How we build the benchmark dataset

How the dataset is built: around 140 million domains scanned and scored every month, grouped by industry and country, using public, non-personal data only.

Published 3 Jul 2026 23

This article explains how the DMARCER benchmark dataset is built, so you can judge how representative and reliable the figures are.

Scale and frequency

Each month we scan around 140 million domains. The dataset is refreshed continuously, so the benchmarks reflect the current state of domain security rather than a one-off snapshot, and we can show how the numbers move over time.

What we check and how we score

Every domain is checked for the same email-security signals: SPF, DKIM, DMARC, DNSSEC and MTA-STS. Each domain is then given a score on the same scale, so a result in one industry or country can be compared fairly with any other.

How the results are grouped

We categorise every domain by industry and by country. That lets the benchmarks answer practical questions, such as how well healthcare protects its domains compared with finance, or how one country compares with another.

What data we use

We only use public, non-personal information. The checks read the DNS records a domain publishes openly, the same records any mail server reads to decide whether to trust a message. We do not collect personal data, and we do not read anyone's email. There is more on this in the privacy guide below.

Was this article useful?

Be the first to vote.
Got feedback for our team? Send us a comment

Related articles