• Most Financial Institutions Have DMARC. Almost None Are Protected.

Most Financial Institutions Have DMARC. Almost None Are Protected.

by

Last Updated:
8 min read
Most Financial Institutions Have DMARC. Almost None Are Protected.

Key Takeaways

  • Financial institutions have some of the highest DMARC adoption rates of any industry. That’s good news, but adopting DMARC and actually being protected are two different things.
  • The difference comes down to policy settings. p=none provides visibility and reports but does not block spoofed emails. p=quarantine sends suspicious messages to spam. Only p=reject actively stops spoofed emails from reaching inboxes. This means many financial institutions have DMARC records but remain vulnerable to impersonation. Adoption is high, but enforcement is far less common, especially beyond the largest banks.
  • PowerDMARC’s guide to DMARC for financial institutions walks through what it takes to close this gap and move from visibility to real protection.

The Headline Number: Adoption Is (Almost) Solved

Let’s start with the good news, because it’s worth noting: financial services has moved faster on DMARC adoption than almost any other industry. Across the countries PowerDMARC has studied, banking and financial services consistently rank among the top one or two sectors nationally for simply having a DMARC record in place, well ahead of retail, healthcare, or government in most markets.

  • Belgium: financial institutions are “the clear frontrunners in email security adoption,” with only 1 in 12 lacking a DMARC record entirely, according to PowerDMARC’s Belgium DMARC Report 2025.
  • Germany: the banking sector “sets the pace” for email security nationally, per PowerDMARC’s Germany DMARC Report 2025.
  • Norway: financial services shows DMARC adoption that’s “nearly universal,” with only 6.8% of domains lacking a record at all, according to PowerDMARC’s Norway DMARC & MTA-STS Adoption Report.
  • United States: PowerDMARC’s United States DMARC & MTA-STS Adoption Report 2026 found overall national DMARC adoption at 95.8% across more than 900 domains, effectively near-universal, with banking and finance among the sectors driving that number.
  • Canada: banking has some of the lowest non-adoption in the country, with only 8.0% of domains lacking a DMARC record at all, per PowerDMARC’s Canada DMARC & MTA-STS Adoption Report 2026.
  • Poland: banking and finance shows 83.7% of domains with a DMARC record in place, according to PowerDMARC’s Poland DMARC & MTA-STS Adoption Report 2026, though a meaningful 16.3% still have none at all.
  • France: banking leads every other sector on record adoption, with only 7.6% of domains lacking a DMARC record, per PowerDMARC’s France DMARC & MTA-STS Adoption Report 2026.

Explore DMARC Adoption Reports by Country

Reasons for High Adoption Rates in 2026

The high adoption rates for DMARC in financial institutions didn’t happen by accident. Regulatory pressure on this sector has been building for years and is now arriving from several directions at once.

  • PCI DSS v4.0.1 made anti-phishing controls a required control rather than a best practice for any organization handling payment card data, effective March 31, 2025. Under it, DMARC, SPF, and DKIM are recommended options to meet these requirements.
  • In the U.S., the FTC Safeguards Rule has quietly expanded to cover a much wider range of financial businesses than most people realize.
  • National financial regulators from Riyadh to Ottawa have been pushing the same message through their own domain-security mandates.
  • Major mailbox providers added their own pressure on top of all this. Since February 2024, Google and Yahoo have required any domain sending more than roughly 5,000 emails a day to publish at least a p=none DMARC record with aligned SPF and DKIM, or risk having mail rejected or sent straight to spam. Microsoft has moved in the same direction for high-volume senders to Outlook and Hotmail addresses. For a bank sending routine statements and alerts to millions of Gmail and Yahoo customers, that isn’t optional anymore either.

The Real Number: Enforcement Is Nowhere Close

Here’s where the story turns. Look past any single country’s headline number and the same shape appears everywhere PowerDMARC has studied the sector: banking usually leads its national economy on enforcement, and even that leadership leaves a large share of the sector exposed.

