Skip to main content

🇫🇷 CAC 40 Email Security

Weekly audit of email security across 40 companies in the CAC 40.

Euronext Paris · 40 companies analysed · Scan week: 2026-03-23

  • Companies listed in the CAC 40 score an average of 54/100 for email security this week.
  • 0% of CAC 40 companies achieve a grade of A+ or A in email authentication, while 33% receive a D or F.
  • The average score of 54 is 12 points above the global average of 42, indicating stronger-than-average email security practices.
  • 97.5% of CAC 40 companies have deployed DMARC email authentication, and 60% enforce a strict reject policy to block spoofed emails.
  • SPF record deployment stands at 100%, authorizing legitimate sending servers and helping prevent email spoofing.
  • 8% of companies have configured BIMI to display their verified brand logo in supported email clients.
  • 3% enforce TLS encryption for inbound email delivery via MTA-STS, protecting against downgrade attacks.
  • DNSSEC is enabled on 25% of CAC 40 domains, adding cryptographic validation to DNS queries.
  • Schneider Electric leads the CAC 40 with a top score of 73/100 (B).
  • Safran has the lowest score at 15/100, indicating significant gaps in email security configuration.
  • Scores range from 15 to 73 with a median of 55, reflecting varied levels of email security maturity across the index.

Average score

54/ 100

DMARC reject

60%

BIMI configured

8%

MTA-STS enforce

3%

DNSSEC enabled

25%

0
A+
0
A
3
B
24
C
12
D
1
F

54

Average

55

Median

15

Min

73

Max

Company

Grade
1Schneider Electricse.com73B
2Thalesthalesgroup.com71+2B
3BNP Paribasbnpparibas.com70B
4Stellantisstellantis.com69C
5ArcelorMittalarcelormittal.com68C
6Vivendivivendi.com67C
7Danonedanone.com67C
8STMicroelectronicsst.com67C
9Orangeorange.com66C
10Eurofins Scientificeurofins.com66C
11LVMHlvmh.com59C
12Capgeminicapgemini.com59C
13L'Oréalloreal.com59+5C
14Airbusairbus.com58C
15Renaultrenaultgroup.com58+3C
16Hermèshermes.com58C
17Air Liquideairliquide.com57C
18TotalEnergiestotalenergies.com56+2C
19Michelinmichelin.com56C
20Unibail-Rodamco-Westfieldurw.com55C
21Dassault Systèmes3ds.com55C
22Saint-Gobainsaint-gobain.com55C
23Bureau Veritasbureauveritas.com55C
24Sanofisanofi.com54C
25Veoliaveolia.com54C
26Carrefourcarrefour.com51C
27Bouyguesbouygues.com51C
28EssilorLuxotticaessilorluxottica.com49D
29Teleperformancetp.com49D
30Vincivinci.com49D
31Engieengie.com48+1D
32Société Généralesocietegenerale.com47D
33Legrandlegrand.com47D
34Pernod Ricardpernod-ricard.com46D
35Keringkering.com44D
36Publicis Groupepublicisgroupe.com42D
37Crédit Agricolecredit-agricole.com40D
38Alstomalstom.com39D
39AXAaxa.com38D
40Safransafran-group.com15F

Understanding index-level analysis

A stock index groups the largest companies in a market. Analyzing their email security provides a representative snapshot of how a country's or region's corporate sector protects against email-based threats.

What this page shows:

  • Average score - The mean email security score across all constituent companies
  • Grade distribution - How many companies fall into each grade bracket (A+ through F)
  • Company table - Individual scores, grades and key indicator status for each company
  • Sector breakdown - How different industries within the index compare

Key standards tracked

Each company is evaluated on:

  1. SPF - Is the sending policy properly configured? Does it use -all (hard fail)?
  2. DKIM - Are signing keys published and strong enough (2048-bit minimum)?
  3. DMARC - Is a policy in place? Is it set to quarantine or reject?
  4. BIMI - Is the brand logo published for inbox display?
  5. MTA-STS - Is inbound email transport encryption enforced?
  6. DNSSEC - Is the DNS zone signed to prevent spoofing?

FAQ - Frequently asked questions

Q: How are companies scored?

A: Each domain is analyzed for email authentication standards and awarded up to 100 points across three pillars.


Q: What does the grade distribution show?

A: The spread of scores from A+ to F, indicating overall index maturity.


Q: Can I compare indices?

A: Yes, via the Statistics page.


PagePurpose
Observatory DashboardOverall overview with key metrics
StatisticsCross-index and cross-sector comparison
Email Domain CheckAudit your own domain