← All research

The startups with no DMARC record at all

2026-09-22 · OrangeStealth Security

If your company sends invoices, password resets, or a sales follow-up from your own domain, DMARC is the setting that decides whether someone else can do the same thing. No DMARC record means no policy at all: no request to quarantine, no request to reject, and no reports telling you when mail is going out in your name that you didn't send.

Most small B2B SaaS teams never touch it. It's not on a launch checklist, nobody owns email infrastructure part time, and the domain just sits there wide open until a customer forwards a phishing email that "looks exactly like us."

What we measured

We ran a passive, public data only scan against a population of US B2B SaaS companies with 5 to 50 employees, sample size N = 1054, aggregate generated 2026-09-04. The scan looks at what's already published in DNS, nothing sent to any mail server and nothing that touches a login. Results are k-anonymised and no company is named individually.

In that sample, 12.2% (n=129) of domains had no DMARC record at all. Not a weak policy, not p=none, nothing published. For those domains, a receiving mail server has no DMARC signal to check against, and the domain owner gets zero visibility into who else is sending mail claiming to be them.

That's not proof anyone is abusing those domains today. It's a gap that makes abuse easier and, if it happens, invisible to the owner.

What it looks like in practice

Picture a hypothetical 20-person SaaS company, invoicecorp.example. Their domain has SPF set up for their email provider but no DMARC record. Someone spins up a look-alike sending setup, forges the From address as billing@invoicecorp.example, and emails a customer asking them to update payment details on a new "portal" link.

Because there's no DMARC record, the receiving mailbox has no domain-level policy to weigh that message against. Depending on the receiver's own filtering, the message might land in spam, might land in the inbox, or might get blocked for unrelated reasons. None of that is guaranteed either way. What is certain is that invoicecorp.example never finds out it happened, because without a configured reporting destination, nobody sends them a report. DMARC without reporting is a closed loop: the domain owner is the last person to know.

What to actually do about it

  • Check whether your domain has a DMARC record at all. If you're not sure, that's the first thing to find out, not the last.
  • If you have none, start at p=none. That requests no enforcement, it just turns on visibility: you'll see what's sending as your domain before you ask receivers to act on any of it.
  • Add a reporting address (rua tag) when you publish the record. Without it, even a correct DMARC record tells you nothing, since reports require a configured destination.
  • Before moving from p=none toward quarantine or reject, confirm every legitimate sender, your email provider, your invoicing tool, any marketing platform, is passing SPF or DKIM in alignment. A pass needs one of the two aligned, not both. Move too fast and you can block your own mail.
  • Treat quarantine and reject as your policy request to receivers, not a guarantee of what happens on their end. Different mail providers enforce differently.

You can check your own domain's DMARC status for free at https://orangestealth.com/check, no signup, just the same passive DNS lookup we ran across the sample above. If you want the fuller picture (DMARC alongside SPF, exposed services, and the rest of what's publicly visible about your domain) that's what our External Security Posture Assessment covers, as a passive, external only review, separate from the free checker and going deeper than a single record.

A missing DMARC record isn't dramatic on its own. It's just one of those settings nobody remembers to set, until it's the reason a customer got a convincing fake invoice with your name on it.