5 min read By Excello Mail Team

GMX, WEB.DE and mail.com Start Rejecting DMARC Failures at the SMTP Level, While Half a Million Domains Still Have the Alarm Switched Off

1&1 Mail & Media, the operator behind GMX, WEB.DE and mail.com, is rolling out full inbound DMARC p=reject enforcement across 42 million mailboxes. At the same time, a fresh DMARC adoption report shows more than half a million domains that published a DMARC record are still sitting at p=none, the setting that does nothing to stop spoofing.

The postmaster team at 1&1 Mail & Media, the company behind GMX, WEB.DE and mail.com, told the mailop mailing list this quarter that it is rolling out full inbound DMARC enforcement across its infrastructure, honoring p=reject policies at the SMTP transaction itself instead of treating them as a soft signal. Mail from a domain that publishes p=reject and fails to pass DMARC through aligned SPF or aligned DKIM now gets bounced outright, with the sending server receiving “554 Transaction failed Reject due to domain’s DMARC policy” before the message ever reaches a mailbox. GMX, WEB.DE and mail.com together serve 42 million active users and hold a leading position in Germany, Austria and Switzerland, so this is not a niche mailbox provider tightening a minor setting. Postmastery’s Q1 2026 delivery benchmark, built from 15.5 billion tracked transactions, flags the change as one of the most consequential deliverability shifts of the year. In the same window, EasyDMARC’s 2026 DMARC adoption report found that 525,996 domains, more than half of every domain that has ever published a DMARC record, are still parked at p=none. Those two facts sit on opposite sides of the same problem, and neither one makes sense without the other.

What Actually Changed at GMX, WEB.DE and mail.com

DMARC has technically covered GMX and WEB.DE since 2021, when the provider first said it would honor sending domains’ published policies to help protect users from spoofed addresses. What is changing now is enforcement depth. A published p=reject policy used to be something these providers could weigh alongside other signals. Now it is a hard instruction: no aligned SPF, no aligned DKIM, no delivery, decided during the SMTP conversation rather than after the fact. For a sender whose authentication is already clean, this changes nothing. For a sender who published p=reject as a compliance checkbox years ago and never verified that every legitimate sending source, a marketing platform, a helpdesk tool, an internal relay, actually aligns, this is the moment misconfigured mail starts bouncing at one of the largest mailbox footprints in German-speaking Europe.

The Other Half of the Story: Domains That Never Turned the Policy On

EasyDMARC’s report puts the flip side of this problem in hard numbers. Of the domains that have ever published a DMARC record, more than half sit at p=none, the monitoring-only setting that generates aggregate reports but takes no action against spoofed mail. That figure tracks almost exactly with the timeline of Google’s and Yahoo’s 2024 bulk sender requirements, which mandated DMARC at p=none as a minimum bar. Millions of domains cleared that bar and stopped there. Among the Fortune 500, 95% have a valid DMARC record and more than 80% enforce at quarantine or reject; reporting is close to universal at 97.9%. Among the Inc. 5000, adoption is a respectable 76.2%, but only 15.2% ever reach p=reject, and more than half remain stuck at p=none. The pattern is consistent everywhere it has been measured: publishing a DMARC record is now table stakes, but the move from monitoring to actual enforcement is where the vast majority of organizations stall out.

Why This Matters for DMARC and Deliverability

These two developments describe the same gap from opposite directions. GMX, WEB.DE and mail.com enforcing p=reject on the receiving side only protects senders who have already done the work of moving their own policy to p=reject and keeping every authorized source aligned. For the 525,996 domains still sitting at p=none, this enforcement change delivers zero additional protection, because there is no reject policy for GMX’s mail servers to honor in the first place. A spoofed email impersonating one of those domains still lands in a GMX, WEB.DE or mail.com inbox exactly as it always has. Meanwhile, for the smaller set of domains that did publish p=reject without confirming every sending source stays aligned, this enforcement rollout is the moment years of unverified configuration turns into real bounced mail, missed invoices, and support tickets. DMARC’s value was never in the record existing. It was always in the gap between “published” and “enforced and correct,” and this week two independent data points landed on exactly that gap from different angles.

What Senders Should Do Now

If your domain already publishes p=reject, audit your aggregate reports before, not after, mail starts bouncing. Every third-party platform sending on your behalf, marketing tools, transactional email services, helpdesk software, needs SPF or DKIM alignment confirmed against your actual DMARC record, not assumed from a setup guide you followed once.

If your domain is still at p=none, that record is not protecting anyone. It is collecting data. Use the aggregate reports it generates to identify every legitimate sending source, fix alignment for each one, and move deliberately through quarantine to reject rather than leaving the policy at monitoring-only indefinitely.

Treat GMX, WEB.DE and mail.com as a preview, not an outlier. Mailbox providers moving from soft DMARC handling to hard SMTP-level rejection is the direction the entire industry is heading, following Gmail and Yahoo’s earlier enforcement moves. Domains that get their alignment right now avoid being caught flat-footed at the next provider that flips the switch.

The Takeaway

A DMARC record with no enforcement stops nothing, and an enforced policy with unverified alignment starts bouncing legitimate mail the moment a major provider like 1&1 Mail & Media decides to honor it at the SMTP level. Both failure modes are common, both are measurable in a domain’s own aggregate reports, and both are fixable well before a bounce or a spoofed email forces the issue.


Excello Mail turns your DMARC aggregate reports into a clear picture of exactly which sending sources are authenticated and aligned, so you can move confidently from p=none to full enforcement without guessing which provider’s next policy change will catch you off guard. Sign up for free to Excello Mail to see where your domain actually stands.