Stileex

DMARC, SPF and DNSSEC in Brazil's federal government

The Stileex Domain Authentication Index (SDAI) reads the domains of the federal census every week: whether they publish the records that let a receiving mail server refuse a message forged in their name, and whether their DNS answers can be validated.

On 13/09/2026, 25.1 % of the 996 active federal domains publish a DMARC policy asking mail servers to quarantine or reject messages that fail authentication; 40.1 % publish a DMARC record, 61.2 % an SPF record, and 30.1 % have their DNS answers validated with DNSSEC.

Enforcing DMARC policy (quarantine or reject)

25.1 %

Over 996 active domains.

DMARC record published

40.1 %

Over 996 active domains.

SPF record published

61.2 %

Over 996 active domains.

DNS answers validated with DNSSEC

30.1 %

Over 996 active domains.

DMARC, policy by policy

The 996 active domains of the census, by the DMARC policy published at _dmarc.<domain>. The first two rows make up the headline figure.

Policy Domains Share
Reject (p=reject) 85 8.5 %
Quarantine (p=quarantine) 165 16.6 %
Quarantine or reject applied to part of the mail (pct under 100) 25 2.5 %
Monitoring (p=none) 124 12.4 %
A record no receiver applies (two records, or no readable policy) 4 0.4 %
No DMARC record 593 59.5 %

A DMARC policy tells receiving mail servers what to do with a message that carries the domain in its From address and fails SPF and DKIM authentication: deliver it and report, quarantine it, or reject it.

Domains that receive mail, and those that do not

Mail exchangers (MX) Domains Enforcing DMARC policy
The domain declares a mail exchanger 539 40.4 % (218)
The domain declares none 457 7.0 % (32)

A domain that receives no mail can still appear in the From address of a message. For such a domain, mail security guides describe an SPF record authorising no server (v=spf1 -all) and a DMARC policy of reject.

SPF records

How the SPF record of each active domain ends: what it asks a receiving server to do with mail from a server the record does not list.

Ending Domains Share
-all: fail the mail of any unlisted server 419 42.1 %
~all: accept it, marked as suspicious 173 17.4 %
?all: take no position 13 1.3 %
redirect: another domain's record decides 2 0.2 %
No all mechanism 3 0.3 %
Two SPF records or more, which no receiver applies 7 0.7 %
No SPF record 379 38.1 %

DNSSEC

A domain counts as validated when the resolver authenticated its answer along a chain of trust running from the root of the DNS down to the domain's zone.

Zone Domains Share
Answers validated with DNSSEC 300 30.1 %
Answers without DNSSEC validation 696 69.9 %

104 of the 996 active domains (10.4 %) combine all three: an enforcing DMARC policy, an SPF record and DNS answers validated with DNSSEC.

The census, domain by domain

The 1,624 systems of the census, read on the day of the figures, by the state their domain was found in. The shares above are computed on the active domains.

State Domains
Active: the domain exists and its zone answers 996
The domain no longer exists (NXDOMAIN) 355
The domain's zone does not answer 242
No answer obtained that day 31

Among the zones that do not answer, 10 carry DNSSEC signatures that do not verify: they answer once validation is set aside.

What these three records do

SPF (RFC 7208) lists the servers allowed to send mail for a domain. DKIM signs each message with a key the domain publishes. DMARC (RFC 7489) ties the two to the address a reader sees, and tells receiving servers what to do with a message that fails: deliver it and report, quarantine it, or reject it. A policy of quarantine or reject is the one that asks a receiver to act.

DNSSEC signs the answers of the DNS itself, so that a validating resolver can tell an authentic answer from a forged one. It covers every record a domain publishes, its SPF and DMARC records included.

The same census is read by two other Stileex indices: hosting sovereignty · public cloud

How it is measured

Census
%systems% federal systems: the 1,610 domains of the gov.br register the Secretaria de Governo Digital publishes on dados.gov.br, plus the federal institutions outside that zone (.jus.br, .leg.br, .mil.br, .mp.br). It is the census of the hosting sovereignty index.
Cadence
One campaign a week, on Sundays: each point is dated on the day the domains were read.
Reading
Five questions per domain on the public resolver 1.1.1.1, which validates DNSSEC: NS (and the validation flag of its answer), DS, TXT at _dmarc.<domain>, TXT at the domain, MX. A domain that no longer exists is asked the first one alone.
Base
The active domains: those that exist and whose zone answered the five questions. The four shares are computed on this same base.
DMARC
One DMARC record at _dmarc.<domain>, read as RFC 7489 defines it. A policy is enforcing when it is quarantine or reject, applied to all failing mail (pct absent or 100). Every system of the census is a registrable domain, so the record read is that of its organizational domain.
SPF
One TXT record at the domain beginning with v=spf1 (RFC 7208, section 4.5). A domain publishing two has published none that a receiver applies.
DNSSEC
The resolver set the authenticated data flag (AD) on its answer about the domain: the chain of trust runs from the root down to the domain's zone, through the DS record its parent publishes.
Method version
Each point carries the version of the method in force on its date, currently version 1. Read the method
API
GET https://api.stileex.xyz/v1/series/br/dmarc-enforced-share/latest