Servnet FTSE 350 Email Security Study 2026: data README Study page: https://www.servnetuk.com/research/ftse-350-dmarc-email-security-2026 Public DNS records as observed on 19 September 2026 (12:32:34 to 15:47:25 UTC). The figures describe DNS records on that date, not a company's wider security. Not investment advice. The study reports dated observations of public DNS records. FILES ftse350-dmarc-2026.csv one row per company and recorded domain (483 rows, of which 26 withheld) data.json (on the study page, /research/ftse-350-dmarc-email-security-2026/data.json) the same rows and every aggregate LICENCE AND ATTRIBUTION Company names, tickers, index membership and sector labels are adapted from the Wikipedia articles "FTSE 100 Index" (revision of 18 September 2026, https://en.wikipedia.org/w/index.php?title=FTSE_100_Index&oldid=1375553849) and "FTSE 250 Index" (revision of 18 September 2026, https://en.wikipedia.org/w/index.php?title=FTSE_250_Index&oldid=1375571342) by Wikipedia contributors, licensed under CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/). Changes: checked against LSEG index-review announcements, email domains added by Servnet, sector labels grouped into industry groups by Servnet. This dataset (CSV and JSON) is released under CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/); please credit "Servnet FTSE 350 Email Security Study 2026" with a link to this page. Licence scope: The CSV and the JSON dataset. The page prose and charts are Servnet's own work. ROWS One row per company and recorded domain. domainRole primary is the domain the company is measured on (its own email domain, or for a managed trust its manager's, adviser's or company secretary's domain); domainRole alt (other domains with MX) and web-only (website domains without MX) are secondary rows that list other domains recorded for the company. Withheld rows (withheld true) come after the named rows. Primary rows: 340 (267 companies on their own email domain; 73 managed investment companies on 39 manager or secretary domains). Secondary rows: 93 alt, 50 web-only. The 10 companies whose email domain could not be identified are not in the data. WITHHELD ROWS 17 companies (8 on their own email domain and 9 managed investment companies) are counted in the totals but not named because their email domain could not be confirmed to a high standard. A company is named only where its primary-domain evidence is high; these are the companies whose evidence is medium. Their rows (primary and secondary) have withheld true and keep index, industryGroup, cohort, domainRole, domainKind, domainLabel, confidence, evidenceStrength, managedDomainCounted and every DNS result, so every figure reproduces from the rows. name, ticker, sectorLabel, domain, orgDomain, sharedWith, evidenceKind, evidenceStrengthWhy, evidenceUrl, note and any cross-reference (alsoPrimaryOf, dmarcInheritedFrom) read "Withheld: email domain not confirmed to a high standard"; raw record text and report addresses are replaced by placeholders of the same kind (a usable report URI becomes mailto:[redacted]@withheld.invalid or https://withheld.invalid/, a Mail Check URI stays a Mail Check URI, an SPF record other than v=spf1 -all becomes the placeholder), SPF syntax and MTA-STS policy error details read the placeholder, measuredAt gives the date only and measurementFile is blank. withheldRef (W01, W01-2, ...) links a withheld company's secondary rows to its primary row; the numbering follows index, cohort and industry group, not the company name. EVIDENCE COLUMNS Evidence columns (evidenceKind, evidenceStrength, evidenceStrengthWhy, evidenceUrl) and confidence describe the company's primary email domain; secondary rows list other domains recorded and leave the evidence columns and confidence blank. Evidence strength (evidenceStrength). high: a role address on the primary domain is visible on the cited page (visible text, a mailto link, the text of a PDF, or a closed accordion or tab panel a visitor opens). medium: the evidence is weaker. Every named company is high; the companies with medium evidence are withheld (see withheld), so their evidenceStrengthWhy reads the placeholder and the reasons are given, without names, on the study page. Confidence (confidence). high or medium: how firmly the primary email domain is attributed to the company. medium where the kind of evidence is itself weaker (evidenceKind individual-mailbox-not-quoted, role-address-form-routing, role-address-manager-trusts-page, trust-website-on-manager-domain); each of those rows is also medium on evidenceStrength. evidenceStrength can also be medium on a high-confidence row, because of how the cited page was read or shown. What makes evidence medium is explained in the evidenceStrength note (above). Every company with medium evidence is withheld (see withheld): counted in the totals but not