Canny Pigeons

Research › Australia's ten largest banks

All ten of Australia's largest banks enforce DMARC. Seven leave their .au domain open.

Email authentication across the ten largest Australian-owned banks. Scanned 13 September 2026.

We took the ten largest Australian-owned banks by resident assets, as ranked by APRA in its July 2026 monthly statistics, and looked up everything their DNS says about email: the DMARC policy, the SPF record, the DKIM keys published under well-known selector names, the BIMI logo record, the MTA-STS and TLS-RPT transport records, the direct .au domain each bank registered in 2022, and the gateway that receives their inbound mail.

The short version: the banks did the hard part. Every one of the ten enforces DMARC on its main domain, which is a better result than the world's hundred largest companies managed. The rest of this study is about what the best of them do beyond that, and the one thing most of them missed.

DMARC enforced
10
Forged mail dropped or sent to spam
Logo in the inbox
4
BIMI with a verified mark certificate
Clean DKIM
2
Only 2048-bit keys, nothing broken
.au protected
3
Direct .au domain at reject

What we checked

DMARC is the DNS record that tells a receiving mail server what to do with a message that claims to come from your domain but fails authentication. p=reject drops the forgery, p=quarantine sends it to spam, and p=none delivers it and only asks for a report. SPF lists the servers allowed to send for the domain. DKIM signs each message with a key published in DNS; the strength of that key is what a forger would have to break.

Three younger standards sit on top. BIMI displays a verified logo next to authenticated mail in Gmail, Apple Mail and Yahoo, but only when the domain enforces DMARC and holds a verified mark certificate tied to a registered trademark. MTA-STS tells sending servers that the domain requires encrypted delivery, and TLS-RPT asks them to report when encryption fails.

We also looked next door. Since 2022 every Australian business has been able to register a direct .au domain, and every bank on this list did. A shorter domain that carries the bank's exact name is a convincing From address, so we checked whether those domains carry the same protection as the main one.

Finding 1: ten for ten

Adoption of each email standardOf 10 Australian banks, the ten largest by resident assets, scanned 13 September 2026
Dot plot showing how many of the 10 companies publish each email authentication and transport standardSPF recordSPF record: 10 of 1010DMARC recordDMARC record: 10 of 1010DMARC enforcedDMARC enforced: 10 of 1010BIMIBIMI: 4 of 104TLS-RPTTLS-RPT: 1 of 101MTA-STSMTA-STS: 1 of 101MTA-STS enforcedMTA-STS enforced: 0 of 100

8 of the ten banks are at reject and 2, AMP Bank and People First Bank, are at quarantine. All 10 request aggregate reports, and none has a broken SPF record or one over the ten-lookup limit.

That is the whole of the policy story, and it is a good one. Not one of the ten is unprotected, against 26 of the Forbes Global 2000 top 100. Australian banking has done what a quarter of the world's largest companies have not.

The detail separates them. Commonwealth Bank is the only one of the ten with strict DKIM and SPF alignment, and one of 3 with an explicit subdomain policy, which is the record of a team that read the specification rather than accepting a vendor's default. NAB and Macquarie also lock their subdomains explicitly. The other seven leave subdomains to inherit the parent policy, which works, but leaves nothing to stop a future subdomain being carved out with a weaker one.

Finding 2: two banks have the full picture

Commonwealth Bank and People First Bank, the largest and the smallest on the list, are the only two with a clean DKIM inventory: every key we found under a well-known selector is 2048-bit and nothing is broken. Both also show their logo in the inbox through BIMI with a verified mark certificate.

People First Bank, the customer-owned bank formed from Heritage Bank and People's Choice, goes one step further than anyone. It is the only bank of the ten publishing MTA-STS and TLS-RPT at all. Its MTA-STS policy is still in testing mode and its DMARC policy is quarantine rather than reject, so it is not finished, but it is the only one that has started on transport security. The bank with a fortieth of Commonwealth Bank's assets has the most complete email setup in Australian banking.

BIMI itself is at 4 of ten: Commonwealth Bank, Westpac, ANZ and People First Bank all hold a verified mark certificate, so their logos appear in Gmail and Apple Mail. NAB is the one major without it.

