Reputation Is All You Need · Data Study

Email Authentication Statistics 2026: We Subscribed to 34 Brands and Read 217 Real Emails

os
Ohmysend
Marketing Automation Expert · Updated Aug 25, 2026

Only 57% of top brands enforce DMARC, and 100% of the mail that reaches the inbox is fully authenticated. We subscribed to 34 top-traffic brands and read 217 of their actual emails — header by header, through Gmail's own authentication verdicts. This is what the mail said.

The test Gmail inbox filling with brand marketing emails — Swanson Vitamins, Grunt Style, Keds, TUMI, Crunchyroll and more, August 2026
The test mailbox, late August 2026 — brand campaigns arriving daily. Every message in this study came through this inbox.

Every few months another "state of email authentication" report lands, built the same way: scan a million domains' DNS records, count the DMARC TXT entries, call it a study. Those reports tell you what brands configured. They can't tell you what brands actually send — whether the configuration survives contact with real mail flow, which pipe the mail really travels, or where it lands.

So we ran the other experiment. The headline finding is the one we didn't expect to be the story: everything that reached the inbox was perfectly authenticated — 100% of it — and that is not good news about the industry's health. It's a statement about what an inbox is. The interesting variation hides everywhere else: in who enforces DMARC and who just watches, in whose pipes the mail really rides, and in the senders who did everything right and landed in spam anyway.

How we got the data (the 60-second version)

We subscribed to brand newsletters from an ordinary Gmail address and let the mail accumulate. The brands weren't a random grab: the list was screened from BuiltWith data for top-traffic commerce companies — the head of the industry curve, senders with real infrastructure teams and real budgets. Read every number below with that in mind: this sample starts life biased toward competence. For this analysis we took every brand with an active mailing presence in that mailbox — 34 senders, 217 messages — and parsed the headers of up to 10 recent emails per sender: Gmail's Authentication-Results verdicts, the Return-Path domain, the DKIM signing domains, and which folder each message landed in.

Two things about the mailbox matter for how you read the numbers: it has no engagement history (nobody opens or clicks anything — Gmail sees a dead subscriber), and it only sees mail that arrived (we can't analyze senders whose mail never got here). The full methodology, including why both of those skew the results and in which direction, is in the appendix at the end.

Finding 1: Everything that arrives is authenticated — the inbox is a survivors' club

Across the 23 highest-volume senders — 194 messages — the authentication pass rate was, to the decimal, perfect. Every message passed SPF with an aligned domain. Every message carried a DKIM signature aligned with the From domain. Not one message failed DMARC. Zero in 194.

A DNS-scan study would have you believe senders live everywhere on the spectrum: some aligned, some broken, some misconfigured. The received-mail view says something different and, we think, more honest: the inbox is a survivors' club — everything that arrives is authenticated, because nothing unauthenticated arrives. Two filters produce that perfect rate, and honesty requires naming both. The first is the sample: top-traffic brands, the industry's best-resourced senders — of course their configurations are tidy. The second is the one that generalizes: mailbox providers spent a decade turning authentication into the price of admission, and it worked. By the time mail reaches a Gmail folder, the unauthenticated majority has already been filtered out upstream — rejected at the door, drowned in the spam folder of a mailbox nobody checks, or blocked before a connection was even accepted.

Which means the practical question for a sender in 2026 is no longer "are you authenticated?" — that's table stakes, and your competitors all are. The question is what happens after you clear the gate. That's where the remaining differences live.

Finding 2: Only 57% enforce DMARC — the rest are watching, not deciding

Authentication tells receivers what happened. DMARC's policy tag is where the domain owner tells receivers what to do about failures: p=none (report it, deliver it anyway), p=quarantine (spam-folder it), or p=reject (drop it at the door).

The DMARC policy adoption split across the 23 senders: 13 enforce p=reject (57%), 6 ask for quarantine (26%), and 4 still sit on p=none (17%) — verified against their live DNS records as of this week, not just the headers.

p=reject p=reject: 13 of 23 (57%) 13 · 57% p=quarantine p=quarantine: 6 of 23 (26%) 6 · 26% p=none p=none: 4 of 23 (17%) 4 · 17%
DMARC policy across the 23 senders — live DNS records, week of Aug 25, 2026.

The four on p=none aren't obscure operations. Grunt Style, amika (mailed as email-loveamika.com), Crunchyroll, and Cole Haan's Hong Kong storefront all publish monitoring-only policies. One of the four doesn't even collect the reports — colehaan.hk's record is a bare v=DMARC1; p=none; with no rua= address, which means no visibility into who sends as them, either. Another routes its reports to a third-party monitoring mailbox — someone, somewhere, gets the daily XML; whether anyone reads it is a different question.

And remember whose policies these are: the top of the traffic curve, with infrastructure teams and deliverability budgets. If 17% of them still sit on monitoring-only, the rate among smaller senders without those teams is not going to look better.