named. Blank on secondary rows. COLUMNS (CSV order) name: Company name as in the constituent tables on Wikipedia (see licence and attribution). The placeholder on withheld rows. ticker: Ticker. The placeholder on withheld rows. withheld: true on the rows (primary and secondary) of a company counted in the totals but not named because its email domain could not be confirmed to a high standard (see WITHHELD ROWS); false on every other row. withheldRef: Withheld rows only: W01, W02, ... on a withheld company's primary row and W01-2, W01-3, ... on its secondary rows. Blank on named rows. index: FTSE 100 or FTSE 250. industryGroup: Servnet's grouping of the sector label into industry groups; not an official FTSE Russell or ICB classification. sectorLabel: Sector label as published in the Wikipedia table. The placeholder on withheld rows. cohort: ownDomain: measured on the company's own email domain (the headline). managed: an investment company whose published contact address is on its manager's, adviser's or company secretary's domain, or whose website is hosted on its manager's domain and publishes no address of its own (reported separately, per domain). confidence: high or medium: how firmly the primary email domain is attributed to the company. medium where the kind of evidence is itself weaker (evidenceKind individual-mailbox-not-quoted, role-address-form-routing, role-address-manager-trusts-page, trust-website-on-manager-domain); each of those rows is also medium on evidenceStrength. evidenceStrength can also be medium on a high-confidence row, because of how the cited page was read or shown. What makes evidence medium is explained in the evidenceStrength note (EVIDENCE COLUMNS above, and the evidenceStrength column below). Every company with medium evidence is withheld (see withheld): counted in the totals but not named. Blank on secondary rows. evidenceKind: How the primary email domain is evidenced (on named rows: role-address-annual-report, role-address-company-document, role-address-company-website, role-address-group-website, role-address-trust-annual-report, role-address-trust-website, security-txt). Blank on secondary rows; the placeholder on withheld rows. evidenceStrength: high: a role address on the primary domain is visible on the cited page (visible text, a mailto link, the text of a PDF, or a closed accordion or tab panel a visitor opens). medium: the evidence is weaker. Every named company is high; the companies with medium evidence are withheld (see withheld), so their evidenceStrengthWhy reads the placeholder and the reasons are given, without names, on the study page. Blank on secondary rows. evidenceStrengthWhy: The reason for the evidence strength, in words. Blank on secondary rows; the placeholder on withheld rows. evidenceUrl: The page or document where the address evidencing the primary email domain was read. Blank on secondary rows; the placeholder on withheld rows. domain: The domain measured on this row. The placeholder on withheld rows. domainRole: primary, alt (another domain with MX recorded for the company) or web-only (a website domain without MX). domainKind: own or manager on primary rows; alt or web-only on secondary rows. domainLabel: The domain role in words. sharedWith: Other named companies whose primary domain is the same (semicolon-separated). The placeholder on withheld rows. alsoPrimaryOf: Managed rows only: the company whose own primary domain this also is. The placeholder on a withheld row where there is one. managedDomainCounted: Managed primary rows only: true on the one row per manager or secretary domain that the per-domain managed figures count (a named row where the domain has one; every row on a domain has the same records), false on that domain's other rows. Blank on other rows. orgDomain: Organisational domain (Public Suffix List). The placeholder on withheld rows. profile: sending or nonSending. Primary rows are always sending; secondary rows are sending if they have MX or an SPF record that authorises a sender. receivesMail: An MX record other than a null MX. mxCount: Number of MX records. nullMx: Null MX (RFC 7505). dmarcSource: own (record at _dmarc.), inherited (from the organisational domain), none, invalid, multiple or unresolved (lookup did not resolve). dmarcInheritedFrom: Organisational domain the DMARC policy is inherited from. The placeholder on a withheld row where there is one. dmarcOwnClass: Class of the record at _dmarc. itself, as the UK public sector census computes it (used for the comparison). dmarcPolicy: Policy that applies to mail from the domain (p, or sp when inherited from the organisational domain). dmarcPct: pct tag (100 when absent). dmarcT: t tag (RFC 9989 testing flag). dmarcSp: sp tag. dmarcNp: np tag. dmarcRua: Aggregate-report URIs (dotted local parts that are not role mailboxes are [redacted]; on withheld rows