Skip to main content
75/ 100

CaixaBank

caixabank.com · 🇪🇸 ES · financials

Scan week: 2026-03-23

  • CaixaBank scores 75/100 and receives a grade of B in the Email Security Observatory.
  • This score is 33 points above the global average of 42/100, placing CaixaBank among the better-protected companies.
  • CaixaBank ranks #7 out of 1601 companies globally in the email security observatory.
  • The score decreased by 2 points since last week.
  • Outbound email security - covering DMARC, SPF, DKIM and BIMI - scores 92/100 (A).
  • Inbound email protection - covering MX, MTA-STS, DANE and TLS-RPT - scores 40/100 (D).
  • DNS security (DNSSEC) scores 100/100 (A+).
  • 3 recommendations have been identified to improve CaixaBank's email security posture.
  • Score history spans 4 weeks, enabling week-over-week tracking of email authentication progress.

Outbound

50%
A
92/ 100
dmarc
36/40A
spf
30/30A
dkim
23/25A
bimi
3/5C

Inbound

35%
D
40/ 100
mx
40/40A
mta-sts
0/30F
dane
0/15F
tls-rpt
0/15F

DNS Security

15%
A+
100/ 100
dnssec
100/100A

Rankings

global

#7 / 1601

country ES

#1 / 34

index ibex-35

#1 / 35

sector financials

#3 / 222

Score history

75
03-23
75
03-16
75
03-09
73
03-02

Recommendations

Mediummta-sts

Deploy MTA-STS to enforce TLS for inbound email

Lowtls-rpt

Add a TLS-RPT record to receive TLS failure reports

Lowdane

Add DANE/TLSA records to authenticate your MX certificates via DNS

Understanding the company audit

Each company in the Observatory is analyzed weekly for email authentication standards. The audit provides a comprehensive view of the company's email security posture.

What this page shows:

  • Total score - A score out of 100 reflecting overall email security maturity
  • Letter grade - From A+ (excellent) to F (significant gaps)
  • Per-standard analysis - Individual scores for SPF, DKIM, DMARC, BIMI, MTA-STS, DANE/TLSA and DNSSEC
  • Recommendations - Prioritized steps to improve the score

Standards evaluated

  1. SPF - Sender Policy Framework prevents unauthorized servers from sending email on behalf of the domain
  2. DKIM - DomainKeys Identified Mail ensures emails are signed and unaltered during transit
  3. DMARC - Domain-based Message Authentication, Reporting and Conformance ties SPF and DKIM together with a policy
  4. BIMI - Brand Indicators for Message Identification displays the brand logo in supporting email clients
  5. MTA-STS - Mail Transfer Agent Strict Transport Security enforces TLS encryption for inbound email
  6. DNSSEC - Domain Name System Security Extensions prevent DNS spoofing attacks

FAQ - Frequently asked questions

Q: How is the score calculated?

A: Points are awarded for each standard based on configuration quality, totaling up to 100.


Q: What do the grades mean?

A: A+ is excellent (90-100), F indicates significant gaps (below 50).


PagePurpose
Observatory DashboardOverall overview with key metrics
StatisticsCross-index and cross-sector comparison
Email Domain CheckAudit your own domain