Understanding the company audit
Each company in the Observatory is analyzed weekly for email authentication standards. The audit provides a comprehensive view of the company's email security posture.
What this page shows:
- Total score - A score out of 100 reflecting overall email security maturity
- Letter grade - From A+ (excellent) to F (significant gaps)
- Per-standard analysis - Individual scores for SPF, DKIM, DMARC, BIMI, MTA-STS, DANE/TLSA and DNSSEC
- Recommendations - Prioritized steps to improve the score
Standards evaluated
- SPF - Sender Policy Framework prevents unauthorized servers from sending email on behalf of the domain
- DKIM - DomainKeys Identified Mail ensures emails are signed and unaltered during transit
- DMARC - Domain-based Message Authentication, Reporting and Conformance ties SPF and DKIM together with a policy
- BIMI - Brand Indicators for Message Identification displays the brand logo in supporting email clients
- MTA-STS - Mail Transfer Agent Strict Transport Security enforces TLS encryption for inbound email
- DNSSEC - Domain Name System Security Extensions prevent DNS spoofing attacks
FAQ - Frequently asked questions
Q: How is the score calculated?
A: Points are awarded for each standard based on configuration quality, totaling up to 100.
Q: What do the grades mean?
A: A+ is excellent (90-100), F indicates significant gaps (below 50).
Related pages
| Page | Purpose |
|---|---|
| Observatory Dashboard | Overall overview with key metrics |
| Statistics | Cross-index and cross-sector comparison |
| Email Domain Check | Audit your own domain |