UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Servnet Research · Email security · FTSE 350

FTSE 350 email security 2026: DMARC, SPF and MTA-STS at FTSE 100 and FTSE 250 companies, checked against NCSC guidance

The public email-authentication records of FTSE 350 companies, as observed on 19 September 2026, checked against NCSC guidance. Each company is measured on the email domain it publishes, and every gap comes with the NCSC fix.

74.2%
of 267 companies on their own email domain had DMARC at quarantine or reject for mail from that domain (198)
55.4%
applied p=reject to all failing mail from the domain (148 of 267)
7
companies had no DMARC record; 57 were at p=none (monitor only)
12 of 267
mail-receiving domains had MTA-STS in enforce mode

Updated 19 September 2026 · public DNS records as observed on 19 September 2026; yardstick: NCSC guidance and the RFCs · method and dataset below

Read this first

What this study is, and is not

  • All figures are observations of public DNS records as observed on 19 September 2026 (2026-09-19T12:32:34.338Z to 2026-09-19T15:47:25.616Z UTC), not a judgement of a company's security.
  • Not investment advice. The study reports dated observations of public DNS records.
  • Tiers are Servnet's grouping of NCSC recommendations; NCSC has not reviewed or endorsed this study. Contains public sector information licensed under the Open Government Licence v3.0. (https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/)
  • Companies can ask for a correction or a re-measurement at webmaster@servnetuk.com. Corrections are shown with both the original and the new measurement date.
Summary

What the records show

Servnet checked the public email-authentication DNS records of the FTSE 350 on 19 September 2026, against NCSC guidance. For the 267 companies whose own email domain was identified from their published addresses, 198 (74.2%) had a DMARC policy of quarantine or reject for mail from that domain and 148 (55.4%) had p=reject for all failing mail from that domain (pct 100). 57 were at p=none and 7 had no DMARC record. Fewer protected email in transit: 12 domains had MTA-STS in enforce mode and 27 had TLS reporting. 10 companies met all of the study's DNS-visible controls (DKIM was not measured). Investment trusts that use their manager's domain are reported separately. Each gap is listed with the NCSC page that explains the fix, and the per-company data is open for download.

  • As observed on 19 September 2026, 198 of the 267 FTSE 350 companies whose own email domain was identified (74.2%) had a DMARC policy of quarantine or reject for mail from that domain. 12 of those 198 records set sp=none, which leaves subdomains without a record of their own at "none".
  • As observed on 19 September 2026, 148 of the 267 (55.4%) had p=reject for all failing mail from that domain (pct 100), the policy that NCSC says, used on all of an organisation's domains, is "the best way to prevent spoofing of your email"; 7 of these 148 set sp=none for subdomains. 57 of the 267 (21.3%) published p=none, which NCSC says will not "prevent illegitimate emails being sent from your domains", and 7 of the 267 (2.6%) published no DMARC record.
  • As observed on 19 September 2026, FTSE 100: 73 of 96 (76.0%) had a DMARC policy of quarantine or reject for mail from their own domain, and 53 (55.2%) had p=reject for all failing mail from that domain (pct 100). FTSE 250: 125 of 171 (73.1%) and 95 (55.6%).
  • As observed on 19 September 2026, 12 of the 267 (4.5%) own domains that receive mail had an MTA-STS policy in enforce mode, the goal NCSC sets, and 27 of the 266 whose record could be assessed (10.2%) published a TLS-RPT record. The MTA-STS enforce step was the most common gap (255 of 267).
  • As observed on 19 September 2026, 10 of the 267 (3.7%) had an SPF record whose full evaluation needs more than 10 DNS lookups; RFC 7208 says a receiver must return a permanent error (permerror) once that limit is exceeded, so mail from senders listed beyond it cannot get an SPF pass. 1 more record had a syntax error, which gives permerror for all mail (11 of the 267, 4.1%, in total).
  • As observed on 19 September 2026, 182 of the 267 (68.2%) met the Baseline (based on NCSC guidance) tier: an SPF record that ends in ~all or -all and stays within 10 DNS lookups, and DMARC at quarantine or reject with aggregate reports requested. 10 of the 267 (3.7%) met all of the study's DNS-visible controls (the Full set (based on NCSC guidance) tier); DKIM and other recommendations that cannot be seen in DNS were not measured. Tiers are Servnet's grouping of NCSC recommendations; NCSC has not reviewed or endorsed this study.
FTSE 100 and FTSE 250

