Spoofability index
Which big brands can be spoofed in email?
We score the email-authentication posture of the world's most-impersonated brands and tell you, in plain English, whether a third party can send mail from their domain that lands in inboxes. Re-scored monthly.
Spoofable
15 (7%)
No DMARC, or DMARC at p=none. Anyone can send from these domains.
Partial protection
44 (22%)
DMARC at p=quarantine, or p=reject with pct<100. Spoofed mail may slip through.
Not practically spoofable
144 (71%)
DMARC p=reject pct=100 + SPF -all or DKIM. Spoofed mail rejected at SMTP.
Jump to a category
Education (12)
| Brand | Domain | Verdict | |
|---|---|---|---|
| MIT | mit.edu | Spoofable | See the math → |
| Harvard | harvard.edu | Maybe | See the math → |
| Stanford | stanford.edu | Maybe | See the math → |
| University of Oxford | ox.ac.uk | Maybe | See the math → |
| Yale | yale.edu | Maybe | See the math → |
| edX | edx.org | Maybe | See the math → |
| Berkeley | berkeley.edu | Protected | See the math → |
| Cambridge | cam.ac.uk | Protected | See the math → |
| Coursera | coursera.org | Protected | See the math → |
| Duolingo | duolingo.com | Protected | See the math → |
| Khan Academy | khanacademy.org | Protected | See the math → |
| Udemy | udemy.com | Protected | See the math → |
Government (18)
| Brand | Domain | Verdict | |
|---|---|---|---|
| CRA (Canada) | canada.ca | Spoofable | See the math → |
| US Treasury | treasury.gov | Maybe | See the math → |
| Australian Taxation Office | ato.gov.au | Protected | See the math → |
| CDC | cdc.gov | Protected | See the math → |
| CISA | cisa.gov | Protected | See the math → |
| DHS | dhs.gov | Protected | See the math → |
| European Commission | ec.europa.eu | Protected | See the math → |
| FBI | fbi.gov | Protected | See the math → |
| FCC | fcc.gov | Protected | See the math → |
| FTC | ftc.gov | Protected | See the math → |
| Federal Reserve | federalreserve.gov | Protected | See the math → |
| GOV.UK | gov.uk | Protected | See the math → |
| HM Revenue & Customs | hmrc.gov.uk | Protected | See the math → |
| IRS | irs.gov | Protected | See the math → |
| NASA | nasa.gov | Protected | See the math → |
| SEC | sec.gov | Protected | See the math → |
| USPS | usps.com | Protected | See the math → |
| White House | whitehouse.gov | Protected | See the math → |
Healthcare (10)
| Brand | Domain | Verdict | |
|---|---|---|---|
| Kaiser Permanente | kp.org | Spoofable | See the math → |
| Mayo Clinic | mayoclinic.org | Spoofable | See the math → |
| CVS Health | cvs.com | Maybe | See the math → |
| Cigna | cigna.com | Maybe | See the math → |
| HCA Healthcare | hcahealthcare.com | Maybe | See the math → |
| Walgreens | walgreens.com | Maybe | See the math → |
| Anthem (Elevance Health) | elevancehealth.com | Protected | See the math → |
| Cleveland Clinic | clevelandclinic.org | Protected | See the math → |
| Humana | humana.com | Protected | See the math → |
| UnitedHealthcare | uhc.com | Protected | See the math → |
Logistics / shipping (10)
| Brand | Domain | Verdict | |
|---|---|---|---|
| La Poste | laposte.fr | Spoofable | See the math → |
| Yamato | kuronekoyamato.co.jp | Maybe | See the math → |
| Aramex | aramex.com | Protected | See the math → |
| Canada Post | canadapost.ca | Protected | See the math → |
| DHL | dhl.com | Protected | See the math → |
| FedEx | fedex.com | Protected | See the math → |
| Maersk | maersk.com | Protected | See the math → |
| Purolator | purolator.com | Protected | See the math → |
| Royal Mail | royalmail.com | Protected | See the math → |
| UPS | ups.com | Protected | See the math → |
Retail (20)
| Brand | Domain | Verdict | |
|---|---|---|---|
| Aldi | aldi.com | Spoofable | See the math → |
| Carrefour | carrefour.com | Spoofable | See the math → |
| Lidl | lidl.com | Spoofable | See the math → |
| Trader Joe's | traderjoes.com | Spoofable | See the math → |
| Wayfair | wayfair.com | Maybe | See the math → |
| Best Buy | bestbuy.com | Protected | See the math → |
| Costco | costco.com | Protected | See the math → |
| Etsy | etsy.com | Protected | See the math → |
| Home Depot | homedepot.com | Protected | See the math → |
| IKEA | ikea.com | Protected | See the math → |
| Lowe's | lowes.com | Protected | See the math → |
| Macy's | macys.com | Protected | See the math → |
| Nordstrom | nordstrom.com | Protected | See the math → |
