DMARC didn't become important because the technology changed.
It became important because enforcement did. The protocol is 14 years old. The spec hasn't materially evolved. What changed is that three companies decided to enforce it, and suddenly every organization sending email had to care.
Google and Yahoo didn't invent anything new in 2024. They enforced what already existed. That single shift turned DMARC from a passive DNS record into infrastructure that decides whether your email lands or disappears. Microsoft completed the trifecta in May 2025 with identical requirements for Outlook, Hotmail, and Live. Non-compliant messages are now rejected with a 550 error. The three largest mailbox providers on earth now reject unauthenticated mail.
The market responded fast. Cloud-based DMARC software hit roughly $192M in 2025, projected to reach $742M by 2032 at 21.8% CAGR. Over $300M in VC has flowed into DMARC-focused vendors. The biggest signal: DigiCert acquired Valimail in September 2025 and called it a $4B+ market for paid DMARC solutions. That's not a security vendor hedging. That's a certificate authority making a platform bet.
A policy set to p=none is visibility, not protection. That gap is where spoofing lives, where deliverability quietly degrades, and where pipeline leaks nobody traces back to email authentication.
As of December 2025, only 14.9% of domains from a sample of 73.3 million have even started their DMARC journey with a policy of at least p=none. Just 2.5% enforce p=reject. A staggering 83.9% show no DMARC record at all. Among large enterprises the numbers look better on paper: 89% of Fortune 500 companies have adopted some form of DMARC. Many sit at p=none indefinitely. They chose safety and stayed vulnerable.
250 million active domains worldwide. Only about 5 million use DMARC. Only 1.8 million enforce p=reject. The addressable market isn't shrinking. It's barely been touched.