This article explains how the DMARCER benchmark dataset is built, so you can judge how representative and reliable the figures are.
Scale and frequency
Each month we scan around 140 million domains. The dataset is refreshed continuously, so the benchmarks reflect the current state of domain security rather than a one-off snapshot, and we can show how the numbers move over time.
What we check and how we score
Every domain is checked for the same email-security signals: SPF, DKIM, DMARC, DNSSEC and MTA-STS. Each domain is then given a score on the same scale, so a result in one industry or country can be compared fairly with any other.
How the results are grouped
We categorise every domain by industry and by country. That lets the benchmarks answer practical questions, such as how well healthcare protects its domains compared with finance, or how one country compares with another.
What data we use
We only use public, non-personal information. The checks read the DNS records a domain publishes openly, the same records any mail server reads to decide whether to trust a message. We do not collect personal data, and we do not read anyone's email. There is more on this in the privacy guide below.