| Sainsbury's | sainsburys.co.uk | Protected | See the math → |
| Sephora | sephora.com | Protected | See the math → |
| Shopify | shopify.com | Protected | See the math → |
| Target | target.com | Protected | See the math → |
| Tesco | tesco.com | Protected | See the math → |
| Walmart | walmart.com | Protected | See the math → |
| eBay | ebay.com | Protected | See the math → |
Social (10)
| Brand | Domain | Verdict | |
|---|---|---|---|
| Threads | threads.net | Spoofable | See the math → |
| Mastodon | joinmastodon.org | Maybe | See the math → |
| Discord | discord.com | Protected | See the math → |
| linkedin.com | Protected | See the math → | |
| pinterest.com | Protected | See the math → | |
| Quora | quora.com | Protected | See the math → |
| reddit.com | Protected | See the math → | |
| Substack | substack.com | Protected | See the math → |
| TikTok | tiktok.com | Protected | See the math → |
| Twitter / X | x.com | Protected | See the math → |
Tech (18)
| Brand | Domain | Verdict | |
|---|---|---|---|
| Intel | intel.com | Spoofable | See the math → |
| Samsung | samsung.com | Spoofable | See the math → |
| Sony | sony.com | Spoofable | See the math → |
| AMD | amd.com | Maybe | See the math → |
| Amazon | amazon.com | Maybe | See the math → |
| Apple | apple.com | Maybe | See the math → |
| google.com | Maybe | See the math → | |
| Meta | meta.com | Maybe | See the math → |
| Dell | dell.com | Protected | See the math → |
| HP | hp.com | Protected | See the math → |
| IBM | ibm.com | Protected | See the math → |
| Lenovo | lenovo.com | Protected | See the math → |
| Microsoft | microsoft.com | Protected | See the math → |
| Nvidia | nvidia.com | Protected | See the math → |
| Oracle | oracle.com | Protected | See the math → |
| SAP | sap.com | Protected | See the math → |
| Spotify | spotify.com | Protected | See the math → |
| Tesla | tesla.com | Protected | See the math → |
Telecom (9)
| Brand | Domain | Verdict | |
|---|---|---|---|
| Orange | orange.com | Spoofable | See the math → |
| AT&T | att.com | Protected | See the math → |
| BT | bt.com | Protected | See the math → |
| Bell Canada | bell.ca | Protected | See the math → |
| Comcast | comcast.com | Protected | See the math → |
| NTT | global.ntt | Protected | See the math → |
| T-Mobile | t-mobile.com | Protected | See the math → |
| Verizon | verizon.com | Protected | See the math → |
| Vodafone | vodafone.com | Protected | See the math → |
Travel (20)
| Brand | Domain | Verdict | |
|---|---|---|---|
| IHG Hotels | ihg.com | Spoofable | See the math → |
| Emirates | emirates.com | Maybe | See the math → |
| Hertz | hertz.com | Maybe | See the math → |
| Hilton | hilton.com | Maybe | See the math → |
| Ryanair | ryanair.com | Maybe | See the math → |
| Uber | uber.com | Maybe | See the math → |
| Air France | airfrance.com | Protected | See the math → |
| Airbnb | airbnb.com | Protected | See the math → |
| American Airlines | aa.com | Protected | See the math → |
| Avis | avis.com | Protected | See the math → |
| Booking.com | booking.com | Protected | See the math → |
| British Airways | britishairways.com | Protected | See the math → |
| Delta | delta.com | Protected | See the math → |
| Expedia | expedia.com | Protected | See the math → |
| Hyatt | hyatt.com | Protected | See the math → |
| JetBlue | jetblue.com | Protected | See the math → |
| Lufthansa | lufthansa.com | Protected | See the math → |
| Marriott | marriott.com | Protected | See the math → |
| Southwest | southwest.com | Protected | See the math → |
| United Airlines | united.com | Protected | See the math → |
Finance (25)
| Brand | Domain | Verdict | |
|---|---|---|---|
| Bank of America | bankofamerica.com | Maybe | See the math → |
| Binance | binance.com | Maybe | See the math → |
| Goldman Sachs | goldmansachs.com | Maybe | See the math → |
| Morgan Stanley | morganstanley.com | Maybe | See the math → |
| Robinhood | robinhood.com | Maybe | See the math → |
| Visa | visa.com | Maybe | See the math → |
| Wells Fargo | wellsfargo.com | Maybe | See the math → |
| American Express | americanexpress.com | Protected | See the math → |
| Barclays | barclays.com | Protected | See the math → |
| Capital One | capitalone.com | Protected | See the math → |
| Charles Schwab | schwab.com | Protected | See the math → |
| Citi | citi.com | Protected | See the math → |
| Coinbase | coinbase.com | Protected | See the math → |
