A DMARC record does two jobs. It publishes the domain owner's requested handling policy for mail that fails authentication (p=none, quarantine, or reject), which receiving systems can honour or override with their own decisions, and it names an address that should receive aggregate reports: a periodic XML feed summarising which source IPs sent mail claiming to be the domain and how that mail fared against SPF, DKIM and alignment. That report address is the rua= tag.

The reports are what make a DMARC deployment observable rather than blind. Each aggregate report is a periodic summary from a receiving mail provider: the source IPs that sent mail claiming to be your domain, how many messages each sent, and whether they passed SPF, DKIM and alignment. In practice that is how you find the marketing platform, invoicing tool or regional office quietly sending as your domain but failing authentication, how you catch a spoofing run against your brand, and how you gain the confidence to move a policy from p=none to reject without silently dropping legitimate mail. Without an rua= address none of that arrives: you publish a policy and see nothing behind it. The reports give visibility into the sources observed sending as a domain and which of them fail authentication. An authentication failure is not automatically an impersonation attempt: it is frequently a legitimate sender that has not been aligned yet, such as a newly added marketing tool. The value of the feedback is that it lets the domain owner tell those cases apart, which is exactly what a domain with no rua= tag cannot do.

So we looked at the rua= tag on every European company domain in the CipherCue directory that publishes a DMARC record: 69,887 of them. A large share publish DMARC and then collect nothing at all. Among those that do report, the single biggest destination is European, not American, which cuts against the usual assumption that Europe's email layer is a US monoculture.

A third of policies are running blind

Of the 69,887 domains with a DMARC record, 23,406 have no rua= tag: 33.5%. The policy is published and receiving systems can act on it, but the owner receives no DMARC aggregate feedback through rua. No aggregate view of which sources are sending as the domain, and no way to tell from DMARC whether a legitimate sender is failing alignment. (An organisation may still have other visibility, from its mail provider or SIEM; it just is not getting it through DMARC.) It is the single most common rua gap we found, and far more common than a malformed address (more on those below).

We are not the first to notice that DMARC reporting is widely half-configured. A peer-reviewed measurement study presented at USENIX Security 2023, tracking reporting across .com, .net, .org and .se over 13 months, found "pervasive mismanagement and missing security considerations in DMARC reporting". That work looked at whole TLDs from the report-consumer's side; ours looks at a European company cohort from the DNS record's side, so the numbers are not directly comparable. They point the same way: publishing a policy is common, wiring up the feedback loop behind it is not.

Has a report address (rua)
46,481  66.5%
No report address: policy runs blind
23,406  33.5%
69,887 European company domains that publish a DMARC record. Snapshot 4 August to 16 September 2026.

Of the rest, most point at an external domain

Among the 46,481 domains that have an rua= tag, 29,401 list at least one address on a registrable domain different from their own: 63.3% of the domains with reporting, or 42.1% of the full 69,887-domain cohort. A same-domain destination is the minority. One thing to keep in mind for the rest of this piece: an rua= value records where a domain owner has asked reports to be sent, not proof that they are delivered there. An external consumer normally has to opt in with a matching _report._dmarc record, which we did not verify at scale, so read these as configured destinations. (There is a dig check for it at the end.)

These external destinations are spread across 3,864 distinct registrable domains, so this is not a market with one or two obvious owners. But the head of the distribution is concentrated. Ranking every external destination by how many European domains point at it (counting each company domain once, and merging obvious aliases such as Brevo's mailinblue.com) gives a top ten that is a mix of email service providers, dedicated DMARC-monitoring tools, and one CDN:

European company domains pointing at each destination
Brevo (ESP, France)
3,600
Cloudflare (CDN/security, US)
2,792
Valimail (DMARC monitoring, US)
1,993
Proofpoint (email security, US)
1,498
DMARC Analyzer (monitoring, NL-founded, now Mimecast/London)
1,117
DMARC Advisor (monitoring, Netherlands)
1,093
dmarcian (monitoring, US)
986
Postmark (ESP, US)
857
OnDMARC / Red Sift (monitoring, London)
772
Green bars are products founded in the EU or UK (DMARC Analyzer is now Mimecast-owned but was founded in the Netherlands). Founding country is not a claim about where reports are processed. Brevo merges its brevo.com and mailinblue.com domains.
DestinationDomainsTypeFounding countryHQ / parent
Brevo3,600Email service providerFranceParis
Cloudflare2,792CDN / securityUnited StatesSan Francisco
Valimail1,993DMARC monitoringUnited StatesSan Francisco
Proofpoint1,498Email securityUnited StatesSunnyvale, US
DMARC Analyzer1,117DMARC monitoringNetherlandsMimecast, London (Permira-owned)
DMARC Advisor1,093DMARC monitoringNetherlandsNetherlands
dmarcian986DMARC monitoringUnited StatesUnited States
Postmark857Email service providerUnited StatesUnited States
OnDMARC (Red Sift)772DMARC monitoringUnited KingdomLondon
EasyDMARC486DMARC monitoringArmeniaUS-incorporated

