State of Domain Security 2026
A detailed analysis of domain security across the internet. Covering protocol adoption rates, common misconfigurations, industry gaps, and compliance readiness.
Published March 2026 | Based on analysis of domain security data and publicly available industry research
1. Executive Summary
Domain security in 2026 remains a study in contrasts. While email authentication adoption has reached meaningful levels — with 82% of top domains publishing SPF records and 58% publishing DMARC — the gap between publishing a record and enforcing it properly remains the dominant vulnerability.
Only 22% of domains with DMARC records enforce a policy of p=reject, meaning the vast majority of DMARC deployments are in monitoring-only mode. This leaves organizations technically compliant but practically unprotected against domain spoofing.
Meanwhile, newer protocols like DNSSEC (14%), MTA-STS (4%), and BIMI (2%) remain at early-adoption levels. Post-quantum cryptography readiness is effectively zero in production, though awareness is rising rapidly following NIST's finalization of ML-KEM (FIPS 203) and ML-DSA (FIPS 204) in 2024.
The enterprise-SMB gap continues to widen. Enterprise domains average an estimated TrustScore of ~580 compared to ~340 for SMBs, driven by dedicated security teams and compliance mandates that smaller organizations lack.
2. Key Findings
3. Protocol Adoption Rates
Estimated adoption rates across the top 1 million domains, based on publicly available research and industry reports. "Correct Config" indicates records that are both present and properly configured.
| Protocol | Adoption | Correct Config | Trend |
|---|---|---|---|
| SPF | 82% | 70% | Stable |
| DKIM | 68% | 61% | Rising |
| DMARC | 58% | 22% | Rising |
| DNSSEC | 14% | 11% | Rising |
| MTA-STS | 4% | 3% | Rising |
| BIMI | 2% | 1.5% | Rising |
| DANE / TLSA | 3% | 2% | Stable |
| TLS-RPT | 8% | 6% | Rising |
Sources: Industry estimates based on publicly available research from DMARC.org, Google Transparency Report, Cloudflare Radar, and APNIC DNSSEC measurement data. Figures are approximate.
4. Common Misconfigurations
The top 5 domain security misconfigurations observed across analyzed domains, ranked by prevalence and impact.
DMARC p=none without enforcement path
SPF exceeding 10 DNS lookup limit
Expired or soon-expiring SSL certificates
Missing security headers (HSTS, CSP)
DKIM key length under 2048 bits
5. Enterprise vs SMB
The security gap between enterprise and small/medium businesses continues to grow. Enterprise organizations benefit from dedicated security teams and compliance mandates, while SMBs often lack the resources and expertise to implement thorough domain security.
| Metric | Enterprise | SMB | Gap |
|---|---|---|---|
| DMARC p=reject | 41% | 12% | 29 points |
| DNSSEC enabled | 22% | 8% | 14 points |
| HSTS deployed | 56% | 28% | 28 points |
| Certificate auto-renewal | 78% | 52% | 26 points |
| MTA-STS policy | 8% | 1% | 7 points |
| Average TrustScore (est.) | ~580 | ~340 | 240 points |
Estimates based on industry reports and aggregated domain security analysis. Enterprise defined as Fortune 5000+ companies. SMB defined as organizations with fewer than 500 employees.
6. Compliance Readiness
Estimated percentage of domains meeting key compliance framework requirements for domain security. These are approximations based on protocol adoption data mapped to framework-specific requirements.
7. Recommendations
Enforce DMARC (p=reject)
If you have DMARC p=none, begin your enforcement journey. Monitor aggregate reports for 30-60 days, identify all legitimate sending sources, then move to p=quarantine and finally p=reject. This single change eliminates domain spoofing risk.
Fix SPF lookup limits
Audit your SPF record for DNS lookup count. If you exceed 10 lookups, consolidate includes, remove unused services, and consider SPF flattening. A broken SPF record is worse than no SPF record.
Deploy HSTS and security headers
Add Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, and X-Frame-Options headers. These take minutes to deploy and protect against protocol downgrade, clickjacking, and content injection attacks.
Enable DNSSEC
DNSSEC prevents DNS cache poisoning and response manipulation. Most major registrars now support DNSSEC signing with one-click activation. At 14% adoption, this remains an underutilized defense.
Rotate DKIM keys to 2048-bit minimum
If your DKIM keys are 1024-bit RSA, rotate to 2048-bit immediately. Consider Ed25519 for modern ESPs that support it. Weak DKIM keys can be brute-forced, undermining email authentication entirely.
Begin PQC readiness assessment
While production PQC deployment is premature, organizations should inventory their cryptographic dependencies and begin planning for the ML-KEM (TLS) and ML-DSA (DKIM) transition. NIST recommends starting migration planning now.
Automate certificate management
With Apple and Chrome moving toward 200-day certificate maximum validity, automated renewal is no longer optional. Use ACME (Let's Encrypt), Cloudflare, or your CA's auto-renewal to prevent expiration incidents.
Scan Your Domain Free
See where your domain stands across all 29 security categories. Get a 0-1000 TrustScore with clear fix recommendations in seconds. No credit card required.
Methodology
This report uses estimated data based on publicly available research from DMARC.org, Google Transparency Report, Cloudflare Radar, APNIC DNSSEC measurements, and industry analyst reports. All statistics are approximations and should be treated as directional indicators rather than exact measurements. TrustScore estimates are based on Vysiro's 28-category scoring methodology applied to protocol adoption data. Enterprise/SMB segmentation uses estimated organizational size data. This report will be updated as Vysiro accumulates first-party scan data at scale.