Finding 3: the .au domain next door

Every bank on the list registered its direct .au domain, and the registry confirms the bank itself holds it. 3 protected it: Westpac, NAB and ANZ have westpac.au, nab.au and anz.au at reject. The other 7 have no DMARC record and no SPF record on it. Anyone can send a message from commbank.au, macquarie.au, bendigobank.au, boq.au, suncorpbank.au, amp.au or peoplefirstbank.au today and no receiving server has been told to refuse it.

Two of those stand out. commbank.au has a mail exchanger, so it accepts inbound mail, which usually means it is in use for something. macquarie.au serves a live website. Neither has a single email authentication record.

The .com twins tell the opposite story. 8 of the nine banks whose main domain is not already .com have their .com at reject; Suncorp Bank is the exception. The banks know how to lock a domain they do not send from. They did it for .com and did not repeat it for .au when the new domains opened in 2022. The fix is a null SPF record and a reject DMARC record, two lines of DNS, and our guide to writing a DMARC record covers the reject record and the SPF guide covers the null record.

Finding 4: the keys are older than the policies

DKIM keys live under selector names that the sender chooses, so there is no way to list every key a domain publishes. We probed 110 selector names that the common mail platforms use by default and found 43 across the ten banks. What we found is exact; what we did not find is simply not under a well-known name.

8 of the ten banks publish at least one live 1024-bit RSA key. Google, Microsoft and Yahoo still accept those, but 1024-bit RSA has been considered too short since 2013 and 2048-bit is the norm for any key issued today. Most of the short keys sit on marketing platforms: SendGrid's second selector is 1024-bit at every bank that uses it, Campaign Monitor and Postmark keys are 1024-bit, and so is Mailchimp's original selector, although its newer ones at AMP Bank are 2048-bit. Westpac and Bank of Queensland also sign their corporate Microsoft 365 mail with 1024-bit keys, which is a tenant setting to rotate rather than a vendor limitation.

Bendigo and Adelaide Bank and Suncorp Bank have no 2048-bit key under any well-known name, only a single 1024-bit key each. 5 banks have retired selectors still pointing at vendors that no longer publish a key for them. Westpac has an Amazon SES selector carrying a 32-byte Ed25519 key without the tag that declares its type, so a verifier treats it as RSA and fails to parse it; the record is also flagged as test mode and is probably a leftover from a trial.

None of this weakens the DMARC result. A forged message still fails DMARC at all ten banks. It is the maintenance layer underneath, and it is the kind of thing that only shows up in DMARC reports or in a scan like this one, because nothing breaks until someone forges a 1024-bit signature.

Finding 5: who runs it

Two vendors receive the DMARC reports for eight of the ten banks. Proofpoint handles 5: ANZ, Macquarie, Bendigo and Adelaide Bank, Bank of Queensland and AMP Bank. Valimail handles 3: Westpac, Suncorp Bank and People First Bank. Commonwealth Bank and NAB collect their own.

Inbound mail is split differently. 4 banks, including the two largest, run their mail exchangers straight into Microsoft 365 with no third-party gateway in front: Commonwealth Bank, Westpac, NAB and People First Bank. 4 run Proofpoint: Macquarie, Bendigo and Adelaide Bank, Bank of Queensland and AMP Bank. Suncorp Bank uses Mimecast and ANZ uses Trellix, the former FireEye. So Proofpoint reports on five banks' outbound mail but filters only four banks' inbound, and Microsoft's built-in filtering is trusted by the biggest balance sheets in the country.

ANZ and AMP Bank each publish eight DKIM selectors, the most on the list, across Microsoft 365, SendGrid, Mailchimp and Campaign Monitor, plus Postmark and an on-premise relay at ANZ. That is the widest sending footprint of the ten and the most surface to keep aligned, which is exactly what a DMARC reporting vendor is for.

The full table

Every bank on the list, with the domain we scanned. The CSV carries the raw records, the DKIM selector counts, the .au registrant and the reason for every domain choice.

