Skip to main content

🇧🇷 Email Security in Brazil

Weekly audit of email security across 76 listed companies headquartered in Brazil.

76 companies analysed · Scan week: 2026-03-23

  • Listed companies headquartered in Brazil score an average of 45/100 for email authentication and DNS security.
  • 0% of Brazil companies achieve grades A+ or A in email security, while 59% score D or F.
  • This is 3 points above the global average of 42 across all 1601 companies in the observatory.
  • DMARC email authentication is deployed by 88.2% of Brazil companies, with 36.8% enforcing a reject policy to prevent domain spoofing.
  • SPF records are published on 97% of analysed domains, authorizing legitimate email senders.
  • BIMI brand indicator adoption stands at 1% in Brazil.
  • MTA-STS enforced TLS encryption is deployed by 0% of companies, securing inbound email delivery.
  • DNSSEC domain signing is active on 22.4% of Brazil domains.
  • The highest-scoring company is ENGIE Brasil with 71/100 (B).
  • Hypera Pharma trails at 0/100, with significant room for improvement.
  • Scores range from 0 to 71 with a median of 45, showing disparate email security postures across Brazil listed companies.

Average score

45/ 100

DMARC reject

36.8%

BIMI configured

1%

MTA-STS enforce

0%

DNSSEC enabled

22.4%

0
A+
0
A
4
B
27
C
36
D
9
F

45

Average

45

Median

0

Min

71

Max

Grade
1ENGIE Brasilengie.com.br71B
2Fleuryfleury.com.br70B
3Embraerembraer.com70B
4SLC Agrícolaslcagricola.com.br70B
5EcoRodoviasecorodovias.com.br67C
6B3b3.com.br67C
7Banco do Brasilbb.com.br65+1C
8Petrobraspetrobras.com.br63C
9JBSjbs.com.br62C
10RaiaDrogasilraiadrogasil.com.br62C
11EDP - Energias do Brasiledp.com.br61-2C
123R Petroleum3rpetroleum.com.br60C
13Santander Brasilsantander.com.br58C
14Minerva Foodsminervafoods.com57+2C
15Equatorial Energiaequatorialenergia.com.br56C
16Cognacogna.com.br55+11C
17Klabinklabin.com.br55C
18BRFbrf-global.com55C
19Cosancosan.com.br54C
20Banco Interinter.co54C
21BB Seguridadebbseguridade.com.br53C
22Energisaenergisa.com.br52C
23Gol Linhas Aéreasvoegol.com.br52C
24Itaúsaitausa.com.br52C
25Localizalocaliza.com52C
26CSNcsn.com.br51C
27CEMIGcemig.com.br51+2C
28Magazine Luizamagazineluiza.com.br51C
29WEGweg.net51C
30CPFL Energiacpfl.com.br51-13C
31Banco Panbancopan.com.br50C
32Taesataesa.com.br49D
33Alpargatasalpargatas.com.br49D
34Natura &Conaturaeco.com49D
35BTG Pactualbtgpactual.com47D
36Hapvidahapvida.com.br46D
37Locaweblocaweb.com.br46D
38Assaíassai.com.br46D
39Multiplanmultiplan.com.br45D
40Vibra Energiavibra.com.br44D
41Itaú Unibancoitau.com.br44D
42Copelcopel.com43D
43MRV Engenhariamrv.com.br43D
44Lojas Rennerrenner.com.br43D
45Bradesparbradespar.com.br41D
46Ambevambev.com.br41D
47Bradescobradesco.com.br41D
48TOTVStotvs.com.br41D
49Telefónica Brasiltelefonica.com.br41D
50Sabespsabesp.com.br40+2D
51Cielocielo.com.br40D
52Ezteceztec.com.br39D
53Valevale.com38D
54Eletrobraseletrobras.com38D
55Gerdaugerdau.com37D
56Metalúrgica Gerdaugerdau.com37D
57Dexcodexco.com.br37D
58Grupo Somagruposoma.com.br36D
59Iguatemiiguatemi.com.br36D
60Rede D'Orrededorsaoluiz.com.br36D
61Suzanosuzano.com.br36D
62Enevaeneva.com.br35D
63Braskembraskem.com34D
64Carrefour Brasilcarrefour.com.br33D
65Marfrigmarfrig.com.br32D
66Yduqsyduqs.com.br31D
67CCRccr.com.br30D
68Usiminasusiminas.com.br29F
69Ultraparultrapar.com.br29F
70IRB Brasil REirbbrasil.com.br29F
71Azul Airlinesazul.com.br26F
72Rumorumo.com.br26F
73Prioprio.com.br23F
74Cyrela Brazil Realtycyrela.com.br23-9F
75TIM Brasiltim.com.br23F
76Hypera Pharmahyperafarmaceutica.com.br0F

Understanding country-level analysis

Grouping companies by country reveals how corporate email security practices vary across markets. Countries with stricter regulatory environments or more mature cybersecurity ecosystems tend to show higher average scores.

What this page shows:

  • Average score - The mean email security score across all listed companies in this country
  • Grade distribution - How many companies fall into each grade bracket (A+ through F)
  • DMARC reject rate - The percentage of companies enforcing strict DMARC policies
  • Company table - Individual scores, grades and key indicator status

Key standards tracked

Each company is evaluated on:

  1. SPF - Is the sending policy properly configured? Does it use -all (hard fail)?
  2. DKIM - Are signing keys published and strong enough (2048-bit minimum)?
  3. DMARC - Is a policy in place? Is it set to quarantine or reject?
  4. BIMI - Is the brand logo published for inbox display?
  5. MTA-STS - Is inbound email transport encryption enforced?
  6. DNSSEC - Is the DNS zone signed to prevent spoofing?

FAQ - Frequently asked questions

Q: How are companies grouped by country?

A: Based on the stock exchange where they are listed.


Q: What standards are checked?

A: SPF, DKIM, DMARC, BIMI, MTA-STS, DANE/TLSA and DNSSEC.


Q: Can I compare countries?

A: Yes, via the Statistics page.


PagePurpose
Observatory DashboardOverall overview with key metrics
StatisticsCross-country and cross-sector comparison
Email Domain CheckAudit your own domain