Observatory ยท data from September 2026

Can Europe's largest listed companies be spoofed by email?

47 of 226 have no DMARC policy preventing the domain of their corporate website from being used to send forged email.

Of the rest, 137 reject it, 39 send it to spam and 3 only partly set it aside.

The companies in 5 stock indices (IBEX 35, Euro Stoxx 50, FTSE 100, DAX 40 and CAC 40), measured every month with the same engine as the CyberEscudo auditor. A company listed in two indices counts once. Public records only: nobody was attacked or contacted.

Index by index

Each index has its own size: compare the percentages, not the counts.

Can be spoofed

Protected

Can be spoofed
No effective DMARC policy: receivers are not asked to reject or set aside mail forging the domain.
Protected
reject at 100%: receivers reject mail forging the domain.

The reports

Each report has its methodology, its limitations, the full figures and a per-company lookup.

How it is done

What is measured
SPF, DMARC and DKIM for the domain of each company's corporate website, with the email auditor engine: the same weights, scale and caps you see when auditing your domain. How we score
When
One edition a month per index, with public DNS queries to Google Public DNS. A published edition is never rewritten and keeps the methodology of its time: if the methodology changes, it shows in the next edition, not in past ones.
Which companies
Each index's composition on the date of its edition, with the source cited in each report. The domain is that of the corporate website, and each comes with its source in the CSV.
Companies in several indices
They count in every index they belong to, but only once in this page's total, with their latest measurement.

For the press

If you cite the observatory, please give the source and the date of the data. A faithful wording:

"47 of the 226 large European listed companies in the IBEX 35, Euro Stoxx 50, FTSE 100, DAX 40 and CAC 40 indices have no DMARC policy preventing the domain of their corporate website from being used to send forged email." Source: CyberEscudo, Email Spoofing Observatory (data from September 2026).

And your domain?

The same analysis, for yours, in seconds and without signing up. If something needs fixing, I can help you reach p=reject without losing legitimate mail.

Audit your domain Let's talk