All articles
S&P 500 email security: not one domain scored above a C
Case Studies

S&P 500 email security: not one domain scored above a C

We scanned every S&P 500 domain for SPF, DMARC, MTA-STS, DANE, and DNSSEC. Not one earned an A or a B - here's what the biggest companies get right, and skip.

The S&P 500 is shorthand for serious money and serious IT - 500 of the most valuable companies on earth, the ones you'd bet on to get the basics right.

So we tested that bet. SecRift scanned every domain in the index from the outside - no warning, no inside access, just the public signals any attacker can read - and graded each one exactly the way it grades any domain at secrift.com.

Corporate America did not ace it.

Five hundred household names. Not one earned an A or a B.

E

median grade across the cohort

0

domains that earned an A or a B

C

the best grade anyone reached

94%

domains hard-capped at C by one critical finding

How we did it. One scan per domain on 2026-06-22, from the same engine, with no notice and no special access - exactly what an outsider sees. Scores reflect public DNS and mail setup only, nothing internal.

The 10 that came closest

These are the best-configured domains in the index. Look at the grade column: every one of them is a C. That is not a fluke - it is a ceiling, and we will get to why.

What they nailed, and what they skipped

Here is the surprising part: the S&P 500 is not careless. It is lopsided. The control everyone has heard of - the one that stops criminals from emailing the world as you - is in great shape. The quiet machinery that protects your mail in transit is almost untouched.

Nearly 9 in 10 of these companies enforce DMARC: they have told inbound mail servers to bin anything impersonating them. For anti-spoofing, that is the gold standard - and the index mostly clears it.

DMARC policy across the cohort

341p=reject96p=quarantine50p=none (monitor only)11missing or invalid

Enforcement is the cohort's real strength: nearly 9 in 10 domains publish quarantine or reject.

SPF is where the nerves show. Half the index runs a strict -all that hard-rejects forgeries. The other half hedges with ~all, which flags a fake but still lets it through - the safe choice when dozens of services send your mail and you cannot risk blocking your own.

SPF policy terminator

231-all (hard fail)234~all (soft fail)19neutral or no terminator14missing or invalid

~all (soft fail) is as common as -all (hard fail). Most large senders play it safe.

Then there is the part almost nobody touches.

97%

publish no MTA-STS policy

95%

publish no TLS-RPT reporting record

90%

have DNSSEC switched off

88%

leave inbound mail unprotected by DANE

That last number is the one that quietly caps everybody. Hold that thought.

The 10 at the bottom

At the other end, things fall apart - records missing, duplicated, or contradicting each other. Every domain here scored an F.

CrowdStrike won, and still couldn't crack a B

If anyone should run the table, it is a cybersecurity company - and CrowdStrike tops the index at 89 out of 100. On raw points, that is a B. The grade still reads C. Welcome to the ceiling.

CrowdStrike did almost everything right. MTA-STS in enforce mode, perfect. TLS-RPT, perfect. DNSSEC fully signed on the domain. DMARC at the strictest setting. A near-flawless sheet.

Two tiny things nibble at the score: SPF ends in ~all instead of a strict -all, and DMARC uses relaxed alignment. Fix both and the number climbs. The grade will not budge - because of this:

No MX host TLSA zone is protected by DNSSEC. CrowdStrike's inbound mail runs through Proofpoint (mx*.pphosted.com). DANE for SMTP needs the mail host's zone to be DNSSEC-signed so its TLSA records can be trusted - and that zone belongs to the provider, not to CrowdStrike.

One critical finding pins the grade to C, full stop, no matter how high the score goes. The kicker: the missing piece lives in Proofpoint's DNS, not CrowdStrike's. The best-configured domain in the S&P 500 is held back by something it does not even control.

APA Corporation came last by trying twice

Dead last at 29 out of 100 is APA Corporation - and the twist is that APA tried. The SPF record exists. It is just doubled.

APA publishes two separate SPF records - and no DMARC at all. Here is the rule nobody warns you about: two records count as none. Mail servers see the duplicate SPF, give up, and apply no protection at all - so on paper APA authorizes its senders, and in practice it authorizes nobody. With DMARC missing too, nothing is left to catch the gap.

The pattern. This is not neglect - it is fragmentation. One team pointed SPF at Microsoft 365, another bolted on a second record full of mail-server IPs, and nobody merged them. The fix is mechanical: collapse to exactly one SPF record, publish a single DMARC policy, and the score jumps the moment the duplicate is gone.

And that is before the rest: no MTA-STS, no TLS-RPT, no DANE, DNSSEC off. Here is the full scorecard.

0/100

SPF - two separate records

20/100

DMARC - no record at all

20/100

MTA-STS - no policy

20/100

TLS-RPT - no record

33/100

DANE - MX not DNSSEC-signed

50/100

DNSSEC - disabled

Merging the SPF records and publishing one DMARC policy is a five-minute fix. Everything after that is a roadmap.

Why everyone hits the same wall

Six findings repeat across hundreds of the biggest companies in America, and a few simple reasons explain almost all of it.

Why nobody beats a C. It is not effort - it is physics. 88% of the index fails the same DANE check CrowdStrike did: the mail host's zone is not signed with DNSSEC, so DANE cannot work. Most of these companies outsource email to Proofpoint, Mimecast, or Microsoft 365, and those providers do not sign their mail zones. Until they do, their customers literally cannot deploy DANE, and that one critical finding caps the whole index at C.

Why DNSSEC stays off (90%). DNSSEC signs your DNS, but a botched key change does not fail gracefully - it can take your entire domain offline. When your domain is your business, the risk of self-inflicted downtime outweighs the upside. So the biggest brands treat it as a third rail.

Why SPF leans soft (~all on nearly half). A strict -all tells servers to reject anything not on the list. Forget one of your dozens of senders and you are blocking your own invoices. Soft fail ~all never does that - and with DMARC already enforcing, it is DMARC making the real call anyway.

The takeaway. The S&P 500 won the loud battle - stopping impersonation - and has barely started the quiet one: encrypting mail in transit. MTA-STS, TLS-RPT, and DANE adoption all sit in the single digits. The giants stopped the spoofers. They just have not locked the pipe yet.

How does your domain score?

SecRift checks SPF, DMARC, MTA-STS, TLS-RPT, DANE, and DNSSEC, then hands you a client-ready report in seconds. See where you land against the S&P 500.

Run a free scan