Can US stores prove their email is theirs?
Gmail, Yahoo and Outlook now require bulk senders to authenticate their mail, or it goes to spam or is refused. We read the public DNS of 360 US stores to see who is set up and who is not.
DMARC policy in force
A store’s DMARC policy decides what happens to mail that forges its address.
| Reject (blocks spoofed mail) | 37.8% | |
| Quarantine (sends spoofed mail to spam) | 30% | |
| None (watches, blocks nothing) | 29.7% | |
| No DMARC record | 2.5% |
The three records
Share of stores that receive mail and publish each protection.
| SPF (one valid record) | 95.6% | |
| DKIM key found | 96.4% | |
| DMARC record | 97.5% | |
| Brand logo in inbox (BIMI) | 21.4% |
By platform
Share enforcing DMARC, by platform.
| Shopify (238) | 61.3% | |
| Other (85) | 80% | |
| Salesforce Commerce Cloud (27) | 77.8% |
A store with no enforced DMARC has two problems at once: its own receipts and campaigns are more likely to land in spam, and anyone can send mail that looks like it came from the store. Both are fixed in DNS in an afternoon, with no change to the store itself.
Method. Public DNS lookups (Cloudflare and Google resolvers): SPF and BIMI TXT records, the DMARC record at _dmarc, MX, and DKIM keys under the selectors of the most common email senders. No email was sent. Aggregates only; no store or app is named. Related research: all studies.