Report ยท public DNS as of 23 September 2026
How many IBEX 35 companies can be spoofed by email?
11 of 35 have no DMARC policy preventing the domain of their corporate website from being used to send forged email.
Of the rest, 20 reject it and 4 send it to spam.
SPF, DMARC and DKIM for the domain of each company's corporate website, using the same methodology as the CyberEscudo auditor. Public records only: nobody was attacked or contacted.
What protection they have
DMARC is the record a domain owner uses to tell receivers what to do with mail forging it. It decides whether someone can spoof it.
- Can be spoofed
- No effective DMARC policy: receivers are not asked to reject or set aside mail forging the domain.
- Partial protection
- quarantine with pct below 100: part of the forged mail arrives as if nothing happened.
- Goes to spam
- quarantine at 100% (or partial reject): forged mail ends up, at least, in the spam folder.
- Protected
- reject at 100%: receivers reject mail forging the domain.
Look up a company
We do not publish a ranking: look up the company you are interested in. Each result links to its live audit, which may have changed since 23 September 2026.
The lookup needs JavaScript. You can audit any domain with the email auditor.
The figures
Published DMARC policy
"No valid policy" covers not publishing DMARC, publishing several records (receivers apply none) or a policy that does not exist.
Overall grade
The grade adds SPF, DMARC and DKIM hygiene (for example, requesting rua reports), but never exceeds what DMARC allows: a protected company can get a B for those details, and there is no A without reject. How we score
Other indicators
- with strict SPF (-all): a single record, and every other server is not authorised
- 29 of 35
- request DMARC reports (rua): without them, the owner cannot see who tries to send on its behalf
- 29 of 35
- with DKIM detected, searched with 15 common selectors: not detected does not mean absent, and it does not lower the grade
- 26 of 35
- domains without an MX record: they do not seem to be used for email, but can still be put as the sender; the advice is "v=spf1 -all" and "p=reject"
- 3 of 35
Methodology
- Sample
- The 35 IBEX 35 companies per the official BME composition. Last change: 22 July 2024; no review has changed it since (the latest in BME's table is dated 21 September 2026). BME history (PDF)
- Which domain
- One domain per company: that of its corporate website, the shareholders and investors site (for Spanish listed companies, the one required by art. 11 bis of the Spanish Companies Act; ArcelorMittal and Ferrovial are based outside Spain), without subdomains. Source: Wikidata (official website) checked against a search engine; where they differ, the shareholders site wins. In banking, the corporate website is not the retail one. List of domains and sources (CSV)
- What is measured
- SPF, DMARC and DKIM with the email auditor engine, methodology 2026.2: the same weights, scale and caps you see when auditing your domain. How we score
- How
- Public DNS queries over DNS over HTTPS to Google Public DNS, on 23 September 2026 at 13:23 UTC. We never connect to the companies' servers: Google resolves the queries as it would for any user.
- Reproduce
- The snapshot keeps the records as they were and the engine reproduces every grade from them. Figures (JSON) ยท repeat any lookup today with the auditor
Limitations
- One domain per company, that of its corporate website. Its commercial brands may use others (in banking, the corporate website is not the customer one) and be better or worse protected.
- DKIM can only be searched for by known selectors: not detected does not mean it does not exist, which is why it does not lower the grade.
- It is a snapshot from 23 September 2026. A company may have changed its configuration since: the lookup links to the live audit.
- It is not an exploited vulnerability: it is public DNS configuration. No company was attacked, tested or contacted.
- "Can be spoofed" describes the domain's policy, not what every receiver does: some filter unauthenticated mail on their own.
For the press
If you cite the report, please give the source and the date of the data. A faithful wording:
"11 of 35 IBEX 35 companies have no DMARC policy preventing the domain of their corporate website from being used to send forged email." Source: CyberEscudo, IBEX 35 report (public DNS data as of 23 September 2026).
- Report card (PNG, 1200ร630)
- Figures (JSON) ยท analysed domains and their sources (CSV)
- Each company's result is in the lookup, with the date and the records as they were.
- Contact for interviews or more data
And your domain?
The same analysis, for yours, in seconds and without signing up. If something needs fixing, I can help you reach p=reject without losing legitimate mail.