10 banks, ranked by total resident assets · Download CSV

#BankDMARCSPFDKIM keysBIMITransport.au domainInbound mail
1Commonwealth Bankcommbank.com.au · A$1,252bnrejectsubdomains reject · strict alignment · reports to in-house soft fail5 of 10 lookupsclean1 × 2048-bit · 0 × 1024-bit · 1 retired with VMCno recordcommbank.au · accepts mailMicrosoft 365
2Westpacwestpac.com.au · A$1,192bnrejectreports to Valimail hard fail4 of 10 lookupsmixed1 × 2048-bit · 4 × 1024-bit · 1 retired · 1 broken with VMCrejectwestpac.auMicrosoft 365
3NABnab.com.au · A$984bnrejectsubdomains reject · reports to in-house soft fail6 of 10 lookupsmixed2 × 2048-bit · 3 × 1024-bit · 1 retiredrejectnab.auMicrosoft 365
4ANZanz.com · A$781bnrejectreports to Proofpoint hard fail4 of 10 lookupsmixed3 × 2048-bit · 5 × 1024-bit with VMCrejectanz.auTrellix (FireEye)
5Macquarie Bankmacquarie.com.au · A$362bnrejectsubdomains reject · reports to Proofpoint hard fail5 of 10 lookupsmixed1 × 2048-bit · 1 × 1024-bitno recordmacquarie.auProofpoint
6Bendigo and Adelaide Bankbendigobank.com.au · A$117bnrejectreports to Proofpoint hard fail4 of 10 lookups1024 only0 × 2048-bit · 1 × 1024-bitno recordbendigobank.auProofpoint
7Bank of Queenslandboq.com.au · A$110bnrejectreports to Proofpoint hard fail2 of 10 lookupsmixed1 × 2048-bit · 3 × 1024-bitno recordboq.auProofpoint
8Suncorp Banksuncorpbank.com.au · A$95bnrejectreports to Valimail hard fail3 of 10 lookups1024 only0 × 2048-bit · 1 × 1024-bit · 2 retiredno recordsuncorpbank.auMimecast
9AMP Bankamp.com.au · A$33bnquarantinereports to Proofpoint soft fail1 of 10 lookupsmixed5 × 2048-bit · 3 × 1024-bitno recordamp.auProofpoint
10People First Bankpeoplefirstbank.com.au · A$30bnquarantinereports to Valimail soft fail1 of 10 lookupsclean1 × 2048-bit · 0 × 1024-bit · 1 retired with VMCMTA-STS testing · TLS-RPTno recordpeoplefirstbank.auMicrosoft 365

Methodology

The list. APRA's register of authorised deposit-taking institutions, Australian-owned section, ranked by the "Total residents assets" column of the Monthly Authorised Deposit-taking Institution Statistics for July 2026, released 31 August 2026. Foreign subsidiary banks, which would have placed ING sixth and HSBC tenth, are excluded because they are not Australian-owned. Norfina Limited appears under its trading name Suncorp Bank, and Heritage and People's Choice Limited under its trading name People First Bank.

The domain. The primary customer-facing website domain of each bank, verified by fetching the homepage. ANZ is scanned as anz.com because anz.com.au has no mail exchanger and a null SPF record, so it is not the domain the bank sends from. AMP Bank operates under the AMP group domain. Every choice and its reason is in the CSV.

The scan. On 13 September 2026 we queried each domain's DNS over Cloudflare's resolver for the DMARC record, the SPF record and its lookup count, the MTA-STS record and policy file, the TLS-RPT record and the BIMI record, using the same grading rule as our free DMARC checker. DKIM keys were looked up under 110 selector names used by default by Microsoft 365, Google Workspace, Proofpoint, Mimecast, SendGrid, Mailchimp, Salesforce, Amazon SES and other common platforms; key sizes were read from the published public key. The direct .au, .com and .net.au twins were checked for DMARC, SPF and mail exchangers, and the .au registrant was confirmed through the auDA registry. Inbound gateways were read from the mail exchanger hostnames.

What this does not say. A DNS record is a statement of policy at a moment in time. It says nothing about whether a domain has been spoofed, how a bank's mail is filtered internally, or what other controls it runs. A DKIM key we did not find under a well-known selector may exist under a custom one. Records change; we will re-scan this list and publish the difference.

Licence. The dataset and charts are released under Creative Commons Attribution 4.0. Use them freely, including commercially, with a credit to Canny Pigeons and a link to this page.

Corrections. If you work at one of these banks and something here does not match what you know, tell us at gday@cannypigeons.com and we will re-check and amend the table.

Check your own domain in ten seconds

The free DMARC checker applies the same grading rule as this study. If reports are already arriving, paste one into the report analyzer to see who is sending as you.

Check a domain