Results by index

As observed on 19 September 2026, 96 FTSE 100 companies were measured on their own email domain (the others' email domain could not be identified, or is their manager's). 73 (76.0%) had a DMARC policy of quarantine or reject for mail from that domain, 53 (55.2%) had p=reject for all failing mail from that domain (pct 100), 19 were at p=none and 1 had no DMARC record. 3 met all of the study's DNS-visible controls.

As observed on 19 September 2026, 171 FTSE 250 companies were measured on their own email domain; investment trusts whose published address is their manager's are reported separately below. 125 (73.1%) had a DMARC policy of quarantine or reject for mail from that domain, 95 (55.6%) had p=reject for all failing mail from that domain (pct 100), 38 were at p=none and 6 had no DMARC record.

Companies on their own email domainnQuarantine or rejectReject (pct 100)p=noneNo DMARC record
FTSE 250171125 (73.1%)95 (55.6%)386
FTSE 1009673 (76.0%)53 (55.2%)191
FTSE 350 (own domain)267198 (74.2%)148 (55.4%)577

Scroll the table sideways to see every column →

By industry

Results by industry group

As observed on 19 September 2026, across both indices, the share of companies with a DMARC policy of quarantine or reject for mail from their own domain ranged from 52.6% (Real Estate, 10 of 19) to 83.1% (Financials, 49 of 59). Industry groups are Servnet's grouping of the sector labels on Wikipedia and are shown only where at least 10 companies were measured; 3 smaller groups are combined as "Other industries" (21 companies).

Industry groupnQuarantine or rejectReject (pct 100)p=noneNo DMARC record
Financials5949 (83.1%)40 (67.8%)73
Technology119 (81.8%)7 (63.6%)20
Industrials5847 (81.0%)34 (58.6%)90
Consumer Discretionary5337 (69.8%)30 (56.6%)142
Basic Materials139 (69.2%)3 (23.1%)21
Health Care128 (66.7%)6 (50.0%)40
Consumer Staples2112 (57.1%)8 (38.1%)80
Real Estate1910 (52.6%)7 (36.8%)90
Other industries2117 (81.0%)13 (61.9%)21

Scroll the table sideways to see every column →

Industry group (Servnet grouping of the sector labels on Wikipedia). Not an official FTSE Russell or ICB classification. Industry groups with fewer than 10 own-domain companies each (Utilities 8, Energy 7, Telecommunications 6), combined. Not shown separately because the groups are too small.

Email in transit

MTA-STS and TLS-RPT

NCSC recommends MTA-STS, first in testing mode with TLS reporting and then in enforce mode, for every domain that receives email. As observed on 19 September 2026, of the 267 own domains with an MX record, 26 published an MTA-STS record, 23 (8.6%) had a retrievable policy in testing or enforce mode (the public-sector census rule, which also counts mode none, gives 24), and 12 of the 267 (4.5%) were in enforce mode. 27 of the 266 assessed domains (10.2%) published a TLS-RPT record; 1 could not be assessed because the lookup failed DNSSEC validation.

How to fix

How to fix each gap (NCSC guidance)

Every gap in the data is paired with the free NCSC page that explains the fix, and with the NCSC email security check (https://checkcybersecurity.service.ncsc.gov.uk/email-security-check). NCSC retired Mail Check on 31 March 2026 (https://www.ncsc.gov.uk/blog-post/retiring-mail-check-web-check); several of its guidance pages still mention it, so send DMARC and TLS reports to your own mailbox or report-processing tool, not the Mail Check address.

