The Illusion of Email Security

People say email authentication is a solved problem. They claim Google and Yahoo rules made the internet secure.

The data tells a different story.

We pulled DNS records for the Tranco Top-1M domains in July 2026, examining MX, SPF, and DMARC to gauge real-world email security.

Three main findings emerged:

1. DMARC is often security theater

Out of 668,000 domains that receive mail, 463,497 have a DMARC record—good on paper, but the reality is poor.

  • Only 47% of those domains actually enforce a policy.
  • Over 58,000 domains use a placeholder record: p=none.
  • Enforced DMARC adoption slipped 0.46% in the last 30 days.

Companies keep DMARC in “monitoring mode” to avoid breaking marketing tools, choosing vulnerability to spoofing over the risk of a misconfigured filter stopping their emails.

2. The battle for mail hosting

Google Workspace and Microsoft 365 handle 38.5% of inbound mail for the Top-1M, yet self-hosting still matters.

  • In 2016, 44.6% of domains ran their own mail servers.
  • Today that figure stands at 22.6%.
  • Self-hosting remains the largest single category, outpacing Google and Microsoft individually.

About 80,000 domains rely on regional hosters or custom setups, showing many businesses still favor decentralization over cloud services.

3. API-driven delivery dominates

Email delivery has become a backend engineering task. Firms favor raw APIs over marketing platforms because they scale better.

The top five Email Service Providers in the Top-1M are:

  • Amazon SES (6.19%)
  • SendGrid / Twilio (4.75%)
  • Mailgun (4.11%)
  • Zendesk (3.83%)
  • Mailchimp (3.68%)

We derived these numbers by mapping daily OpenINTEL DNS snapshots against our own classification dictionaries.

Source: https://dev.to/livedirectmarketing/the-illusion-of-email-security-what-we-found-analyzing-the-tranco-top-1m-2026-e56