Executive Summary

2 Domains Scanned
81.0 Average Score
B- Average Grade

The Fortune 500 Email Security Report shows above-average email security posture with an average score of 81.0 across 2 domains scanned. While most enterprises have deployed core authentication protocols, gaps in enforcement policies and advanced protocol adoption prevent many from achieving top-tier grades. The data reveals a clear divide between organizations that treat email security as a priority and those still relying on minimal configurations.

Grade Distribution

Distribution of email security grades across 2 scanned Fortune 500 Email Security Report domains.

Protocol Adoption

Percentage of Fortune 500 Email Security Report domains with each email security protocol correctly configured.

Pillar Breakdown

Average scores across the three DoSPM pillars for all scanned Fortune 500 Email Security Report domains.

Top Performers

The 10 highest-scoring Fortune 500 Email Security Report domains by overall email security posture.

# Domain Grade Score Identity Shadow Reputation
1 google.com B+ 87 72 92 96
2 amazon.com C 75 66 60 100

Common Vulnerabilities

The 10 most frequent critical and high severity failures across 2 scanned Fortune 500 Email Security Report domains.

# Failure Severity Domains % Affected
1 No NS records found critical 1 50.0%
2 Cannot check DNS consistency — no NS records high 1 50.0%
3 External report destination not authorized: dmarc.amazon.com high 1 50.0%

Key Findings

100% of Fortune 500 Email Security Report companies have published a DMARC record
While adoption is high, many policies remain at p=none, offering no enforcement protection.
0% of Fortune 500 Email Security Report domains score below a C grade
Most companies in this group maintain at least a baseline level of email security configuration.
Identity is the weakest pillar with an average score of 69
A 29-point gap between Reputation and Identity reveals that enterprises prioritize visible protocols over infrastructure hardening.
Advanced protocols (MTA-STS, DANE, BIMI) average only 33.3% adoption
Next-generation email security standards remain largely undeployed across the Fortune 500 Email Security Report, representing a significant opportunity for improvement.

Methodology

Scanning Approach

This report analyzes the email security posture of 529 domains from the Fortune 500 Email Security Report constituent list, of which 2 were successfully scanned. Each domain undergoes automated DNS and protocol checks that examine published records, validate configurations, and verify protocol compliance without sending any email traffic or interacting with mail servers beyond standard DNS queries and TLS connection probes.

Three-Pillar Model (DoSPM)

Every domain is evaluated across three security pillars, each representing a distinct dimension of email security posture:

Identity
Measures authentication and sender verification protocols including SPF, DKIM, DMARC, MTA-STS, DANE, and BIMI. These controls establish domain ownership and prevent unauthorized senders from impersonating the domain.
Shadow
Evaluates DNS infrastructure security including DNSSEC validation and DNS configuration hygiene. These controls protect against DNS spoofing, cache poisoning, and unauthorized zone modifications.
Reputation
Assesses transport security and domain standing including TLS configuration, certificate validity, and blacklist status. These controls ensure encrypted delivery and protect against interception and reputation damage.

Grading Scale

Each domain receives an overall score from 0 to 100, derived from weighted pillar scores. The score maps to a letter grade on a 13-point scale:

Grade Score Range
A+97–100
A93–96
A−90–92
B+87–89
B83–86
B−80–82
C+77–79
C73–76
C−70–72
D+67–69
D63–66
D−60–62
F0–59

Checks Per Domain

Each domain is evaluated against 57+ individual checks spanning all three pillars. Checks range from verifying the presence and syntax of DNS records to validating policy enforcement levels, cryptographic key strengths, certificate chains, and protocol interoperability. Results are classified by severity (pass, fail, warning, informational) and aggregated into pillar scores.

Data Coverage

Of the 529 domains in the Fortune 500 Email Security Report constituent list, 2 (0.4%) were successfully scanned and included in aggregate calculations. Domains without scan data or with scans older than 90 days are excluded from statistical analysis to ensure the report reflects current security posture.

Domain Lookup

Search and sort all Fortune 500 Email Security Report domains by email security posture.

Domain Grade Score Identity Shadow Reputation
google.com B+ 87 72 92 96
amazon.com C 75 66 60 100