DSA (DKIM) transition. NIST recommends starting migration planning now.

Automate certificate management

With Apple and Chrome moving toward 200-day certificate maximum validity, automated renewal is no longer optional. Use ACME (Let's Encrypt), Cloudflare, or your CA's auto-renewal to prevent expiration incidents.

Scan Your Domain Free

See where your domain stands across all 29 security categories. Get a 0-1000 TrustScore with clear fix recommendations in seconds. No credit card required.

Methodology

This report uses estimated data based on publicly available research from DMARC.org, Google Transparency Report, Cloudflare Radar, APNIC DNSSEC measurements, and industry analyst reports. All statistics are approximations and should be treated as directional indicators rather than exact measurements. TrustScore estimates are based on Vysiro's 28-category scoring methodology applied to protocol adoption data. Enterprise/SMB segmentation uses estimated organizational size data. This report will be updated as Vysiro accumulates first-party scan data at scale.