NCSC retired Mail Check on 31 March 2026; send reports to your own mailbox or report-processing tool, not the Mail Check address. https://www.ncsc.gov.uk/blog-post/retiring-mail-check-web-check

Look up a company

Look up a company

The lookup shows, for each company, the email domain the study measured, how that domain was identified (a role address such as investor relations or the company secretary, with the page it was read from), how strong that evidence is, the records observed on 19 September 2026 and the NCSC fix for each gap. Evidence is high where a role address on the domain is visible on the cited page, and is marked medium where the address is only a contact-form routing value, is shown only behind a disclaimer or is on the manager's shared investment-trust contact page; where the page could be read only through a third-party fetch service or could not be re-opened on 19 September 2026; where only individuals' mailboxes are published; or where a trust's website is hosted on its manager's domain. Investment trusts appear on their manager's, adviser's or company secretary's domain, labelled as such. Figures describe DNS records on that date, not a company's wider security. The 10 companies whose email domain could not be identified are not scored and are not in the lookup. Companies can ask for a correction or a re-measurement at webmaster@servnetuk.com. Corrections are shown with both the original and the new measurement date.

340 of 340 · as observed on 19 September 2026 · select a row for details, evidence and fixes

CompanyEmail domain measuredDMARCSPFMTA-STSControls met

Companies can ask for a correction or a re-measurement at webmaster@servnetuk.com. Corrections are shown with both the original and the new measurement date.

Investment trusts

Investment trusts on manager domains

73 investment trusts publish a contact address on the domain of their investment manager, adviser or company secretary, or have their website on their manager's domain, not on a domain of their own. Those 39 domains are measured once each. 5 of them are also the own email domain of a FTSE 350 company (3i, Aberdeen Group, Foresight Group, ICG and Schroders) and count in the headline only as that company's domain. As observed on 19 September 2026, 28 of the 39 domains (71.8%) had a DMARC policy of quarantine or reject; without those 5, 24 of 34 (70.6%). Every managed row is labelled as the manager's or secretary's domain: the records describe that domain, not the trust's own.

Comparison

Compared with the UK public sector

Servnet's UK public sector DMARC census was measured on the same day with the same code, and only measures defined identically in both are compared here (the public-sector yardstick differs). Using the census rules (the domain's own record only, and pct below 100 counted as not enforcing), as observed on 19 September 2026: DMARC at quarantine or reject applied to all failing mail from the domain (pct 100), on domains that send mail, 195 of 267 FTSE companies (73.0%) and 649 of 821 public-sector domains (79.0%); across all 907 public-sector domains, including 86 that send no mail, 653 (72.0%). MTA-STS in enforce mode: 12 of 267 FTSE companies (4.5%) and 219 of 907 public-sector domains (24.1%). A TLS-RPT record: 27 of 267 FTSE companies (10.1%; census rule, where a lookup that failed DNSSEC validation counts as no record) and 416 of 907 public-sector domains (45.9%), although 284 of the 416 public-sector TLS-RPT records still include the retired NCSC Mail Check address.

See the UK public sector DMARC census.

Earlier work

Previous studies of FTSE email authentication

Email authentication at FTSE companies has been measured before. This study builds on that work; the main differences are listed after the table.

PublisherDateCompaniesWhat was measuredPer-company data
Agari (reported by SecurityWeek)August 2017FTSE 100 (with the Fortune 500)DMARC adoption and policy level (none, quarantine, reject)No
Agari2019FTSE 100 among several national indicesDMARC adoption and p=rejectNo
Rapid7, Industry Cyber-Exposure ReportApril 2021FTSE 350Internet-facing exposure, including valid DMARC policiesNo
Rapid7, The FTSE 350 Cyber Attack SurfaceApril 2023FTSE 350Valid DMARC policies and DNSSEC, alongside open ports and web-server softwareNo
Proofpoint (ASX 200 analysis)June 2023FTSE 100 as a comparatorDMARC adoption rateNo
Red SiftJanuary 2024; guide with January 2026 dataFTSE 100 and FTSE 250 among listed companies worldwideDMARC records against the Google and Yahoo sender rules (2024); share at quarantine or reject (2026)No
Hornetsecurity (Infosecurity Europe; reported by IT Pro)June 2025FTSE 100DMARC configuration (method not published)No
CaptainDNS ObservatoryWeekly (latest scan week shown: 23 March 2026, as seen on 19 September 2026)FTSE 100 among 16 indicesSPF, DKIM, DMARC, BIMI, MTA-STS, DANE and DNSSEC, with a composite score and letter gradeYes (company rankings with scores and grades)
PowerDMARC, UK DMARC & MTA-STS Adoption Report2026UK domains by sector (not FTSE)DMARC, SPF, MTA-STS and DNSSECNo