| Fidelity | fidelity.com | Protected | See the math → |
| HSBC | hsbc.com | Protected | See the math → |
| JPMorgan Chase | jpmorganchase.com | Protected | See the math → |
| Klarna | klarna.com | Protected | See the math → |
| Kraken | kraken.com | Protected | See the math → |
| Lloyds Bank | lloydsbank.com | Protected | See the math → |
| Mastercard | mastercard.com | Protected | See the math → |
| PayPal | paypal.com | Protected | See the math → |
| Plaid | plaid.com | Protected | See the math → |
| Square (Block) | block.xyz | Protected | See the math → |
| Stripe | stripe.com | Protected | See the math → |
| Vanguard | vanguard.com | Protected | See the math → |
Media (16)
| Brand | Domain | Verdict | |
|---|---|---|---|
| Bloomberg | bloomberg.com | Maybe | See the math → |
| Politico | politico.com | Maybe | See the math → |
| Wall Street Journal | wsj.com | Maybe | See the math → |
| Associated Press | apnews.com | Protected | See the math → |
| Axios | axios.com | Protected | See the math → |
| BBC | bbc.com | Protected | See the math → |
| CNN | cnn.com | Protected | See the math → |
| Financial Times | ft.com | Protected | See the math → |
| Forbes | forbes.com | Protected | See the math → |
| NPR | npr.org | Protected | See the math → |
| Reuters | reuters.com | Protected | See the math → |
| TIME | time.com | Protected | See the math → |
| The Atlantic | theatlantic.com | Protected | See the math → |
| The Guardian | theguardian.com | Protected | See the math → |
| The New York Times | nytimes.com | Protected | See the math → |
| The Washington Post | washingtonpost.com | Protected | See the math → |
Security vendors (15)
| Brand | Domain | Verdict | |
|---|---|---|---|
| 1Password | 1password.com | Maybe | See the math → |
| Auth0 | auth0.com | Maybe | See the math → |
| Bitdefender | bitdefender.com | Maybe | See the math → |
| Fortinet | fortinet.com | Maybe | See the math → |
| Norton | norton.com | Maybe | See the math → |
| Bitwarden | bitwarden.com | Protected | See the math → |
| Check Point | checkpoint.com | Protected | See the math → |
| Cisco | cisco.com | Protected | See the math → |
| CrowdStrike | crowdstrike.com | Protected | See the math → |
| LastPass | lastpass.com | Protected | See the math → |
| Okta | okta.com | Protected | See the math → |
| Palo Alto Networks | paloaltonetworks.com | Protected | See the math → |
| SentinelOne | sentinelone.com | Protected | See the math → |
| Trend Micro | trendmicro.com | Protected | See the math → |
| Twilio | twilio.com | Protected | See the math → |
Software (20)
| Brand | Domain | Verdict | |
|---|---|---|---|
| Asana | asana.com | Maybe | See the math → |
| Calendly | calendly.com | Maybe | See the math → |
| Dropbox | dropbox.com | Maybe | See the math → |
| Figma | figma.com | Maybe | See the math → |
| GitHub | github.com | Maybe | See the math → |
| Notion | notion.so | Maybe | See the math → |
| ADP | adp.com | Protected | See the math → |
| Adobe | adobe.com | Protected | See the math → |
| Atlassian | atlassian.com | Protected | See the math → |
| Cloudflare | cloudflare.com | Protected | See the math → |
| HubSpot | hubspot.com | Protected | See the math → |
| Klaviyo | klaviyo.com | Protected | See the math → |
| Mailchimp | mailchimp.com | Protected | See the math → |
| Monday.com | monday.com | Protected | See the math → |
| Salesforce | salesforce.com | Protected | See the math → |
| SendGrid | sendgrid.com | Protected | See the math → |
| ServiceNow | servicenow.com | Protected | See the math → |
| Slack | slack.com | Protected | See the math → |
| Workday | workday.com | Protected | See the math → |
| Zoom | zoom.us | Protected | See the math → |
How we score
For each domain we resolve DMARC, SPF, DKIM (probing the common selectors), and MTA-STS. The verdict synthesises all four into a single answer: YES (no DMARC at all, or DMARC at p=none) - anyone can spoof you and receivers have no policy to apply. MAYBE(p=quarantine, or p=reject with pct<100) - spoofed mail may be quarantined but isn't reliably rejected. NO (p=reject pct=100 + SPF hardfail or a published DKIM key) - spoofed mail is rejected at SMTP.
Click See the math on any row for the per-signal breakdown of that brand. Want to check your own domain? Run the free Spoofability check.
Last scored: . Index re-scores monthly via our background worker.