Report ยท public DNS as of 23 September 2026

How many IBEX 35 companies can be spoofed by email?

11 of 35 have no DMARC policy preventing the domain of their corporate website from being used to send forged email.

Of the rest, 20 reject it and 4 send it to spam.

SPF, DMARC and DKIM for the domain of each company's corporate website, using the same methodology as the CyberEscudo auditor. Public records only: nobody was attacked or contacted.

What protection they have

DMARC is the record a domain owner uses to tell receivers what to do with mail forging it. It decides whether someone can spoof it.

Can be spoofed
No effective DMARC policy: receivers are not asked to reject or set aside mail forging the domain.
Partial protection
quarantine with pct below 100: part of the forged mail arrives as if nothing happened.
Goes to spam
quarantine at 100% (or partial reject): forged mail ends up, at least, in the spam folder.
Protected
reject at 100%: receivers reject mail forging the domain.

Look up a company

We do not publish a ranking: look up the company you are interested in. Each result links to its live audit, which may have changed since 23 September 2026.

The lookup needs JavaScript. You can audit any domain with the email auditor.

The figures

Published DMARC policy

"No valid policy" covers not publishing DMARC, publishing several records (receivers apply none) or a policy that does not exist.

Overall grade

The grade adds SPF, DMARC and DKIM hygiene (for example, requesting rua reports), but never exceeds what DMARC allows: a protected company can get a B for those details, and there is no A without reject. How we score

Other indicators

with strict SPF (-all): a single record, and every other server is not authorised
29 of 35
request DMARC reports (rua): without them, the owner cannot see who tries to send on its behalf
29 of 35
with DKIM detected, searched with 15 common selectors: not detected does not mean absent, and it does not lower the grade
26 of 35
domains without an MX record: they do not seem to be used for email, but can still be put as the sender; the advice is "v=spf1 -all" and "p=reject"
3 of 35

Methodology

Sample
The 35 IBEX 35 companies per the official BME composition. Last change: 22 July 2024; no review has changed it since (the latest in BME's table is dated 21 September 2026). BME history (PDF)
Which domain
One domain per company: that of its corporate website, the shareholders and investors site (for Spanish listed companies, the one required by art. 11 bis of the Spanish Companies Act; ArcelorMittal and Ferrovial are based outside Spain), without subdomains. Source: Wikidata (official website) checked against a search engine; where they differ, the shareholders site wins. In banking, the corporate website is not the retail one. List of domains and sources (CSV)
What is measured
SPF, DMARC and DKIM with the email auditor engine, methodology 2026.2: the same weights, scale and caps you see when auditing your domain. How we score
How
Public DNS queries over DNS over HTTPS to Google Public DNS, on 23 September 2026 at 13:23 UTC. We never connect to the companies' servers: Google resolves the queries as it would for any user.
Reproduce
The snapshot keeps the records as they were and the engine reproduces every grade from them. Figures (JSON) ยท repeat any lookup today with the auditor

Limitations

For the press

If you cite the report, please give the source and the date of the data. A faithful wording:

"11 of 35 IBEX 35 companies have no DMARC policy preventing the domain of their corporate website from being used to send forged email." Source: CyberEscudo, IBEX 35 report (public DNS data as of 23 September 2026).

And your domain?

The same analysis, for yours, in seconds and without signing up. If something needs fixing, I can help you reach p=reject without losing legitimate mail.

Audit your domain Let's talk