Skip to main content
40/ 100

Cielo

cielo.com.br · 🇧🇷 BR · financials

Scan week: 2026-03-23

  • Cielo scores 40/100 and receives a grade of D in the Email Security Observatory.
  • This score is 2 points below the global average of 42/100, indicating areas where email security could be strengthened.
  • Cielo ranks #1057 out of 1601 companies globally in the email security observatory.
  • The score is unchanged from last week.
  • Outbound email security - covering DMARC, SPF, DKIM and BIMI - scores 52/100 (C).
  • Inbound email protection - covering MX, MTA-STS, DANE and TLS-RPT - scores 40/100 (D).
  • DNS security (DNSSEC) scores 0/100 (F).
  • 4 recommendations have been identified to improve Cielo's email security posture.
  • Score history spans 4 weeks, enabling week-over-week tracking of email authentication progress.

Outbound

50%
C
52/ 100
dmarc
27/40B
spf
3/30F
dkim
22/25A
bimi
0/5F

Inbound

35%
D
40/ 100
mx
40/40A
mta-sts
0/30F
dane
0/15F
tls-rpt
0/15F

DNS Security

15%
F
0/ 100
dnssec
0/100F

Rankings

global

#1057 / 1601

country BR

#50 / 76

index ibovespa

#50 / 76

sector financials

#165 / 222

Score history

40
03-23
40
03-16
40
03-09
40
03-02

Recommendations

Mediumdmarc

Upgrade DMARC policy from quarantine to reject for full protection

Mediummta-sts

Deploy MTA-STS to enforce TLS for inbound email

Lowtls-rpt

Add a TLS-RPT record to receive TLS failure reports

Lowdnssec

Enable DNSSEC for your domain to improve DNS security

Understanding the company audit

Each company in the Observatory is analyzed weekly for email authentication standards. The audit provides a comprehensive view of the company's email security posture.

What this page shows:

  • Total score - A score out of 100 reflecting overall email security maturity
  • Letter grade - From A+ (excellent) to F (significant gaps)
  • Per-standard analysis - Individual scores for SPF, DKIM, DMARC, BIMI, MTA-STS, DANE/TLSA and DNSSEC
  • Recommendations - Prioritized steps to improve the score

Standards evaluated

  1. SPF - Sender Policy Framework prevents unauthorized servers from sending email on behalf of the domain
  2. DKIM - DomainKeys Identified Mail ensures emails are signed and unaltered during transit
  3. DMARC - Domain-based Message Authentication, Reporting and Conformance ties SPF and DKIM together with a policy
  4. BIMI - Brand Indicators for Message Identification displays the brand logo in supporting email clients
  5. MTA-STS - Mail Transfer Agent Strict Transport Security enforces TLS encryption for inbound email
  6. DNSSEC - Domain Name System Security Extensions prevent DNS spoofing attacks

FAQ - Frequently asked questions

Q: How is the score calculated?

A: Points are awarded for each standard based on configuration quality, totaling up to 100.


Q: What do the grades mean?

A: A+ is excellent (90-100), F indicates significant gaps (below 50).


PagePurpose
Observatory DashboardOverall overview with key metrics
StatisticsCross-index and cross-sector comparison
Email Domain CheckAudit your own domain
Cielo - Email Security Score