each URI is replaced by a placeholder of the same kind). dmarcRuf: Failure-report URIs (redacted as dmarcRua). ruaMailCheckOnly: rua points only at the retired NCSC Mail Check. ruaIncludesMailCheck: rua includes the retired NCSC Mail Check. spNoneOnEnforcing: Own record counted as enforced that sets sp=none. enforced: DMARC policy of quarantine or reject for mail from the domain: the DMARC policy that applies to mail from this domain is quarantine or reject reject: p=reject for all failing mail from that domain (pct 100, no t=y). enforcingBis: quarantine or reject without t=y, pct ignored (the RFC 9989 reading). enforcing7489Census: The public-sector census rule: the domain's own record only, and pct below 100 counted as not enforcing. spfState: present, missing, multiple or unresolved. spfQualifier: Qualifier of the final all term (-, ~, ?, +) or none. spfLookups: DNS-querying terms in the full evaluation, each occurrence counted (RFC 7208 section 4.6.4). spfLookupsCensusCounter: The census counter's count, for comparison. spfOverLimit: spfLookups above 10. spfSyntaxError: Syntax error found in the record, if any (the placeholder on withheld rows). spfPermerror: Over the limit, a syntax error or more than one record. spfClassCensus: SPF class as the census computes it. spfSenderless: The record is exactly v=spf1 -all. spfAuthorisesSenders: The record authorises at least one sender. spfMacroIncludes: Number of macro (%{...}) terms, counted once each and not expanded. mtaStsRecord: _mta-sts record published. mtaStsPolicyOk: Policy file retrieved and valid. mtaStsMode: Mode in the policy file. mtaStsPolicyError: Why the policy file could not be used, if so (the placeholder on withheld rows). mtaStsState: none, record-only, testing, enforce, mode-none, multiple or invalid-mode. mtaStsCensus: The census's MTA-STS status field. tlsRptState: published, none, multiple or unresolved (lookup failed). tlsRptMailCheckOnly: TLS-RPT rua points only at the retired NCSC Mail Check. dnssecAd: The resolver marked the answer DNSSEC-validated (AD flag). c_dmarc-published: Status of the control dmarc-published (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. c_dmarc-enforced: Status of the control dmarc-enforced (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. c_dmarc-reject: Status of the control dmarc-reject (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. c_dmarc-reporting: Status of the control dmarc-reporting (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. c_spf-published: Status of the control spf-published (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. c_spf-valid: Status of the control spf-valid (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. c_mta-sts: Status of the control mta-sts (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. c_mta-sts-enforce: Status of the control mta-sts-enforce (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. c_tls-rpt: Status of the control tls-rpt (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. c_ns-spf-none: Status of the control ns-spf-none (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. c_ns-dmarc-reject: Status of the control ns-dmarc-reject (met, unmet, not-assessed or na). Definitions: standard.controls in the JSON. t_basicDns: Status of the tier basicDns (met, unmet, not-assessed or na). t_baseline: Status of the tier baseline (met, unmet, not-assessed or na). t_fullSet: Status of the tier fullSet (met, unmet, not-assessed or na). t_parkedDomain: Status of the tier parkedDomain (met, unmet, not-assessed or na). controlsMet: Controls met. controlsApplicable: Controls that apply (met or unmet). controlsNotAssessed: Controls not assessed (lookup failed). meetsAll: true when every applicable control is met; blank when a control could not be assessed. unmetControls: Unmet control ids, space-separated. fixesText: The NCSC page that explains the fix for each unmet control, the Mail Check retirement note and the NCSC email security check. measuredAt: When the domain was measured (UTC); the date only on withheld rows. measurementFile: The raw measurement file (not published) that holds the DNS answers. Blank on withheld rows. note: Free-text note on the row, including why a secondary domain is recorded where that is known. The placeholder on withheld rows. dmarcRecord: DMARC record as observed (redacted as dmarcRua; on withheld rows the report URIs are placeholders and any tag other than the policy tags reads withheld). spfRecord: SPF record as observed (on withheld rows the placeholder, unless the record is v=spf1 -all). tlsRptRecord: TLS-RPT record as observed (redacted as dmarcRua; on withheld rows v=TLSRPTv1 with placeholder report URIs). CORRECTIONS: Companies can ask for a correction or a re-measurement at webmaster@servnetuk.com. Corrections are shown with both the original and the new measurement date.