Scroll the table sideways to see every column →

  • All 350 constituents checked at company level: 340 measured on the email domain evidenced by an address the company or trust publishes (or its manager's or secretary's domain), 10 not measured because no email domain could be identified.
  • Every control sourced to NCSC guidance with a quoted basis, and the NCSC fix for each gap. No composite score, grade or league table.
  • DMARC read under the new standard, RFC 9989 (May 2026), alongside RFC 7489: pct and t tags, organisational-domain inheritance and multiple records.
  • MTA-STS policy files fetched and read, and TLS-RPT measured, for FTSE 250 companies as well as the FTSE 100, with the effect of the Mail Check retirement shown.
  • Investment trusts that use their manager's domain counted once per domain and kept out of the company headline.
  • An open, reproducible per-company dataset, comparable with the UK public sector census on the measures defined identically in both, measured the same day with the same code.
Method

Method, yardstick and licence

The FTSE 100 and FTSE 250 constituents effective from 21 September 2026 were taken from Wikipedia and checked against LSEG's index-review announcements. Each company's email domain comes from a role address it publishes (on its website, in its annual report or other company documents, or in its security.txt), with the evidence URL in the data; the evidence was re-checked on 19 September 2026 for whether the address is visible on the cited page (hidden parts of the page are left out), and is marked medium where the address is only a contact-form routing value, is shown only behind a disclaimer or is on the manager's shared investment-trust contact page; where the page could be read only through a third-party fetch service or could not be re-opened on 19 September 2026; where only individuals' mailboxes are published; or where a trust's website is hosted on its manager's domain. Public DNS was read over DNS-over-HTTPS from Cloudflare and Google on 19 September 2026, and MTA-STS policy files were fetched over HTTPS. Controls are sourced to NCSC guidance, mailbox-provider sender rules and RFCs, including RFC 9989. Tiers are Servnet's grouping of NCSC recommendations; NCSC has not reviewed or endorsed this study. Contains public sector information licensed under the Open Government Licence v3.0.

Licence and notices

Company names, tickers, index membership and sector labels are adapted from the Wikipedia articles "FTSE 100 Index" (revision of 18 September 2026) and "FTSE 250 Index" (revision of 18 September 2026) by Wikipedia contributors, licensed under CC BY-SA 4.0. Changes: checked against LSEG index-review announcements, email domains added by Servnet, sector labels grouped into industry groups by Servnet. This dataset (CSV and JSON) is released under CC BY-SA 4.0; please credit "Servnet FTSE 350 Email Security Study 2026" with a link to this page.

FTSE®, FTSE 100, FTSE 250, FTSE 350 and ICB® are trade marks of the London Stock Exchange Group. Servnet is not affiliated with or endorsed by LSEG or FTSE Russell; index membership is reported as a fact.

Tiers are Servnet's grouping of NCSC recommendations; NCSC has not reviewed or endorsed this study. Contains public sector information licensed under the Open Government Licence v3.0. (https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/)

Scroll the chart sideways to see all of it →

Downloads (CC BY-SA 4.0): CSV · README (columns and evidence) · JSON.

FAQ

Questions

What is DMARC, and why does NCSC recommend quarantine or reject?

DMARC is a DNS record at _dmarc.<your domain> that tells receiving mail servers what to do with mail that claims to be from your domain but fails SPF and DKIM checks aligned with it: nothing (p=none), treat it as suspicious (p=quarantine) or refuse it (p=reject). It also asks receivers to send you aggregate reports (the rua tag). NCSC says a policy of none will not prevent illegitimate emails being sent from your domains, that you must at least use quarantine for that, and that reject on all of your domains is the best way to prevent spoofing.

What are MTA-STS and TLS-RPT?

MTA-STS (RFC 8461) lets a domain that receives email tell sending servers to deliver only over an encrypted, certificate-checked connection to its listed mail servers. It is a _mta-sts DNS record plus a policy file at https://mta-sts.<your domain>/.well-known/mta-sts.txt, in testing or enforce mode. TLS-RPT (RFC 8460) is a DNS record at _smtp._tls.<your domain> that asks senders to report delivery problems over TLS. NCSC recommends starting MTA-STS in testing mode with TLS-RPT, then moving to enforce.

