ViKeLaAi logo ViKeLaAi Research
Report 2 / Email Authentication

Email Security Across the Supply Chain Behind DoD's Next 15 Months of Contract Recompetes

Quarterly public-signal view of DMARC posture across prime contractors with DoD-linked contracts expiring in the next 15 months and the supply-chain companies connected to them.

Updated September 19, 2026 Quarterly refresh Public-signal analysis only
69%
Enforcing DMARC
1,213 of 1,770 observed companies publish an enforcing DMARC posture: 1,157 with explicit reject/quarantine and 56 with enforcement inferred but policy variant unspecified.
18%
p=none still present
321 observed companies still expose email spoofing risk through non-enforcing policy.
0%
No DMARC record observed
0 observed companies resolved to no DMARC record on the checked primary domain.
71%
DoD-linked supplier base
Companies whose top observed buyer is DoD, a service branch, or a defense agency show 71% enforcing DMARC across 562 observed contractors; this aggregate is broader than the single Department of Defense row in the agency table.

Supply-Chain Spoofing Signals

Observed DMARC outcomes
Spoofing Exposure Mix
Enforcing69%
p=none18%
Present / unclassified13%
No record0%

557 observed companies are still outside clear DMARC enforcement.

Role-based enforcement
Contract Chain
Prime with expiring contract71%
Connected supply-chain company with direct awards71%
Supply-chain company without direct awards67%

Compares expiring primes with connected suppliers using the same observed-DMARC denominator.

Buyer ecosystem
DoD-Linked Supplier Base
71%
enforcing DMARC

562 observed companies have DoD, a service branch, or a defense agency as their top observed buyer; the table below lists those buyer rows separately.

Industry risk map
Capability Segments
Software Development73%
Aerospace & Defense76%
IT Infrastructure & Services73%
Cybersecurity Services80%

Shows where email authentication risk concentrates by supplier market, not just by company count.

Spoofing risk is most useful when it is read through the contract chain. A non-enforcing DMARC posture at a connected supplier is not just an email hygiene issue; it can become believable impersonation surface around teaming, invoicing, onboarding, and recompete communications.

The DoD-linked portion of this sample gives the report its sharper sales value: it connects observable email-authentication posture to buyer ecosystems, expiring prime contracts, supplier relationships, and capability segments instead of treating every company as an isolated domain.

The industry view is the strongest prospecting lens. Capability segments with lower enforcement or larger no-record populations are better campaign targets because the story is concrete: these are the supplier markets where spoofed procurement and vendor communications can blend into ordinary contract activity.

Where supplier email exposure concentrates

This view links email authentication to the actual buying ecosystem: which supplier bases enforce DMARC, which capability segments lag, and where spoofing exposure can still sit behind recompetes.

Spoofing risk follows the contract chain

The same email control gap looks different when it sits behind a recompete, a prime/sub relationship, or a buyer-linked supplier base. This graph connects buyer exposure, supplier role, industry segment, and DMARC posture.

Buyer Ecosystem
71%
DoD-linked aggregate (562 observed companies with DoD, service-branch, or defense-agency top-buyer assignment)
Expiring Primes
377
observed companies with contracts in the 15-month recompete window
Connected Suppliers
1,393
observed companies linked through supply-chain relationships
Full-Sample Exposure
31%
557 observed companies across the full sample are p=none, unclassified, or no-record
Software Development
73%
enforcing DMARC in the largest capability segment

DMARC Distribution Across the Cohort

Enforcing DMARC 69% · 1,213
These domains publish reject, quarantine, or an enforcement-derived DMARC signal that is harder to spoof successfully at scale.
p=none 18% · 321
These domains still advertise monitoring mode, which leaves procurement and supplier impersonation risk more exposed.
Present / unclassified 13% · 236
A DMARC record exists, but the stored signal does not cleanly resolve to enforcement or monitor-only behavior.
No DMARC record observed 0% · 0
These domains resolved to a scan result that explicitly found no DMARC record on the primary domain.

Spoofing-Risk Reading

Spoofing Exposure
31% of the full observed sample still sits outside clear enforcement.

Between published p=none (18%) and present-but-unclassified DMARC records (13%), plus domains with no DMARC record observed (0%), a large slice of the contractor base still leaves room for supplier and invoice-spoofing campaigns to blend in.

Buyer Impact
DoD-linked supplier base shows 71% DMARC enforcement where DoD is the top observed buyer.

That aggregate covers 562 observed companies assigned to DoD, a military service branch, or a defense agency as their top observed buyer. The agency table keeps those components as separate line items, so its single Department of Defense row is narrower than this aggregate.

Data Fusion
The value is in linking posture to buyers, industries, and supply-chain roles.

The distribution is calculated on observed DMARC rows, then broken out by procurement agency, company role, award footprint, and industry so the story is about where exposure sits, not just whether a TXT record exists.

