一项最新研究显示,尽管邮件认证技术DMARC自2012年发布以来已逾十年,但其采用和执行状况仍不理想[1]。在调查的67,336个域名中,45.1%完全缺失DMARC记录,而即使部署了该技术的域名中,也仅有29.7%真正执行了拒绝或隔离策略[1]。综合来看,共有46,071个域名(68.4%)要么没有配置DMARC,要么没有实施任何强制措施[1]。
研究发现,最大的单一群体占比42.5%,这些域名被设置在p=none监控模式下,停留在该阶段多年未见进展[1]。阻碍域名所有者从监控阶段向执行阶段推进的主要原因是难以准确识别所有合法的邮件发送源[1]。相比之下,更基础的SPF技术采用率要高得多,达到72.7%,而更新的MTA-STS和BIMI技术采用率均低于3%[1]。此外,DMARC的核心规范在2026年发生更新,其原有标准RFC 7489已被RFC 9989、9990、9991取代,其中RFC 9989首次获得IETF正式标准地位[1]。
A research study examining email authentication practices has revealed persistent gaps in DMARC implementation across the internet.[1] Of 67,336 domains analyzed, 45.1% lack DMARC records entirely, while among those with records in place, only 29.7% have actually enforced protective policies.[1] Collectively, 68.4% of domains either have no DMARC record or fail to enforce any protective measures.[1]
The research found that the largest single category of domains—42.5%—remain stuck at the p=none monitoring stage, which serves as a temporary setup phase but has stalled for years without progression.[1] Domain administrators cite difficulty in identifying all legitimate email sending sources as the primary barrier preventing the transition from monitoring to active enforcement.[1] In contrast, SPF adoption has achieved significantly higher penetration at 72.7%, though newer authentication standards like MTA-STS and BIMI lag far behind at below 3% adoption each.[1]
The findings coincide with DMARC's core specification undergoing revision, with RFC 7489 being superseded by RFC 9989, 9990, and 9991 in 2026, marking the first instance RFC 9989 has achieved formal IETF standards status.[1]