Cargando…
Cargando…
MEASUREMENT · 14,523 DOMAINS · 14–15 AUGUST 2026
$ dig +short TXT _dmarc.yourcompany.mx
"v=DMARC1; p=none; rua=…"
“p=none” asks the receiving server to do nothing and merely send reports. A domain in that state is exactly as forgeable as one publishing no DMARC at all — except it reads as “configured” in any review. We measured how many are in it.
PRINCIPAL FINDING
Each bar is the share of firms whose published policy CANNOT refuse a forged message sent in their name. It draws what is open rather than what is covered, because that is the figure that describes the risk.
Enforcement falls monotonically: 31.5% → 23.2% → 16.0%. Both steps (−8.4 and −7.2 points) clear the 3-point threshold we fixed in writing before seeing the data.
THE CONSEQUENCE
34.4%
101–250 staff
46.4%
31–50 staff
49.0%
11–30 staff
Of the firms that do publish DMARC, this is the share publishing it with no reporting address (rua=). Without those reports nobody can know which systems send mail as the domain — not the ERP, not billing, not the CRM, not the website form.
For them the standard advice — “set p=reject” — is not a security improvement. It is a high probability of blocking their own invoicing for days, with no way to know beforehand what would break or afterwards what did. This is not a configuration gap. It is an observability one, and it closes in the reverse of the usual order: reports first, policy second.
REGIONAL CONTEXT
Among domains with a determined DNS result, Mexico enforces on 30.6%, against a 32.3% average across the other six countries: below average and inside the range. Presenting it as an outlier would be false.
| Country | Enforces | “p=none” among publishers |
|---|---|---|
| España | 37.9% | 44.8% |
| Perú | 35.8% | 41.0% |
| Chile | 34.6% | 47.9% |
| México | 30.6% | 46.6% |
| Brasil | 29.8% | 55.3% |
| Colombia | 28.5% | 45.9% |
| Argentina | 27.3% | 60.8% |
Between four and six of every ten organisations that configured DMARC configured a policy that rejects nothing.
WHAT WE CANNOT CLAIM
METHOD AND DATA
Only DNS records the owners themselves published for public consumption: TXT at the domain and at _dmarc, _mta-sts and _smtp._tls, and CNAME at the DKIM selectors. There was no port scanning, no host probing, no authentication attempt and no mail sent, and no message content was read.
We measured 14,523 domains across two frames. Published estimates use 13,458: the 1,065 domains in the DENUE 51–100 employee band were measured but excluded before analysis because an earlier run left them without a comparable sampling design (neither census nor random sample). CITATION.cff preserves this accounting.
Why we do not publish the domain list
The measurement knows, for 14,523 named domains, which cannot refuse a forged sender. Publishing that list would be a targeting file dressed as a dataset: every row is a company and an open door, and the people best served by it are the ones committing the fraud. The published dataset is aggregate and contains not one per-domain row.
email-auth-mexico-2026-08-size-bands.csvemail-auth-latam-2026-08-by-country.csvemail-auth-mexico-2026-08-bands.jsonemail-auth-mexico-2026-08.bibemail-auth-mexico-2026-08-CITATION.cffemail-auth-mexico-2026-08-manifest.jsonAll under CC-BY-4.0. The manifest carries each file’s SHA-256, so anyone can verify that the bytes they analysed are the bytes we published.
You do not have to take our word for any of it. Query the TXT record of _dmarc.yourdomain and read the p= tag. If it says none, or there is no record, the result above includes you.
If you want to fix it in-house, the full method is above and we are glad it helps. If you would rather we did it, check your domain and get the price — fixed scope and price in writing, before anything starts.