Croatian DMARC Barometer 2026
We queried the public DNS records of 6,259 Croatian domains and broke 1,159 of them down to policy level. This is the English summary of a Croatian-language report; the dataset, the full methodology and the CSV live on the original page.
Headline finding
Of the 555 domains in the deep sample that actually receive mail, only 12.1% (67 domains) publish a DMARC policy that rejects forged mail. Another 31.9% (177) publish no DMARC record at all.
| DMARC policy | Domains | Share |
|---|---|---|
| Actually blocks forged mail (p=reject) | 67 | 12.1% |
| Sends forged mail to spam (p=quarantine) | 109 | 19.6% |
| Has a record that does nothing (p=none) | 202 | 36.4% |
| No DMARC record at all | 177 | 31.9% |
Denominator: n = 555, the domains in the deep sample with an MX record. These shares do not apply to the 6,259-domain sweep, which is a different set.
Local government is the weakest link
The two largest public-sector categories protect their domains least. Retail chains, by contrast, are the strongest group in the sample.
| Category | n | Protected |
|---|---|---|
| Cities | 134 | 6% |
| Municipalities | 118 | 4.2% |
| Companies | 85 | 25.9% |
| Universities and faculties | 42 | 9.5% |
| Media | 28 | 14.3% |
| Agencies and public bodies | 27 | 18.5% |
| Retail chains | 26 | 42.3% |
| Healthcare | 21 | 4.8% |
| State-owned companies | 19 | 5.3% |
| Insurers | 14 | 14.3% |
| Banks | 11 | 18.2% |
| Telecoms | 10 | 20% |
„Protected“ means a DMARC policy of p=reject. Cities: 6% of 134 · municipalities: 4.2% of 118 · retail chains: 42.3% of 26.
SPF is nearly universal — and half of it is toothless
SPF exists on 90.6% of the sample (503 domains), but only 49.9% use the strict -all form; 48.1% publish the soft ~all, which asks receiving servers to accept the mail anyway. DKIM signing was detected on 67.9% (377 domains).
Method, in short
Two measurements, deliberately kept apart. A broad sweep of 6,259 .hr domains found 2,613 (41.7%) with no DMARC record on any of four resolvers.
A deep sample of 1,159 named organisations was broken down to policy level; 555 of them have an MX record and form the denominator above. The two sets overlap in only 410 domains, so their percentages must never be combined.
The threshold is part of the number. MX records were queried on three resolvers and a domain counts as mail-receiving when a majority confirm it: 2,087 domains. Had all three been required, the figure would be 1,978; had any single resolver sufficed, 2,184. We publish the middle threshold and state it so the count can be reproduced.
Measured 2026-05-31, published 2026-08-10. Only public DNS records were read. No mail was sent, no system was logged into and nothing was changed.
The dataset
The aggregates behind this summary are published as a CSV under CC BY 4.0 — the same numbers shown here. No sign-up, no e-mail address. Individual domains and institutions are not named in the file.
Questions we get asked
How many Croatian domains actually block forged mail?
12.1% of the 555 domains in the deep sample that receive mail publish a DMARC policy of p=reject — 67 domains. These shares do not apply to the 6,259-domain sweep, which is a different set with its own denominator.
What counts as a domain that receives mail?
MX records were queried on three resolvers and a domain counts as mail-receiving when a majority confirm it: 2,087 domains. Had all three resolvers been required the figure would be 1,978; had any single one sufficed, 2,184. We publish the middle threshold and state it so the count can be reproduced.
May I republish these figures?
Yes, including commercially. The data is published under CC BY 4.0, which asks only for attribution: „Vi-Di.me — DMARC barometar Hrvatske 2026", with a link to https://vi-di.me/istrazivanje/email-sigurnost-2026. Ready-made citation formats are at the bottom of this page.
Were any mail servers contacted or messages sent?
No. Only public DNS records were read — MX, SPF, DKIM and DMARC. No message was sent, no system was logged into and nothing was changed. Individual domains and institutions are not named in the published file.
Which set does the CSV cover?
The CSV carries the aggregates behind both measurements, and every row states its own denominator in a separate column. That is deliberate: the broad sweep (6,259 domains) and the deep sample (1,159 organisations) overlap in only 410 domains, so their percentages must never be combined.
Cite this dataset
The data may be downloaded and republished with attribution. Two ready-made citation formats — copy the one that fits where you are writing.
Za znanstveni rad — BibTeX
Unos za LaTeX, Zotero ili Mendeley. Kopira se u .bib datoteku bez izmjena.
@dataset{vidime_dmarc_barometar_2026,
author = {{Vi-Di.me}},
title = {{DMARC barometar Hrvatske 2026: mjerenje SPF, DKIM i DMARC zapisa hrvatskih domena}},
year = {2026},
publisher = {{Vi-Di.me, obrt za usluge}},
url = {https://vi-di.me/istrazivanje/email-sigurnost-2026},
note = {Skup podataka. Licenca CC BY 4.0}
}In English — one line
For foreign press and researchers citing the dataset.
Vi-Di.me — DMARC barometar Hrvatske 2026 [Croatian DMARC Barometer 2026] (measured 2026-05-31, 6,259 .hr domains): https://vi-di.me/istrazivanje/email-sigurnost-2026
For a paper or report — APA
Full bibliographic record of the dataset, with URL and access date.
Vi-Di.me. (2026). DMARC barometar Hrvatske 2026 [Croatian DMARC Barometer 2026]: a measurement of SPF, DKIM and DMARC records on Croatian domains [Data set]. Vi-Di.me, obrt za usluge. https://vi-di.me/istrazivanje/email-sigurnost-2026