How can an organisation move from p=none to p=reject safely?

Follow the NCSC steps. Publish p=none with a rua address at a DMARC report-processing tool you control. Use the reports to find every service that sends mail as your domain, and make each one pass SPF or DKIM aligned with your domain (NCSC recommends DKIM; keep SPF within 10 DNS lookups). Then move to p=quarantine, and to p=reject once reports show legitimate mail passing. Set the policy for subdomains (sp) as well, and give parked domains v=spf1 -all, p=reject and a null MX. Receivers that follow RFC 9989 ignore the pct tag, so a percentage roll-out may not be applied everywhere; RFC 9989 has a t=y testing flag instead.

What changed with RFC 9989?

RFC 9989 (May 2026) is the Standards Track version of DMARC and obsoletes RFC 7489 and RFC 9091; aggregate reporting is specified separately in RFC 9990. It removes the pct tag (receivers ignore unknown tags), adds a t=y testing flag (reject is then applied as quarantine, and quarantine as none), brings in the np tag for non-existent subdomains (from RFC 9091), finds the organisational domain by a DNS tree walk instead of the Public Suffix List, and discards all records when a name has more than one. It also defines "Enforcement" as every policy for an organisational domain and all subdomains below it being something other than p=none. This study counts the DMARC policy that applies to mail from the domain itself as quarantine or reject only where RFC 7489 and RFC 9989 would apply the same policy to that mail (for example, quarantine with pct below 100 is not counted). It is narrower than RFC 9989's "Enforcement": 12 of the 198 records counted set sp=none.

NCSC Mail Check has been retired. What should users do?

NCSC retired Mail Check and Web Check on 31 March 2026, and users no longer receive findings from them. If a DMARC rua or TLS-RPT record still points at the Mail Check address, replace it with your own mailbox or a report-processing tool. NCSC's retirement notice points to commercial attack-surface management products as alternatives and recommends its Check your cyber security service, which checks email anti-spoofing and email privacy. Some older NCSC guidance pages still mention Mail Check.

Do Gmail, Yahoo and Outlook.com require DMARC?

For bulk senders, yes: a DMARC record is required, and a policy of p=none is enough. Since February 2024 Google has required senders of about 5,000 messages a day or more to Gmail accounts, and Yahoo has required bulk senders, to set up SPF, DKIM and a DMARC record. Microsoft said that from 5 May 2025 Outlook.com would reject mail from domains sending over 5,000 messages a day that do not meet its SPF, DKIM and DMARC requirements, with the code "550; 5.7.515". None of the three requires quarantine or reject. This study does not say whether a company meets these rules: DKIM, alignment and sending volumes cannot be seen in DNS.

What does "DMARC enforced" mean in this study?

It means the DMARC policy that applies to mail from this domain is quarantine or reject. A p=reject record with pct below 100 counts (the rest is quarantined), but quarantine with pct below 100 or t=y does not. It is narrower than RFC 9989's "Enforcement", which also covers every subdomain: 12 of the 198 records counted here set sp=none for subdomains.

How was each company's email domain chosen, and how can it be corrected?

From role addresses the company publishes, such as investor relations, the company secretary or the press office, on its website, in its annual report or other company documents, or in its security.txt file. The page each address was read from is in the data, with the strength of that evidence: high where a role address on the domain is visible on the page, and medium where the address is only a contact-form routing value, is shown only behind a disclaimer or is on the manager's shared investment-trust contact page; where the page could be read only through a third-party fetch service or could not be re-opened on 19 September 2026; where only individuals' mailboxes are published; or where a trust's website is hosted on its manager's domain. 10 companies whose email domain could not be identified are left out of the figures and the lookup, and investment trusts that publish their manager's or company secretary's address are reported separately, labelled as that domain. Companies can ask for a correction or a re-measurement at webmaster@servnetuk.com. Corrections are shown with both the original and the new measurement date.

Related

Email and security

More Servnet research

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111