  • United States: PowerDMARC’s United States DMARC & MTA-STS Adoption Report 2026, which analyzed more than 900 domains, puts overall national p=reject enforcement at 49.0%, the highest of any country in PowerDMARC’s benchmarking, a result the report credits partly to “early regulatory mandates and the high-stakes risk environment” in sectors like banking and healthcare. Within the banking and finance sector specifically, SPF correctness sits at 90.9% while MTA-STS adoption, which protects messages in transit, is just 3.0%.
  • Canada: banking leads the country in enforcement at 42.0% p=reject, per PowerDMARC’s Canada DMARC & MTA-STS Adoption Report 2026, which analyzed 555 domains. The same report notes 8.0% of banking domains have no DMARC record at all, and frames the gap directly: “the remaining 58.0%, including those on ‘None’ or ‘Quarantine’, remain susceptible to sophisticated spoofing attacks that can lead to massive financial fraud and loss of customer trust.”
  • Norway: financial services sits at 44.7% p=reject, the second-strongest sector after healthcare’s 55.6%, per PowerDMARC’s Norway DMARC & MTA-STS Adoption Report.
  • Saudi Arabia: the SAMA-regulated banking sector, the most tightly overseen part of the Saudi economy, has pushed close to 50% enforcement even though the country’s overall enforcement rate across all sectors sits at just 18.4%, according to PowerDMARC’s Saudi Arabia DMARC & MTA-STS Adoption Report.
  • Poland: banking shows the highest enforcement of any Polish sector at 40.8% p=reject, per PowerDMARC’s Poland DMARC & MTA-STS Adoption Report 2026, but 16.3% of banking domains still carry no DMARC record at all, and MTA-STS adoption in the sector sits at 0%.
  • France: banking is the clear national leader here, reaching 63.3% p=reject, according to PowerDMARC’s France DMARC & MTA-STS Adoption Report 2026. Even so, 7.6% of French banking domains have no DMARC record at all, and, as in Poland, MTA-STS adoption across the sector sits at 0%.

Put those numbers side by side, and a pattern emerges that holds across six countries and a wide range of regulatory environments: banking is consistently the best-enforced or near-best-enforced sector nationally, typically landing somewhere between 40% and the low 60s percent on p=reject. But that means somewhere between roughly a third and 60% of financial institutions still don’t block a spoofed email outright.

There’s one genuinely encouraging data point worth calling out fairly. dmarcian’s study of the top 100 global banks by revenue found real, measurable progress between 2021 and 2025:

dmarc financial institutions

  • A 74% decrease in domains with no DMARC record at all.
  • A 52% drop in domains still stuck at p=none.
  • A 50% increase in p=reject adoption.

The Part Nobody’s Measuring: Beyond the Megabanks

Nearly every piece of DMARC research on financial services, including the numbers above, studies the same narrow slice of the industry: the largest U.S. banks, the top 100 global banks by revenue, the handful of institutions large enough to show up in a national domain scan. That’s a small fraction of what regulators actually mean when they say “financial institution.”

Who the FTC Safeguards Rule actually covers

Since 2024, the FTC Safeguards Rule has applied to a much broader population defined by activity rather than institutional type:

  • Auto dealers that arrange or facilitate financing
  • Mortgage brokers
  • Financial advisors and registered investment advisers
  • Tax preparers
  • Debt collectors and payday lenders

Essentially, any business that provides financial services and collects customers’ private information can be covered by this rule. That could include a regional car dealership handling loan applications through a shared inbox, not just a large national bank.

There is no dedicated study on DMARC enforcement among these businesses, but the broader picture is concerning. EasyDMARC’s 2025 Global DMARC Adoption Report found that only 7.7% of the world’s top 1.8 million email domains were fully protected with a p=reject policy. That means roughly 92% were still unprotected.

The takeaway:

Many financial businesses may have DMARC records, but far fewer have moved to enforcement and most likely remain vulnerable to spoofing.

.BANK Domains Are Required to Enforce. Most Bank .com Domains Aren’t.

