DMARC, SPF and DNSSEC in Brazil's federal government
The Stileex Domain Authentication Index (SDAI) reads the domains of the federal census every week: whether they publish the records that let a receiving mail server refuse a message forged in their name, and whether their DNS answers can be validated.
On 13/09/2026, 25.1 % of the 996 active federal domains publish a DMARC policy asking mail servers to quarantine or reject messages that fail authentication; 40.1 % publish a DMARC record, 61.2 % an SPF record, and 30.1 % have their DNS answers validated with DNSSEC.
Enforcing DMARC policy (quarantine or reject)
25.1 %
Over 996 active domains.
DMARC record published
40.1 %
Over 996 active domains.
SPF record published
61.2 %
Over 996 active domains.
DNS answers validated with DNSSEC
30.1 %
Over 996 active domains.
DMARC, policy by policy
The 996 active domains of the census, by the DMARC policy published at _dmarc.<domain>. The first two rows make up the headline figure.
| Policy | Domains | Share |
|---|---|---|
| Reject (p=reject) | 85 | 8.5 % |
| Quarantine (p=quarantine) | 165 | 16.6 % |
| Quarantine or reject applied to part of the mail (pct under 100) | 25 | 2.5 % |
| Monitoring (p=none) | 124 | 12.4 % |
| A record no receiver applies (two records, or no readable policy) | 4 | 0.4 % |
| No DMARC record | 593 | 59.5 % |
A DMARC policy tells receiving mail servers what to do with a message that carries the domain in its From address and fails SPF and DKIM authentication: deliver it and report, quarantine it, or reject it.
Domains that receive mail, and those that do not
| Mail exchangers (MX) | Domains | Enforcing DMARC policy |
|---|---|---|
| The domain declares a mail exchanger | 539 | 40.4 % (218) |
| The domain declares none | 457 | 7.0 % (32) |
A domain that receives no mail can still appear in the From address of a message. For such a domain, mail security guides describe an SPF record authorising no server (v=spf1 -all) and a DMARC policy of reject.
SPF records
How the SPF record of each active domain ends: what it asks a receiving server to do with mail from a server the record does not list.
| Ending | Domains | Share |
|---|---|---|
| -all: fail the mail of any unlisted server | 419 | 42.1 % |
| ~all: accept it, marked as suspicious | 173 | 17.4 % |
| ?all: take no position | 13 | 1.3 % |
| redirect: another domain's record decides | 2 | 0.2 % |
| No all mechanism | 3 | 0.3 % |
| Two SPF records or more, which no receiver applies | 7 | 0.7 % |
| No SPF record | 379 | 38.1 % |
DNSSEC
A domain counts as validated when the resolver authenticated its answer along a chain of trust running from the root of the DNS down to the domain's zone.
| Zone | Domains | Share |
|---|---|---|
| Answers validated with DNSSEC | 300 | 30.1 % |
| Answers without DNSSEC validation | 696 | 69.9 % |
104 of the 996 active domains (10.4 %) combine all three: an enforcing DMARC policy, an SPF record and DNS answers validated with DNSSEC.
The census, domain by domain
The 1,624 systems of the census, read on the day of the figures, by the state their domain was found in. The shares above are computed on the active domains.
| State | Domains |
|---|---|
| Active: the domain exists and its zone answers | 996 |
| The domain no longer exists (NXDOMAIN) | 355 |
| The domain's zone does not answer | 242 |
| No answer obtained that day | 31 |
Among the zones that do not answer, 10 carry DNSSEC signatures that do not verify: they answer once validation is set aside.
What these three records do
SPF (RFC 7208) lists the servers allowed to send mail for a domain. DKIM signs each message with a key the domain publishes. DMARC (RFC 7489) ties the two to the address a reader sees, and tells receiving servers what to do with a message that fails: deliver it and report, quarantine it, or reject it. A policy of quarantine or reject is the one that asks a receiver to act.
DNSSEC signs the answers of the DNS itself, so that a validating resolver can tell an authentic answer from a forged one. It covers every record a domain publishes, its SPF and DMARC records included.
The same census is read by two other Stileex indices: hosting sovereignty · public cloud
How it is measured
- Census
- %systems% federal systems: the 1,610 domains of the gov.br register the Secretaria de Governo Digital publishes on dados.gov.br, plus the federal institutions outside that zone (.jus.br, .leg.br, .mil.br, .mp.br). It is the census of the hosting sovereignty index.
- Cadence
- One campaign a week, on Sundays: each point is dated on the day the domains were read.
- Reading
- Five questions per domain on the public resolver 1.1.1.1, which validates DNSSEC: NS (and the validation flag of its answer), DS, TXT at _dmarc.<domain>, TXT at the domain, MX. A domain that no longer exists is asked the first one alone.
- Base
- The active domains: those that exist and whose zone answered the five questions. The four shares are computed on this same base.
- DMARC
- One DMARC record at _dmarc.<domain>, read as RFC 7489 defines it. A policy is enforcing when it is quarantine or reject, applied to all failing mail (pct absent or 100). Every system of the census is a registrable domain, so the record read is that of its organizational domain.
- SPF
- One TXT record at the domain beginning with v=spf1 (RFC 7208, section 4.5). A domain publishing two has published none that a receiver applies.
- DNSSEC
- The resolver set the authenticated data flag (AD) on its answer about the domain: the chain of trust runs from the root down to the domain's zone, through the DS record its parent publishes.
- Method version
- Each point carries the version of the method in force on its date, currently version 1. Read the method
- API
GET https://api.stileex.xyz/v1/series/br/dmarc-enforced-share/latest