Buyer-Linked Supplier Bases by Enforcing Share

Department of Defense 71% · 533 observed
Department of Veterans Affairs 69% · 42 observed
National Aeronautics and Space Administration 64% · 25 observed
Department of Health and Human Services 78% · 18 observed
Public Buildings Service 50% · 14 observed

Industry / Capability Enforcement Map

Software Development 73% enforcing · 155 observed
p=none 11% · other observed state 16%
Aerospace & Defense 76% enforcing · 147 observed
p=none 15% · other observed state 9%
IT Infrastructure & Services 73% enforcing · 147 observed
p=none 12% · other observed state 15%
Cybersecurity Services 80% enforcing · 101 observed
p=none 10% · other observed state 10%
Telecommunications 63% enforcing · 83 observed
p=none 17% · other observed state 20%
Consulting & Advisory 55% enforcing · 77 observed
p=none 18% · other observed state 27%

Report Tables

Overall DMARC Distribution

Distribution across 1,770 companies with observed DMARC posture in the sampled DoD recompete and supply-chain company set.

Download CSV
DMARC stateObserved companiesShare of observed
Reject66938%
Quarantine48828%
Enforced / policy variant unspecified563%
None32118%
Present / unclassified23613%
No DMARC record observed00%

Agency Cohort Breakout

Contextual agency view. Companies are in this report because of the DoD recompete/supply-chain sample; defense components are listed separately here, while the hero DoD-linked metric combines DoD, service branches, and defense agencies.

Download CSV
Top buying agencyObserved contractorsEnforcing DMARCp=none
Department of Defense53371%14%
Department of Veterans Affairs4269%19%
National Aeronautics and Space Administration2564%16%
Department of Health and Human Services1878%22%
Public Buildings Service1450%29%
Department of Homeland Security1173%27%
Department of the Navy1173%18%
Federal Acquisition Service1060%0%

Prime vs Supply-Chain Breakout

Observed DMARC posture split by companies with DoD-linked contracts expiring in the next 15 months and connected supply-chain companies.

Download CSV
Company roleObserved companiesEnforcing DMARCp=none
Prime with expiring contract37771%14%
Connected supply-chain company with direct awards47371%13%
Supply-chain company without direct awards92067%22%

Direct Award vs Supply-Chain-Only Breakout

Separates companies with direct federal awards from relationship-only supply-chain companies that do not have direct award value in this local dataset.

Download CSV
Award relationshipObserved companiesEnforcing DMARCp=none
Companies with direct federal awards85071%14%
Supply-chain companies without direct awards92067%22%

Industry / Capability Breakout

Observed DMARC posture grouped by NAICS description or research-derived industry tags, connecting email security to supplier markets and capabilities.

Download CSV
Industry or capabilityObserved companiesEnforcing DMARCp=noneOther observed state
Software Development15573%11%16%
Aerospace & Defense14776%15%9%
IT Infrastructure & Services14773%12%15%
Cybersecurity Services10180%10%10%
Telecommunications8363%17%20%
Consulting & Advisory7755%18%27%
Construction & Infrastructure7163%20%17%
Engineering Services5383%9%8%
Commercial & Institutional Building Construction4459%23%18%
Electronics Manufacturing4269%12%19%

Contractor Size Breakout

Breakout by direct federal award footprint for companies with award value in the current database snapshot.

Download CSV
Award-footprint bandObserved contractorsEnforcing DMARCp=none
$1B+4770%19%
$100M-$1B14271%15%
$10M-$100M24264%19%
Under $10M1,33969%18%

Average Award Size Breakout

Breakout by average observed contract size for contractors with current contract data.

Download CSV
Average award bandObserved contractorsEnforcing DMARCp=none
$50M+ avg award450%25%
$5M-$50M avg award5876%16%
$500K-$5M avg award23869%18%
Under $500K avg award1,47068%18%

Want the company-level list behind this sample, including domain evidence and supply-chain context?

Request the full dataset

How This Report Was Calculated

  • Cohort is a local analytical sample, not a census of all federal contractors. It combines companies with DoD-linked contracts expiring in the next 15 months and supply-chain organizations connected through FPDS/USASpending subaward records, mined teaming/subcontractor relationships, and company-research supply-chain partner data.
  • The 15-month recompete window is calculated from contract end_date values in the local contracts table using records whose end date falls between the report generation date and date('now', '+15 months'). Option periods and future extensions are only reflected when already present in the loaded contract record.
  • DMARC state is resolved from company security_signals, the latest passive dns_email_security scan, and fingerprint-derived indicators, then bucketed as reject, quarantine, enforced-unspecified, none, present-unclassified, no-record-observed, or unknown.
  • Passive dns_email_security results are treated as recent authoritative checks for 180 days; stale passive evidence is kept in unknown rather than counted as no-record.
  • Agency breakout uses the contractor's highest-concentration buying agency from current contract records rather than all agencies equally.
  • Explicit no-record findings require an authoritative checked signal, while missing, stale, or non-authoritative evidence stays separate as not yet observed.

Need the scoring definitions behind contractor profiles?

Read methodology

Important Limits

  • This is a public-signal observation of primary contractor domains, not a mail-flow validation or legal compliance assessment.
  • This sample is tied to the expiring-contract and connected supply-chain population in the local database and should not be read as representative of the full federal contractor base.
  • Subsidiary, alternate, and campaign domains may have different DMARC posture than the primary domain represented here.
  • Agency assignment is simplified to the contractor's top current buying relationship for readability, so multi-agency exposure is compressed.
  • Cohort ranking depends on the local contract dataset loaded into this instance and can shift as contract ingestion improves.