Why this matters
Since 2024, Gmail and Yahoo require DMARC from bulk senders, and missing authentication pushes everyone else's mail toward spam too. The bigger risk is fraud: a business without an enforced DMARC policy can't stop someone sending invoices, payment-change requests or password resets that look like they came from its own address. Those emails land with customers and suppliers, who trust them precisely because the address is real.
The website numbers matter for the same reason. An expired or untrusted certificate turns the homepage into a full-page "Your connection is not private" warning, and most visitors leave instead of clicking through.
Methodology
We drew a random sample of US business records that list a website, left out businesses with 100 or more employees, and kept one entry per domain. We excluded social media pages, website builders' shared domains and webmail providers, so every domain is one the business controls. 1,549 domains were checked successfully between their sampling and 2 October 2026.
Each domain was checked with the same code that runs our free DMARC checker and SSL checker: public DNS lookups for MX, SPF, DMARC and common DKIM selectors, then an HTTPS connection to the website to verify its certificate and the http-to-https redirect. Email figures use domains that receive email (have MX records) as the base; website figures use domains with a live website. Segments with fewer than 30 domains are not shown. No individual business is named.
You're welcome to cite these figures. Please link to this page as the source.
Frequently asked questions
What does "can be impersonated by email" mean?
The domain has no DMARC policy that tells receivers to reject or quarantine mail that fails authentication. Without one, a scammer can send email with the business's exact address in the From line and most mailboxes will still deliver it.
Where does the sample come from?
A random sample of US business records that list a website, de-duplicated by domain. Social media pages, free website builders and webmail domains were excluded so that every domain in the sample is one the business owns.
How was each domain checked?
With the same code that runs our free DMARC checker and SSL checker: public DNS lookups for MX, SPF, DMARC and common DKIM selectors, and an HTTPS connection to the website to verify its certificate and whether http:// redirects to https://. Nothing was sent to the businesses and no login or scan beyond these public lookups was made.
How can I check my own domain?
Use the free DMARC checker and SSL checker linked on this page. Both show the exact record or setting that fixes each problem.