Short answer: on 2 October 2026 we looked up the public DMARC and SPF records of 60 well-known Indian domains. 55 of 60 (92%) enforce DMARC with p=reject or p=quarantine, so spoofed mail from those domains gets blocked or sent to spam. Banks lead the pack. The gaps are concentrated in a handful of consumer brands and news sites, plus one surprising pattern: three big brands protect their mail domain but not the website domain customers actually know.

All the raw data is in a CSV file, and you can re-check any domain yourself with our free DMARC Checker and SPF Checker.

Why DMARC matters

Anyone can send an email that says it is from yourbank.com. DMARC is the DNS record that lets a domain owner tell Gmail, Outlook and every other receiver: “if a message claiming to be from us fails authentication, reject it.” It is defined in RFC 7489 and works on top of SPF and DKIM.

There are three policy levels:

  • p=none – monitor only. Spoofed mail is still delivered.
  • p=quarantine – failing mail goes to spam.
  • p=reject – failing mail is refused outright.

Since February 2024, Gmail and Yahoo also require bulk senders to publish at least a p=none DMARC record, so this is no longer optional for anyone who emails customers at scale.

How we checked

  • 60 domains across seven groups: banking and finance (20), e-commerce and consumer apps (13), conglomerates and industry (8), IT services (5), government (5), news media (5) and telecom (4).
  • For each one we queried the TXT records at _dmarc.<domain> and at <domain> through Cloudflare’s public DNS-over-HTTPS resolver – exactly what our DMARC and SPF checkers do in your browser.
  • Where a brand’s best-known address is a subdomain (timesofindia.indiatimes.com), we used the organisational domain (indiatimes.com), because RFC 7489 tells receivers to fall back to it.
  • This is a snapshot of public DNS on 2 October 2026. Records change, and a missing record on one domain doesn’t mean a company’s other mail domains are unprotected (we point out where that’s the case).

The headline numbers

DMARC policyDomainsShare
p=reject3660%
p=quarantine1932%
p=none (monitor only)23%
No DMARC record35%
  • 55 of 60 publish a rua= address, so they receive daily aggregate reports about who is sending as them.
  • 11 set an explicit subdomain policy (sp=). Most of the rest inherit their main policy, which is the safe default.

By sector

SectorDomainsRejectQuarantineNoneMissing
Banking & finance2015401
E-commerce & consumer apps136610
Conglomerates & industry84301
IT services54100
Government53200
News media52111
Telecom42200

Banks are the strongest group: 19 of 20 enforce, and 15 are at full p=reject – including SBI, HDFC Bank, ICICI Bank, Axis Bank, Kotak, Paytm, PhonePe and the RBI itself. That makes sense: banks are the most-phished brands in the country.

News media is the weakest: only 2 of 5 outlets we checked reject spoofed mail.

Four findings worth acting on

1. Some brands protect the mail domain but not the website domain

Three website domains had no DMARC record at all, yet each company runs a sister domain that is locked down with p=reject:

Website domain (no DMARC)Sister domain with p=reject
bankofbaroda.inbankofbaroda.com, bankofbaroda.co.in
bajajfinserv.inbajajfinserv.com
thehindu.comthehindu.co.in

The company’s real email is protected, but a phisher can still send mail “from” the address customers type into their browser every day. Fix: publish v=DMARC1; p=reject; on every domain you own – including ones that never send email. For a domain that never sends mail, also publish SPF v=spf1 -all.

2. Two big consumer brands are still in monitor mode

swiggy.com and indianexpress.com publish p=none. Both collect reports, which is the right first step, but p=none doesn’t stop a single spoofed email. The Indian Express record also sets pct=10, which has no effect while the policy is none.

Fix: after two to four weeks of clean reports, move to p=quarantine and then p=reject (the rollout steps are on our DMARC page).

3. One domain publishes two SPF records

indiatimes.com has two TXT records starting with v=spf1. RFC 7208 says that is a permanent error, so receivers treat the domain as having no valid SPF. DMARC can still pass through DKIM, but SPF is effectively switched off. Fix: merge both into one record. Our SPF Checker flags this instantly.

4. Nearly a third of SPF records end in softfail

Of the 56 domains that publish exactly one SPF record, 39 end with -all (fail) and 17 with ~all (softfail). Three domains publish no SPF record at all, and one publishes two. With DMARC at reject, ~all is a reasonable choice – DMARC makes the final call – but -all is the cleaner end state once every sender is listed.

What this means for your domain

If India’s big brands are at 92% enforcement, small businesses and startups are the easy targets now. Here is the five-minute version:

  1. Check your domain with the DMARC Checker. No record? Start with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com.
  2. Check SPF with the SPF Checker: one record, under 10 DNS lookups, every sending service included.
  3. Turn on DKIM signing in your mail provider (Google Workspace, Microsoft 365 and Zoho all support it).
  4. Read the aggregate reports for a few weeks, fix anything legitimate that fails, then move to quarantine and reject.
  5. Publish p=reject and v=spf1 -all on domains you own but never send mail from.

Data

  • Raw results: india-dmarc-spf-survey-2026-10.csv (domain, sector, DMARC policy, pct, sp, whether rua is set, SPF result, date checked).
  • Method: public DNS TXT lookups via DNS-over-HTTPS on 2 October 2026; organisational-domain fallback per RFC 7489.
  • Spotted something out of date, or fixed your record after reading this? Email us at contact@jugaadbox.net and we’ll update the table.