The single most common external destination is European: Brevo, a French email service provider, at 3,600 domains. That is the surprise. The European Commission's own standards monitoring and the broader digital-sovereignty debate both start from the premise that Europe's email layer is a US monoculture, and for mailbox hosting that premise largely holds. For DMARC reporting it does not: the busiest single destination is French, not American.

The top two destinations are both dedicated reporting mechanisms, not accidental catch-alls. Cloudflare (second, at 2,792) runs a DMARC Management product that adds a Cloudflare rua destination and processes the aggregate reports. Brevo instructs its customers to add rua=mailto:rua@dmarc.brevo.com as part of authenticating a sending domain. What the DNS record cannot tell us is intent: whether an organisation deliberately shopped for a DMARC reporting product, or simply followed the setup steps of a sending platform or DNS provider it had already adopted for other reasons. A Brevo rua tag looks identical either way. So the ranking measures which products end up receiving reports, not how deliberately each was chosen.

Narrow the field to the products whose actual job is DMARC monitoring, and classify each strictly by founding country, and the result is almost a dead heat. The US-founded tools in the top ten, Valimail and dmarcian, account for 2,979 European domains. The EU/UK-founded ones, DMARC Analyzer, DMARC Advisor and OnDMARC, account for 2,982. A gap of three domains. EasyDMARC (486), founded in Armenia and US-incorporated, belongs to neither group and is kept out of that comparison rather than folded into one side. In this cohort, European specialist monitoring products are used at essentially the same rate as American ones.

Per country

Grouping eight countries together as "Europe" hides real differences, so here are the raw counts for the eight with enough domains to report on. The share pointing at an external domain runs from 35.1% in Poland to 56.8% in Ireland. Germany, Poland and Italy lean more towards same-domain destinations than the others.

CountryDomains with DMARCExternal-domain destination
United Kingdom12,7076,319 (49.7%)
Germany17,3226,291 (36.3%)
Poland11,5954,072 (35.1%)
Netherlands7,3273,595 (49.1%)
France7,3653,799 (51.6%)
Italy6,9722,569 (36.8%)
Spain4,3601,715 (39.3%)
Ireland1,358771 (56.8%)

Malformed addresses: 0.46%

We also checked for rua addresses that were simply broken: typos that quietly send reports nowhere. Across the 45,854 domains with a rua tag in the eight countries above, 213 have an address that will not parse. That is 0.46%. The mistakes are the human ones you would guess: mailto:dmarc.heritage.org with no @ at all, an address missing the mailto: scheme, an empty rua=mailto:, and one record with a stray closing quotation mark left in from a copy-paste. At that rate, broken syntax barely moves the totals. The reporting gap is the third of domains that set no rua at all, plus the open question of where the valid addresses actually point.

Two limits on reading this

Two limits are worth stating plainly, because they bound what any of this can claim. First, an aggregate report carries no message bodies, so none of this is about reading anyone's email; it is source IPs, counts and authentication results, which is enough to infer which services send for a domain but not always to name the product. Second, the report data covers only traffic the reporting receiver happened to see, so a quiet sending source that never reached a reporting provider will not appear.

A third limit is data residency. The rua= tag names a vendor, not a location: a vendor headquartered outside the EU may still run EU-resident infrastructure and hold the data under an EU entity, and several of these advertise exactly that. So the destination in DNS is where a sovereignty review starts, not where it ends. It establishes which supplier relationship is configured, which is usually the first thing to pin down and the thing most often missed.