There’s a structural detail here that makes the enforcement gap look less like a technical limitation and more like a choice. Any domain registered under the .BANK or .INSURANCE top-level domains has always been required to publish DMARC as a condition of registration. Since November 2023, that requirement has gone further: fTLD, the registry operator for those TLDs, added Public Suffix Domain DMARC under RFC 9091, which enforces authentication at the registry level itself. In practice, a p=reject policy is effectively mandatory for every domain on .BANK or .INSURANCE.

Meanwhile, the same institution’s ordinary, customer-facing .com domain, the one that actually appears in most customer emails, faces no such requirement and, per the data above, is enforced roughly half the time at best.

That contrast is the clearest evidence available that enforcement is a solved technical and operational problem the moment it’s made mandatory. This makes it not a capability gap, but a policy and prioritization gap.

Why the Gap Persists (It’s Not Ignorance)

The reasons banks give for staying at p=none aren’t about not knowing better. Per Red Sift’s analysis, the reasons are operational complexity and risk aversion:

  • A large bank routes email through hundreds of legitimate third parties: marketing platforms, mortgage servicing systems, statement generators, loan document vendors.
  • Moving straight to p=reject risks blocking a customer’s loan document or payroll notice if even one of those senders isn’t correctly authenticated.
  • For a bank, a blocked legitimate email is its own kind of incident, one that shows up immediately, while a spoofed email sitting at p=none is a risk that stays invisible until it isn’t.

That’s a real concern, but it’s also exactly what the standard, phased DMARC rollout is designed to solve. The path from p=none to monitoring to p=quarantine to p=reject exists precisely so an organization can identify every legitimate sender before it blocks anything.

What “Protected” Should Mean for a Financial Institution in 2026

A reasonable floor for any financial institution today looks like this:

  • DMARC enforced at p=reject, on every domain capable of sending or being spoofed to send financial communications, not just the primary corporate domain.
  • Coverage extended to parked domains and defensive registrations, not only the ones actively used for customer mail.
  • A sending-source inventory that’s actually kept current, so third-party vendors don’t quietly fall out of alignment after the initial rollout.

PCI DSS v4.0.1 made anti-phishing controls mandatory for card-data handlers as of March 2025. The FTC Safeguards Rule already covers a far wider range of financial businesses than most non-bank firms realize. Neither of these treats a p=none record as compliance, and neither should any institution that wants to call itself protected.

That’s the loop the headline closes. An institution can honestly say it “has DMARC” while sitting at p=none, and be exactly as exposed to spoofing as one with no record at all.

How PowerDMARC Helps Close the Gap

Getting from p=none to p=reject is a process, not a switch, and that’s exactly where most financial institutions stall. PowerDMARC’s platform is built around that specific transition:

How-PowerDMARC-Helps-Close-the-Gap-

  • Visibility before enforcement: Real-time threat intelligence surfaces every domain and third party sending mail on an institution’s behalf, so security teams can see who needs to be authorized before a single message gets blocked.
  • Managed authentication: Hosted SPF, DKIM, DMARC, MTA-STS, and BIMI let a team move through the monitor-to-enforce phases with a live compliance dashboard rather than tracking spreadsheets of DNS records by hand.
  • Alignment with existing mandates: Because DMARC is a named control under PCI DSS v4.0.1, the same rollout that gets a bank to p=reject also satisfies a control examiners are already checking for.
  • AI-assisted threat detection: Aimed at catching financial-sector phishing and BEC patterns, like spoofed wire instructions or fake vendor invoices, before they reach an inbox at all.

This removes the excuse that enforcement is too complex or too risky to move on.

Final Thoughts

Financial services solved adoption faster than almost any sector out there. It has not solved enforcement, and the institutions least likely to be enforcing are also the institutions least likely to ever show up in a study. FBI’s own numbers show what’s at stake in the meantime: the FBI’s IC3 2025 Annual Report logged over 1 million cybercrime complaints for the first time in its history, totaling $20.877 billion in losses, a 26% jump over 2024. Phishing was the single most-reported crime type, and business email compromise alone accounted for $3.05 billion of the total.

What’s missing, in most institutions, isn’t a solution. It’s the organizational decision to actually use it. If you want to see where your own institution’s domains actually stand, PowerDMARC’s free Domain Analyzer will show you in under a minute!

dmarc financial institutions