← All research

The startups running DMARC blind

2026-09-16 · OrangeStealth Security

DMARC is the setting that decides whether a stranger can send email that looks exactly like it came from your company. A lot of small B2B SaaS teams have already done the work of turning it on: they checked the box, set a policy, and moved on. But turning DMARC on and actually watching it are two different things, and a surprising number of teams only did the first one.

DMARC has an optional-but-essential piece: a rua= tag that tells mail providers where to send aggregate reports on who is sending mail as your domain, legitimate senders and forgers alike. Skip that tag, and DMARC still runs, but you never see any of the data it was built to give you. You've built a lock with no way to check who's been testing the door.

Enforcing blind

We passively scanned 1,054 US-based B2B SaaS companies (5 to 50 employees) in our September 2026 refresh. 19.0% of that population (200 companies) publish a DMARC record with no rua= reporting address at all. That's one in five teams that configured DMARC and then closed the loop on the one mechanism that tells them whether it's working, who's sending as them, and whether a forger is currently getting through.

This is a different failure than having no DMARC record, and in some ways a sneakier one. A missing DMARC record shows up immediately on any security questionnaire or scanner. A DMARC record with no reporting address looks fine at a glance (the DNS entry is there, the policy tag is there) right up until someone asks "so who's been trying to spoof you this month?" and there's no answer.

What "no rua" looks like from the outside

Picture a 25-person expense-management startup that set up DMARC eighteen months ago during a security push before a big renewal. Their record reads v=DMARC1; p=quarantine; with no rua= tag anywhere in it. The policy line makes the record look mature; enforcement is switched on. But nobody at the company can say which of their vendors send mail as their domain, whether a lookalike sender has ever tried to spoof their finance team, or whether the quarantine policy is currently catching real forgeries or silently swallowing legitimate invoices from a tool they forgot to add. The record technically works. Nobody is watching it.

Three things to do this week

  • Check your own DMARC record for a rua= tag today. It's a one-line DNS lookup: if the tag isn't there, you're in the 19%.
  • Add a reporting address before you touch anything else. Point rua= at a mailbox you'll actually read, or a DMARC reporting service. This is the only way to see who is sending mail as you.
  • Read the reports for a few weeks before you assume your policy is doing what you think: this is how you catch a legitimate sender about to get blocked, or a forger already getting through.
  • Don't treat "we have a DMARC record" as done on a security questionnaire or renewal checklist: a record with no reporting address answers the letter of the question, not the substance of it.
  • Check SPF and DKIM alignment alongside it: reports are far more useful once you can see which of the failures are real spoofing attempts versus your own misconfigured senders.

Want to know if your own domain is in the blind 19%? Our External Security Posture Assessment checks your DMARC, SPF, and the rest of what's visible from the outside, and hands you a plain-English report with the fixes. It's passive and external-only: we never touch your systems.

How we know this

This figure comes from a passive external scan of a population of 1,054 US-based B2B SaaS companies (5 to 50 employees, monthly refresh generated 2026-09-04). We read only public information (public DNS records) with no scanning, probing, or logins. Results are reported in aggregate only, no company is identified, and this figure specifically covers 200 companies (19.0% of the scanned population) whose DMARC record has no rua= tag.