Preskoči na sadržaj
Open dataset · CC BY 4.0

Croatian DMARC Barometer 2026

We queried the public DNS records of 6,259 Croatian domains and broke 1,159 of them down to policy level. This is the English summary of a Croatian-language report; the dataset, the full methodology and the CSV live on the original page.

Headline finding

Of the 555 domains in the deep sample that actually receive mail, only 12.1% (67 domains) publish a DMARC policy that rejects forged mail. Another 31.9% (177) publish no DMARC record at all.

DMARC policyDomainsShare
Actually blocks forged mail (p=reject)6712.1%
Sends forged mail to spam (p=quarantine)10919.6%
Has a record that does nothing (p=none)20236.4%
No DMARC record at all17731.9%

Denominator: n = 555, the domains in the deep sample with an MX record. These shares do not apply to the 6,259-domain sweep, which is a different set.

Local government is the weakest link

The two largest public-sector categories protect their domains least. Retail chains, by contrast, are the strongest group in the sample.

CategorynProtected
Cities1346%
Municipalities1184.2%
Companies8525.9%
Universities and faculties429.5%
Media2814.3%
Agencies and public bodies2718.5%
Retail chains2642.3%
Healthcare214.8%
State-owned companies195.3%
Insurers1414.3%
Banks1118.2%
Telecoms1020%

„Protected“ means a DMARC policy of p=reject. Cities: 6% of 134 · municipalities: 4.2% of 118 · retail chains: 42.3% of 26.

SPF is nearly universal — and half of it is toothless

SPF exists on 90.6% of the sample (503 domains), but only 49.9% use the strict -all form; 48.1% publish the soft ~all, which asks receiving servers to accept the mail anyway. DKIM signing was detected on 67.9% (377 domains).

Method, in short

Two measurements, deliberately kept apart. A broad sweep of 6,259 .hr domains found 2,613 (41.7%) with no DMARC record on any of four resolvers.

A deep sample of 1,159 named organisations was broken down to policy level; 555 of them have an MX record and form the denominator above. The two sets overlap in only 410 domains, so their percentages must never be combined.

The threshold is part of the number. MX records were queried on three resolvers and a domain counts as mail-receiving when a majority confirm it: 2,087 domains. Had all three been required, the figure would be 1,978; had any single resolver sufficed, 2,184. We publish the middle threshold and state it so the count can be reproduced.

Measured 2026-05-31, published 2026-08-10. Only public DNS records were read. No mail was sent, no system was logged into and nothing was changed.

The dataset

The aggregates behind this summary are published as a CSV under CC BY 4.0 — the same numbers shown here. No sign-up, no e-mail address. Individual domains and institutions are not named in the file.

Questions we get asked

How many Croatian domains actually block forged mail?

12.1% of the 555 domains in the deep sample that receive mail publish a DMARC policy of p=reject — 67 domains. These shares do not apply to the 6,259-domain sweep, which is a different set with its own denominator.

What counts as a domain that receives mail?

MX records were queried on three resolvers and a domain counts as mail-receiving when a majority confirm it: 2,087 domains. Had all three resolvers been required the figure would be 1,978; had any single one sufficed, 2,184. We publish the middle threshold and state it so the count can be reproduced.

May I republish these figures?

Yes, including commercially. The data is published under CC BY 4.0, which asks only for attribution: „Vi-Di.me — DMARC barometar Hrvatske 2026", with a link to https://vi-di.me/istrazivanje/email-sigurnost-2026. Ready-made citation formats are at the bottom of this page.

Were any mail servers contacted or messages sent?

No. Only public DNS records were read — MX, SPF, DKIM and DMARC. No message was sent, no system was logged into and nothing was changed. Individual domains and institutions are not named in the published file.

Which set does the CSV cover?

The CSV carries the aggregates behind both measurements, and every row states its own denominator in a separate column. That is deliberate: the broad sweep (6,259 domains) and the deep sample (1,159 organisations) overlap in only 410 domains, so their percentages must never be combined.

Cite this dataset

The data may be downloaded and republished with attribution. Two ready-made citation formats — copy the one that fits where you are writing.

Za znanstveni rad — BibTeX

Unos za LaTeX, Zotero ili Mendeley. Kopira se u .bib datoteku bez izmjena.

@dataset{vidime_dmarc_barometar_2026,
  author    = {{Vi-Di.me}},
  title     = {{DMARC barometar Hrvatske 2026: mjerenje SPF, DKIM i DMARC zapisa hrvatskih domena}},
  year      = {2026},
  publisher = {{Vi-Di.me, obrt za usluge}},
  url       = {https://vi-di.me/istrazivanje/email-sigurnost-2026},
  note      = {Skup podataka. Licenca CC BY 4.0}
}

In English — one line

For foreign press and researchers citing the dataset.

Vi-Di.me — DMARC barometar Hrvatske 2026 [Croatian DMARC Barometer 2026] (measured 2026-05-31, 6,259 .hr domains): https://vi-di.me/istrazivanje/email-sigurnost-2026

For a paper or report — APA

Full bibliographic record of the dataset, with URL and access date.

Vi-Di.me. (2026). DMARC barometar Hrvatske 2026 [Croatian DMARC Barometer 2026]: a measurement of SPF, DKIM and DMARC records on Croatian domains [Data set]. Vi-Di.me, obrt za usluge. https://vi-di.me/istrazivanje/email-sigurnost-2026