DMARC Adoption in Germany 2026
Last fall, on the occasion of Germany’s Year of Email Security, we analyzed the top 250 German parent domains based on revenue as a sample of the country’s domain security and enforcement levels.
It’s been almost a year since we ran the numbers, and we’ve reviewed them again to spot any changes.
Spoiler alert: Not much has changed.
Following are the full August 2026 results from Germany’s top 250 parent domains:
- 12% have no DMARC record.
- 18% have a record at the p=none monitoring phase.
- 15% do not follow best practices or have errors, leaving domains exposed or without visibility.
- 15% have a DMARC policy of p=quarantine, the penultimate policy progression before progressing to p=reject.
- 40% are at p=reject, taking full advantage of the protection DMARC offers.
When we compare the DMARC adoption results from October 2025, we see marginal security improvements in some categories and persistent deficits in others.
While the percentages of parent domains lacking a DMARC record and those at p=quarantine enforcement remain the same, there is a 3% increase in the policy state of p=reject. We observed a 1% increase in domains that have errors or don’t follow best practices, and a 12% decrease in p=none policies, which may partially explain the modest increase in domains at full enforcement.
Common Errors with DMARC Deployment in Germany
In this year’s analysis, we discovered that 34% of this domain set had errors. Those problematic records fall into the two broad categories of DMARC and SPF—45% of the errors involve DMARC records, while 55% are connected to SPF records.
When we compared those findings to last year’s research, we found no appreciable difference. Of the 250 domains we analyzed, 32% had issues—44% of them were related to DMARC records, while 56% of the errors are SPF centric.
DMARC record issues
Of the DMARC record errors, most revolved around a missing RUA tag, which includes the email address for sending aggregate reports. A DMARC record with no RUA is valid, but without the email address, domain owners don’t receive DMARC reports on who or what is sending email on their domain, whether it’s legitimate mail or phishing exploits. A missing RUA tag creates a blind spot, and domain owners don’t get the visibility they need to manage their messaging architecture.
SPF record issues
The lack of SPF records was the most frequent error we saw in this category. SPF is foundational to email authentication and tells receiving mail servers the IP addresses that are allowed to send email on behalf of a domain. Without it, anyone can send email that appears to come from a domain.
SPF records with syntax errors, unsupported mechanisms, or structural problems were also common; in these cases, the receiving mail servers ignore the record and there’s no protection.
Multiple SPF records and too many DNS lookups round out the errors we detected in these German domains, but these challenges are hardly limited to this group of domains. We’ve seen these same problems at the same frequency in all of our DMARC adoption research and strive to produce helpful content and provide expert-led assistance that people need to protect their domains from abuse.
dmarcian provides guided SPF setup that removes the guesswork in identifying legitimate sending sources and constructing accurate records.
Recent Phishing-Related Incidents in Germany
- In April 2026, phishing exploits on Signal targeted German lawmakers. Criminals masqueraded themselves as Signal support and attempted to steal PINs and spread malicious QR codes among senior politicians and diplomats.
- In July, popular grocer Lidl was the victim of a data breach in Germany, Belgium, and the Netherlands. Through a third-party IT vendor, customer names, phone numbers, email addresses, dates of birth, and customer numbers were stolen. The danger in this breach is a second wave of exploits that target customers through phishing, vishing and social engineering schemes.
- Also in 2026, an Austrian hotel IT software company let their German customers know that their network was compromised after a phishing attack. As a result of the breach, guest reservation details were exposed, followed by phishing and fake payment requests targeting those guests.
How DMARC helps
Businesses are using DMARC and its underlying technologies of SPF and DKIM to address the following:
- Email Fraud – DMARC provides visibility of how a domain is used and prevents unauthorized senders from sending email on behalf of an organization.
- Third-party security: With DMARC, you can quickly assess and monitor the security posture of vendors.
- Compliance – Industries, governments, and regulations are increasingly requiring DMARC to be in place.
dmarcian’s commitment
With a team of email security experts and a mission of making email and the internet more trustworthy, dmarcian can help you assess your domain catalog, deploy DMARC and manage domain security for the long haul. With our expertise and mission of DMARC for All, we can help you
- Progress safely from monitoring to enforcement with our expert guidance.
- Understand how SPF, DKIM and DMARC work, and why they are essential.
- Configure these protocols to ensure seamless email delivery.
- Monitor authentication reports to identify and resolve any issues promptly.
Want to continue the conversation? Head over to the dmarcian Forum.