A DMARC record set to p=none is write-only authentication: you're generating data nobody acts on, and telling every receiver on earth to make its own call when something fails. With Gmail, Yahoo and Microsoft all treating enforcement as a baseline expectation for bulk senders, p=none in 2026 reads less like a strategy and more like a project that never got its second week. The fix is neither slow nor risky — the three-day path from none to reject is laid out step by step in the SPF, DKIM and DMARC setup guide, and the reports that tell you when it's safe to move are decoded field by field in the DMARC reports walkthrough.

Finding 3: One pipe carries half the mail — and it isn't the platform you log into

Every email carries fingerprints of the infrastructure that transported it: the DKIM signing domains, the bounce address, the receiving chain, the unsubscribe endpoints. Reading those across all 23 senders, the ESP market share among top senders looks nothing like the marketing-platform surveys suggest — and one name dwarfs everything else:

SendGrid's infrastructure transported 13 of the 23 senders' mail — 57%. SparkPost moved 3 (13%), Cordial 2 (9%), and the remaining five senders split across Klaviyo, Attentive, Salesforce Marketing Cloud, Zeta Global, and Adobe Campaign — one each.

SendGrid SendGrid: 13 of 23 (57%) 13 · 57% SparkPost SparkPost: 3 of 23 (13%) 3 · 13% Cordial Cordial: 2 of 23 (9%) 2 · 9% 5 others Klaviyo, Attentive, SFMC, Zeta, Adobe Campaign: 1 each, 5 of 23 (22%) 5 · 22%
Transport layer per sender, inferred from header fingerprints (n=23). "5 others": Klaviyo, Attentive, Salesforce Marketing Cloud, Zeta Global, Adobe Campaign — one each.

Two honest caveats belong on this number. First, this is the transport layer — who physically carried the message — identified from header fingerprints, not a survey of which marketing platform each brand's team logs into. The two are routinely different companies: a brand can run its campaigns on a homegrown tool or a mid-size platform while the mail itself rides SendGrid or SparkPost pipes underneath. The platform you log into is not the pipe that carries your mail. Second, this sample tilts toward established retail brands, not the Klaviyo-native DTC generation; a sample of 2020s-born Shopify brands would surely look different.

Even with those caveats, the concentration is striking. When one pipe carries half the mail, that pipe's reputation, outages, and policy changes become a shared single point of failure for a huge slice of brand email — a systemic risk nobody budgets for because it's invisible from inside any single ESP dashboard.

Finding 4: The root domain stays home

Thirteen of the 23 senders (57%) send marketing mail from a subdomain — emails.shoplc.com, campaign.tumi.com, e.swansonvitamins.com, email.simon.com — rather than the bare root domain. And every single one of the 23, without exception, keeps its bounce handling on a custom domain under its own control rather than an ESP's shared bounce domain: the Return-Path and the From address always resolve to the same brand domain.

A sending subdomain is not a convention — it's a reputation firewall. Marketing traffic is the riskiest mail a brand sends: the highest volumes, the coldest audiences, the most complaints. Quarantining that risk on emails.brand.com keeps it from scorching the root domain that carries your transactional receipts, your password resets, and your CEO's inbox. The subdomain pattern is DMARC's brand-binding logic applied voluntarily: let each mail stream carry its own reputation, and never let the marketing stream drag the corporate one down with it.

If your marketing mail currently goes out as your root domain — or worse, your Return-Path still points at your ESP's shared domain, which was the single most common misconfiguration we found in client audits before this study — the fix is an afternoon of DNS work, covered in the setup guide.

Finding 5: The senders who broke the pattern

The aggregates say the system works. Three senders from the sample are worth a closer look, because each breaks one of its rules in an instructive way.

Fully authenticated, fully enforced — and in the spam folder. One small lighting brand in the sample does everything the guides prescribe: p=reject, SPF aligned, DKIM aligned, every message passing DMARC. Of their last 8 emails to the test mailbox, 6 landed in spam. Read that twice, because it refutes the most common assumption in email marketing: authentication is the entry ticket, not the seat. Authentication decides whether you're eligible to be judged; reputation decides the judgment — the complaint history, the engagement, the sending patterns that Gmail scores over weeks. If your open rates are sliding while every dashboard shows green checkmarks, you're looking at the wrong layer. The reputation layer has its own mechanics and its own recovery playbook, which is what the domain reputation guide is about; and if you need the conceptual reset on why "98% delivered" says nothing about any of this, that's Inbox Placement vs. Deliverability.

The brand that isn't in its own From address. Several brands in the sample send their cart-abandonment and winback mail through SafeOpt — and the mail goes out as PatPat via SafeOpt <patpat@safeopt.com>. Look carefully at what that means: the From domain is SafeOpt's, not the brand's. DMARC alignment happens for safeopt.com; the brand's own domain is a display-name decoration, unauthenticated and uninvolved. The mail arrives (SafeOpt's infrastructure is clean, and it made the Finding 1 club), so the arrangement "works" — but the brand identity that DMARC was invented to bind is handed to a third party, and the customer relationship, reputation, and deliverability all belong to someone else's domain. If SafeOpt's reputation sinks tomorrow, every one of those brands sinks with it and can't even reroute — the mail was never theirs.

