Key findings
For the sender-spoofing results, 1'700'148 .ch domains examined form the 100% base. They are configured to receive email.
- 1'190'194 domains (70.01%) do not effectively protect against sender spoofing.
- Only 226'957 domains (13.35%) request that emails with forged sender addresses be rejected.
- The figures show whether a safeguard is published. They do not show that an organisation has been attacked or hacked.
DMARC: how does protection against sender spoofing work?
DMARC connects the visible sender address with the SPF and DKIM checks. SPF checks whether a server may send for a domain. DKIM checks a message’s digital signature. To pass DMARC, at least one of these checks must succeed, and the domain it authenticates must match the visible sender domain under the alignment rules. This relationship is called alignment.
The p= value lets the domain owner request how messages that fail DMARC should be handled. This helps prevent misuse of the domain as a sender. It does not prevent lookalike domains or forged display names.
DMARC: which protection policies are published?
p=reject requests rejection. It was detected for 13.35% of the email domains examined. p=quarantine requests suspicious handling, for example moving a message to spam. This value was published by 16.65%.
p=none requests no special handling based on DMARC. This applies to 12.91%. Other spam filters may still act. For 57.07%, no DMARC record was found. For about another 0.03%, the p= value was missing or its content was not recognised. Together they account for 57.10%.
Base: 1'700'148 examined domains with a non-empty MX record. Each full bar represents 100%.
Published requests, not measured delivery. Records were not fully validated.
Download chart (PNG) · Vector graphic (SVG)
The 57.10% without a recognised protection policy and the 12.91% with p=none add up to 70.01%. The methodology explains what the scanner records and its limitations.
What did we examine?
Source: SWITCH .ch zone snapshot. Domains without evaluable results are excluded from substantive percentages, not counted as unprotected. Unless stated otherwise, SPF, DKIM and DMARC percentages refer to domains with a non-null MX record.
Show detailed table
| Metric | Result | Count | Comparison base | Group examined | What the figure means |
|---|---|---|---|---|---|
| No effective block against forged senders | 70.01% | 1'190'194 | 1'700'148 | configured to receive email | No supported rule detected, or a rule requesting neither quarantine nor rejection. |
| p=reject: Request rejection when the DMARC check fails | 13.35% | 226'957 | 1'700'148 | configured to receive email | Published request to reject messages. Actual delivery was not tested. |
| SPF record present | 86.75% | 1'474'906 | 1'700'148 | configured to receive email | Record detected. References to other SPF lists were not fully checked. |
| DKIM selector detected | 20.15% | 342'508 | 1'700'148 | configured to receive email | Search used known names. Other records may remain undetected. |
| DNSSEC: DS record for authenticating domain information | 53.84% | 1'247'313 | 2'316'512 | analysed | Record presence only; no cryptographic DNSSEC validation or functional DANE test. |