/research · October 1, 2026

Can US stores prove their email is theirs?

Gmail, Yahoo and Outlook now require bulk senders to authenticate their mail, or it goes to spam or is refused. We read the public DNS of 360 US stores to see who is set up and who is not.

66.1%enforce DMARC (block or quarantine spoofed mail)
29.7%publish a DMARC policy that blocks nothing
91.4%meet the full bulk-sender bar (SPF, DKIM and DMARC)

DMARC policy in force

A store’s DMARC policy decides what happens to mail that forges its address.

Reject (blocks spoofed mail)37.8%
Quarantine (sends spoofed mail to spam)30%
None (watches, blocks nothing)29.7%
No DMARC record2.5%

The three records

Share of stores that receive mail and publish each protection.

SPF (one valid record)95.6%
DKIM key found96.4%
DMARC record97.5%
Brand logo in inbox (BIMI)21.4%

By platform

Share enforcing DMARC, by platform.

Shopify (238)61.3%
Other (85)80%
Salesforce Commerce Cloud (27)77.8%

A store with no enforced DMARC has two problems at once: its own receipts and campaigns are more likely to land in spam, and anyone can send mail that looks like it came from the store. Both are fixed in DNS in an afternoon, with no change to the store itself.

See automation work ›

Method. Public DNS lookups (Cloudflare and Google resolvers): SPF and BIMI TXT records, the DMARC record at _dmarc, MX, and DKIM keys under the selectors of the most common email senders. No email was sent. Aggregates only; no store or app is named. Related research: all studies.