Australia DMARC & MTA-STS Adoption Report 2026
The scale of Australia’s cyber threat landscape is no longer a projection, but a present reality. In a 2025 report, the Australian Signals Directorate noted responding to more than 1,200 high-priority cyber incidents, an 11% year-on-year increase that signals not a spike, but a sustained trend. The financial toll compounds the picture. Large Australian businesses now report average cybercrime costs exceeding $200,000 per incident, a 219% surge in just one year. That’s a new report lodged roughly every six minutes.
The policy response has been swift, with the commencement of the Security of Critical Infrastructure (SOCI) Rules in April 2025. It drew a firm line that cybersecurity in Australia is no longer a voluntary posture but a legal obligation under the Cyber Security Act 2024, as part of the 2023–2030 Australian Cyber Security Strategy.
The data tells a different story on the ground. Most Australian domains carry a DMARC record, but only 46.7% actually enforce it. The rest sit in monitoring mode while email channels stay exposed. Meanwhile, the annual scam epidemic exceeded $2 billion in 2025 and continues to run largely through those same gaps.
This report breaks down Australia’s email and domain security posture sector by sector to understand where DMARC enforcement stands, where transit encryption falls short, and what the structural exposure actually looks like.
Report Request - Australia DMARC Adoption
"*" indicates required fields