How the benchmark is built, and scored.
Every figure in the DMARCER benchmark comes from live DNS measurement, never from surveys or self-reporting. Here is exactly how we collect the data, how we turn it into a score, and how we group it so you can compare like for like.
Measured, not self-reported
Of domains in the corpus
Regions scanning worldwide
What we measure
For every domain in the corpus we read the same public DNS records a receiving mail server reads when it decides whether to trust a message. Nothing is scraped from a website and nothing is asked of the domain owner. If a record is published, we see exactly what the rest of the internet sees.
Each scan captures the full email-authentication picture:
- SPF (which servers may send for the domain, and how strictly)
- DKIM (whether messages are cryptographically signed)
- DMARC (the policy: monitor, quarantine or reject, plus reporting)
- MTA-STS and TLS-RPT (enforced encryption in transit)
- BIMI (verified brand logo, with or without a VMC)
- DNSSEC, DANE and CAA (DNS and certificate integrity)
- MX (where the domain receives mail, and whether it receives at all)
How we turn it into a score
Each signal earns points toward a single score from 0 to 100. The weighting reflects real-world impact: the controls that actually stop spoofing and interception, such as a DMARC policy at reject and enforced transport encryption, carry the most weight, while supporting signals add polish on top.
The score rolls up into a clear band from A to F, so a domain owner can see where they stand at a glance and where the next gain comes from. The weighting model is versioned, so every historical score stays comparable even as the model is refined.
How we group it for comparison
A raw score only means something in context, so we group domains by industry and by country. That lets you answer the question that matters: how does my email security compare to the organisations I am measured against, rather than to the internet as a whole.
Every published figure is an aggregate across the group. We report on the group, never on any individual domain, so the benchmark stays a fair, anonymised picture of a sector.
How current it is
The corpus is rescanned continuously rather than in one annual sweep, so the benchmark tracks how a sector is actually improving over time. When a domain publishes a stronger DMARC policy or turns on enforced encryption, that progress flows into the numbers on the next cycle.
That continuous measurement is also what powers the guidance in the product: the same signals that build the benchmark are the ones DMARCER walks each customer domain through, from first scan to a policy at reject.
See where your sector stands
Check any domain against the benchmark in seconds, with the same live DNS measurement behind every figure on this page.
Explore the benchmarks