The lookalike sending domain. amika sends from email-loveamika.com — a domain that is not loveamika.com, differs from it by a prefix and a hyphen, and would pass a glance test in any phishing seminar as "the fake one." We understand the logic (quarantine marketing from the root — Finding 4), but the execution trains customers to trust mail from a domain that isn't the brand, which is precisely the habit phishing depends on. A subdomain of the real domain — email.loveamika.com — gets the same firewall benefit without the lookalike problem.

What this means for your own sending

Five findings, five checks, in order:

  1. Authenticated? Both SPF and DKIM aligned to your From domain — "all three say PASS" is not the test. Verify it like an auditor.
  2. Enforcing? If your DMARC record says p=none, you're watching, not deciding. The reports that make enforcement safe to switch on are readable in ten minutes.
  3. Know your pipe? Pull a recent campaign in Gmail → Show original → look at the DKIM domains. The infrastructure carrying your mail is your reputation landlord.
  4. Marketing on a subdomain? If not, your riskiest stream shares a reputation with your most important one.
  5. Green dashboards but falling opens? You're past the authentication layer and into the reputation layer — start with the diagnostic workflow.

And if you'd rather have someone run all five for you: we do exactly this as a free manual check — authentication, alignment, policy, infrastructure, the works — at ohmysend.com/free-check.

FAQ

What percentage of brand emails pass DMARC?+
In this study, 100% of the 194 messages that reached the inbox passed DMARC with full alignment — but that measures survival, not health. Mail that fails authentication is largely filtered before it ever reaches a folder, so received-mail pass rates will always look near-perfect regardless of how misconfigured the wider sender population is.
What DMARC policy do most brands use?+
Among these 23 senders, 57% enforce p=reject, 26% request p=quarantine, and 17% remain on monitoring-only p=none — including some very large retail brands. Industry-wide DNS-scan studies typically report lower enforcement rates, because they count every configured domain, not just successful bulk senders.
Which ESPs do most DTC brands use?+
At the transport layer, SendGrid carried 57% of this sample's mail, followed by SparkPost (13%) and Cordial (9%), with Klaviyo, Attentive, Salesforce Marketing Cloud, Zeta and Adobe Campaign at one sender each. The marketing platform a team logs into is frequently a different company from the pipe that physically carries the mail.
Does passing SPF, DKIM and DMARC guarantee inbox placement?+
No. One sender in this study passed every check with p=reject enforced and still landed 6 of 8 emails in the spam folder. Authentication makes you eligible to be judged; sender reputation — complaint rates, engagement, sending patterns — determines the outcome.
Should I send marketing email from a subdomain?+
Most senders in this study (57%) do, and there is a sound reason: a sending subdomain like emails.yourbrand.com acts as a reputation firewall, isolating risky marketing traffic from the root domain that carries transactional mail and corporate email.

Appendix: full methodology

Sample. Brands screened from BuiltWith data for top-traffic commerce companies, subscribed from an ordinary Gmail address over the months preceding August 2026. Because the sample is the head of the traffic curve, read it as "the industry at its most competent" — the percentages here are a best-case read, and smaller senders without infrastructure teams will generally look worse, not better. The analyzed set is every sender with an active mailing presence in that mailbox: 34 senders, 217 messages. Headline statistics use the 23 senders with 3+ messages (194 messages); the remaining 11 low-volume senders are reported only in aggregate. The sample skews toward US retail and DTC brands, and includes media and marketplace senders alongside pure DTC.

Data collection. For each sender, up to 10 most recent messages were read programmatically via the Gmail API (read-only) between June and August 2026 — headers only: Authentication-Results, From, Return-Path, Received, List-Unsubscribe, Message-ID, plus each message's folder label (Inbox/Spam). No message bodies were accessed.

Classification. ESP/infrastructure identification is inferred from header fingerprints — DKIM signing domains, bounce-address domains, unsubscribe endpoints, and MTA naming — and reflects the transport layer, which may differ from the marketer-facing platform. Alignment follows DMARC's relaxed organizational-domain definition (RFC 7489). DMARC policy values were verified against live DNS records on the week of publication.

Limitations, stated plainly.

  1. Survivorship. The mailbox only sees mail that arrived; senders who never deliver are invisible to this method by definition, so pass rates describe survivors, not the population.
  2. No engagement history. The test mailbox never opens or clicks, so folder placement reflects a worst-case "dead subscriber" profile — real subscribers with engagement history will generally see equal or better placement.
  3. Sample size. 34 senders is a deep look at a small panel, not an industry census; treat the percentages as directional, not precise.

How does your mail compare to these 34 brands?

Authentication, alignment, policy, infrastructure, placement signals — checked by hand, by us, not a script. Free, by email, within 48 hours.

Get a free domain check →

Discuss

Found something in your own headers that surprised you? Or think the sample is too charitable to the industry? That's a conversation worth having — ohmysendcom@gmail.com. We read everything.

Want us to run this analysis on your domain? Here's how that works.