Report ยท public DNS as of 24 September 2026
How many Euro Stoxx 50 companies can be spoofed by email?
3 of 50 have no DMARC policy preventing the domain of their corporate website from being used to send forged email.
Of the rest, 39 reject it and 8 send it to spam.
SPF, DMARC and DKIM for the domain of each company's corporate website, using the same methodology as the CyberEscudo auditor. Public records only: nobody was attacked or contacted.
Part of the Email Spoofing Observatory: compare it with other European indices โ
What protection they have
DMARC is the record a domain owner uses to tell receivers what to do with mail forging it. It decides whether someone can spoof it.
- Can be spoofed
- No effective DMARC policy: receivers are not asked to reject or set aside mail forging the domain.
- Partial protection
- quarantine with pct below 100: part of the forged mail arrives as if nothing happened.
- Goes to spam
- quarantine at 100% (or partial reject): forged mail ends up, at least, in the spam folder.
- Protected
- reject at 100%: receivers reject mail forging the domain.
Look up a company
We do not publish a ranking: look up the company you are interested in. Each result links to its live audit, which may have changed since 24 September 2026.
The lookup needs JavaScript. You can audit any domain with the email auditor.
The figures
Published DMARC policy
"No valid policy" covers not publishing DMARC, publishing several records (receivers apply none) or a policy that does not exist.
Overall grade
The grade adds SPF, DMARC and DKIM hygiene (for example, requesting rua reports), but never exceeds what DMARC allows: a protected company can get a B for those details, and there is no A without reject. How we score
Other indicators
- with strict SPF (-all): a single record, and every other server is not authorised
- 34 of 50
- request DMARC reports (rua): without them, the owner cannot see who tries to send on its behalf
- 48 of 50
- with DKIM detected, searched with 15 common selectors: not detected does not mean absent, and it does not lower the grade
- 42 of 50
- domains without an MX record: they do not seem to be used for email, but can still be put as the sender; the advice is "v=spf1 -all" and "p=reject"
- 2 of 50
Trend
The monthly series starts with this edition (September 2026). The next one is published in early October 2026, and this is where you will see whether it improves.
Methodology
- Sample
- The 50 Euro Stoxx 50 companies per its constituents table on Wikipedia (revision checked on 24 September 2026), which can be checked against the index provider's list. With the changes the provider announced later, which the table did not yet show: 21 September 2026: in: Engie and Nokia; out: Volkswagen and Wolters Kluwer. Wikipedia revision ยท index provider ยท change of 21 September 2026
- Which domain
- One domain per company: that of its corporate website, the group and investor relations site (not the retail one), as a registrable domain. Source: the official website in Wikidata checked against the Wikipedia infobox; where they differ or the group has its own site, its investor relations site wins, cited in the CSV. List of domains and sources (CSV)
- What is measured
- SPF, DMARC and DKIM with the email auditor engine, methodology 2026.2: the same weights, scale and caps you see when auditing your domain. How we score
- How
- Public DNS queries over DNS over HTTPS to Google Public DNS, on 24 September 2026 at 08:17 UTC. We never connect to the companies' servers: Google resolves the queries as it would for any user.
- Reproduce
- The snapshot keeps the records as they were and the engine reproduces every grade from them. Figures (JSON) ยท repeat any lookup today with the auditor
Limitations
- One domain per company, that of its corporate website. Its commercial brands may use others (in banking, the corporate website is not the customer one) and be better or worse protected.
- DKIM can only be searched for by known selectors: not detected does not mean it does not exist, which is why it does not lower the grade.
- It is a snapshot from 24 September 2026. A company may have changed its configuration since: the lookup links to the live audit.
- It is not an exploited vulnerability: it is public DNS configuration. No company was attacked, tested or contacted.
- "Can be spoofed" describes the domain's policy, not what every receiver does: some filter unauthenticated mail on their own.
For the press
If you cite the report, please give the source and the date of the data. A faithful wording:
"3 of 50 Euro Stoxx 50 companies have no DMARC policy preventing the domain of their corporate website from being used to send forged email." Source: CyberEscudo, Euro Stoxx 50 report (public DNS data as of 24 September 2026).
- Report card (PNG, 1200ร630)
- Figures (JSON) ยท analysed domains and their sources (CSV)
- Each company's result is in the lookup, with the date and the records as they were.
- Contact for interviews or more data
And your domain?
The same analysis, for yours, in seconds and without signing up. If something needs fixing, I can help you reach p=reject without losing legitimate mail.