4 min read By Excello Mail Team

Financial Institutions Lead DMARC Adoption. They Are Still the Number One Phishing Target.

PowerDMARC's United States DMARC & MTA-STS Adoption Report 2026 shows banking and finance ahead of nearly every other sector on DMARC enforcement. Separate research on the largest US banks tells a different story. Here is what the gap between sector averages and top targets means for financial institutions.

PowerDMARC’s United States DMARC & MTA-STS Adoption Report 2026, drawn from more than 900 domains across major industries, put national DMARC adoption at 95.8% and national DMARC enforcement, a policy of p=reject, at 49.0%. Banking and finance came out ahead of that national baseline, with roughly 60% of financial services domains at enforcement, a 17-point lead over the global average. Within the sector, SPF record correctness sits at 90.9%. Coverage of the report this month made banking and finance look like one of the stronger performers in American email authentication.

Separate research tells a less comfortable version of the same story. Red Sift’s analysis of the largest US banks found less than half enforcing p=reject, with nearly a third sitting at p=none, publishing a record but taking no action on failures. That is a different population than PowerDMARC’s broader financial services sample, but it is the population that matters most: the very largest, most recognizable, most impersonated banks in the country.

Two Numbers, One Sector, No Contradiction

Both findings can be true at once, and understanding why matters more than picking a side. A sector average pulled up by a large tail of well-run community banks and credit unions is a different thing from the enforcement rate at the handful of national brands that appear in more phishing kits than any other industry. Financial institutions account for over half of all phishing attacks tracked globally, and the Anti-Phishing Working Group has recorded quarterly attack volumes above 989,000, the highest ever measured. Attackers are not spread evenly across a sector’s domain list. They concentrate on the names a phishing email recipient will recognize instantly, and those are disproportionately the largest banks, the ones Red Sift found lagging.

MTA-STS Is the Overlooked Half of the Story

The PowerDMARC report surfaces a second gap that gets less attention than enforcement. MTA-STS, which protects email against interception and downgrade in transit, sits at just 3.0% adoption in banking and finance, barely above the 1.7% national average. A bank can enforce DMARC on the receiving end and still leave the transport layer of its own outbound mail exposed to a man-in-the-middle downgrade attack that neither SPF, DKIM, nor DMARC is designed to catch. Email authentication answers who is allowed to send as your domain. It does not answer whether the connection carrying that mail was protected on the way there.

Why the Cost of Getting This Wrong Is Higher in Finance

IBM’s Cost of a Data Breach research puts the average financial services breach at roughly $6 million, well above the cross-industry average, and a spoofed email is still the cheapest entry point into that outcome for an attacker. A customer who receives a fraudulent wire instruction, a fake fraud alert, or a spoofed password reset from what looks like their bank is not weighing probabilities. They are acting on trust in a brand that has spent decades building it. Every unenforced DMARC record at a major bank is a standing invitation for someone to borrow that trust for free.

What Financial Institutions Should Do

Do not read a sector average as a statement about your own domain. A 60% enforcement rate across financial services means roughly four in ten financial domains are still exposed, and the size of your institution does not automatically put you on the right side of that split. Check your own policy directly.

Move from p=none to p=quarantine to p=reject on a schedule, not indefinitely. Nearly a third of major banks in the Red Sift data are still at monitoring-only. A DMARC record with no enforcement stops nothing. It only tells you, after the fact, who tried.

Add MTA-STS alongside DMARC, not after it. At 3.0% adoption in a sector this frequently targeted, MTA-STS is the gap most financial institutions have not even started closing. It protects a different part of the mail path than authentication does, and both are needed.

Treat your DMARC aggregate reports as a customer-protection tool, not just a security control. Every spoofed domain your reports surface is a domain sending fraud to people who trust your brand enough to open the email.

The Takeaway

Financial services looks strong against a national average and weak against the standard that actually matters, which is whether the specific banks customers recognize by name have closed the door. A sector-wide enforcement rate seventeen points above average is real progress, and it does not change the fact that attackers concentrate on the largest, most trusted names, and that is exactly where enforcement is currently thinnest. The institutions with the most brand recognition to protect are the ones with the most reason to move off p=none this year, not the least.


Excello Mail helps financial institutions move from a published DMARC record to real p=reject enforcement, closing the spoofing gap that puts customer trust and regulatory standing on the line. Sign up for free to Excello Mail and see exactly where your domain stands today.