A domain pointing reports at dmarcian is not less secure than one pointing at Brevo; both are ahead of the third that publish a policy and set no rua. The configured destination just tells you which supplier an organisation reached for, and for most that was whoever already sent their mail or served their DNS, not a deliberate choice of DMARC tooling. Checking which supplier your own domain named takes a single DNS lookup.

Check your own domain

The basic observation in this piece takes one command. Query the _dmarc record for a domain:

dig +short TXT _dmarc.example.com

Read the rua= tag in the answer. If there is no rua=, the domain gets no aggregate feedback through DMARC. If there is one, compare the registrable domain in the mailto: address with the domain you looked up: an address at example.com is a same-domain destination, while an address at, say, ag.dmarcian.com is an external one.

For an external destination, you can also check whether the receiving domain has authorised it, which is what actually permits delivery. If example.com asks reports to be sent to rua=mailto:x@thirdparty.net, the authorisation record lives on the receiver:

dig +short TXT example.com._report._dmarc.thirdparty.net

A valid v=DMARC1 response there means the third party has opted in to receive reports for that domain. No response means the configured destination may not actually receive them. This piece measures the rua= tag in DNS; it does not verify that last step at scale.

Method note
  • Data source: CipherCue's dns_compliance observations for the funnel and per-country figures, and email_security observations for named-processor attribution. Both derive from public DNS lookups of the _dmarc record on each apex domain. No message content is read; DMARC aggregate reports contain none.
  • Snapshot window: 4 August to 16 September 2026.
  • Funnel definitions: "has a report address" means the record contains a rua= tag; without one the domain receives no DMARC aggregate feedback through rua. "External-domain destination" means at least one rua= address sits on a registrable domain different from the record's own; an address on the same registrable domain is a same-domain destination. These describe where a record points, not where reports are handled.
  • Configuration, not delivery: we observed the rua= value published in DNS, which is where a domain owner requests reports be sent. We did not verify that reports are delivered. Under the DMARC aggregate-reporting rules an external report consumer normally has to authorise receipt with a matching _report._dmarc TXT record on its own domain; we did not check that authorisation at scale, so external destinations should be read as configured intent, not confirmed flows.
  • Malformed addresses: an rua= value is counted malformed when an address lacks the mailto: scheme or the address does not pass email validation after stripping any size-limit suffix (for example !10m).
  • Destination ranking: external destinations are taken from the raw rua= tag in each DMARC record, reduced to a registrable domain, and counted once per European company domain (a domain listing two Brevo addresses counts as one Brevo). Obvious same-company aliases are merged (Brevo's mailinblue.com into brevo.com; EasyDMARC's .eu into .com); other companies are not merged, so a vendor using several unrelated report domains may be undercounted. The 3,864-domain long tail is real: the top ten below covers only part of the external total.
  • Type and location, not data residency: the type column reflects a destination's primary business (email service provider, DMARC monitoring, CDN/security), and founding country and HQ are taken from public record, not a claim about where reports are stored or processed. DMARC Analyzer was founded in the Netherlands and acquired in 2019 by Mimecast, which states it is headquartered in London and owned by funds advised by Permira. OnDMARC is Red Sift's product (UK). Brevo is French (formerly Sendinblue). Valimail, dmarcian, Proofpoint and Cloudflare are US-headquartered; DMARC Advisor is Netherlands-based; EasyDMARC was founded in Armenia and is US-incorporated. Beneficial ownership beyond these public facts was not established.
  • Non-vendor destinations excluded from the table: some frequent external destinations are a company's own shared reporting domain rather than a supplier (for example one insurer's group domain appearing across its subsidiaries, or a shared government endpoint). These are counted in the 29,401 external total but left out of the vendor ranking.
  • Representativeness: this is a snapshot of the European company domains represented in the CipherCue directory, not a statistically representative census of every European company. The directory's composition (which sectors, sizes and countries are covered) shapes these figures, so read them as describing this cohort rather than "all of Europe".
  • Scope: 69,887 European company entities in the CipherCue directory that publish a DMARC record and carry an EU/UK country field. Entity country is the company's registered country in the registrar it was seeded from. The per-country table and the malformed-address count are limited to the eight countries with the largest samples; other EU countries appear in the overall totals.
  • Not counted: domains with no DMARC record; entities without a country field.
SenderLedger reads your domain's public DNS in seconds, no account needed. Start free for one domain to see every service sending as you and work towards p=reject without blocking your own mail.