Canny Pigeons

Research › Forbes Global 2000 top 100

26 of the world's 100 largest companies still let anyone send email as them

DMARC adoption across the Forbes Global 2000 top 100. Scanned 7 September 2026.

We looked up the email authentication records of the 100 largest public companies on Earth, as ranked by Forbes in June 2026. The question was simple: if someone forged an email from this company's corporate domain today, has the company told the world's mail servers what to do about it?

For 74 of them, yes. For 26, no.

p=reject
64
Forged mail is dropped
p=quarantine
10
Forged mail goes to spam
p=none
11
Monitoring only, forged mail delivered
No record
15
No policy, no reports

What we checked

DMARC is the DNS record that tells a receiving mail server what to do with a message that claims to come from your domain but fails authentication. It has three settings. p=reject drops the forgery. p=quarantine sends it to spam. p=none delivers it and only asks for a report. No record at all means no instruction and no report.

Of the 100 domains, 64 are at reject and 10 at quarantine. Those 74 companies have made a forged email from their domain either undeliverable or spam-foldered at every major mailbox provider.

The other 26 have not. 11 publish a record set to p=none, which is monitoring only: they receive reports about who is sending as them, but the forged message still lands in the inbox. 15 publish no DMARC record at all. They receive nothing, and receivers apply nothing.

6 of those 15 also have no SPF record. Toyota, NTT, Hon Hai, Sinopec, CNOOC and China Mobile have no email authentication of any kind on their corporate domain. Volkswagen Group has a monitoring-only DMARC record and no SPF.

Finding 1: a quarter of the list is unprotected

The 26 are not small names hiding at the bottom of the ranking. They include Alphabet at number four, ICBC at six, China Construction Bank at nine, Samsung at fifteen and Toyota at seventeen.

Nothing in the group is unusual for its size. Collectively they employ millions of people and email hundreds of millions of customers, which is exactly the population a phishing campaign wants to reach with a From address it recognises.

The split inside the 26 matters. A p=none record is a company that has started: it is collecting reports and has, presumably, a project underway. A missing record is a company that has not looked. 15 of the hundred largest companies in the world are in the second group.

Finding 2: geography predicts enforcement, size does not

Every company on this list is enormous, so size explains nothing. Where the company is headquartered explains almost everything.

DMARC policy by headquarters regionShare of companies in each region, Forbes Global 2000 top 100, scanned 7 September 2026
Stacked bars showing the share of companies at each DMARC policy level for each headquarters regionNorth AmericaNorth America, 42 companies: 37 reject, 2 quarantine, 3 none, 0 no record372342EuropeEurope, 22 companies: 17 reject, 4 quarantine, 1 none, 0 no record174122East AsiaEast Asia, 29 companies: 4 reject, 3 quarantine, 7 none, 15 no record4371529OtherOther, 7 companies: 6 reject, 1 quarantine, 0 none, 0 no record617
  • p=reject
  • p=quarantine
  • p=none
  • No record
  • Grey number: companies in the region

Canada, France, Switzerland and India each have every one of their companies at reject. The United States has 32 of 37, and its three laggards are Alphabet, Chevron and Disney, all at monitoring only.

East Asia is the mirror image. Of 29 companies headquartered in China, Hong Kong, Japan, South Korea and Taiwan, four are at reject: Agricultural Bank of China, Mitsubishi UFJ, Sumitomo Mitsui and TSMC. Twenty-two are at monitoring only or have no record. Mainland China accounts for seven of the 15 domains with no record, nine counting Hong Kong, and one of its fifteen companies is at reject.

The likely reason is regulatory rather than technical. Google and Yahoo have required DMARC from bulk senders since 2024, and Microsoft since 2025, but those rules bite hardest where the customers' mailboxes are. A company whose customers live on Gmail and Outlook has been forced to act. A company whose customers live elsewhere has not.

Finding 3: transport security barely exists at the top

Adoption of each email standardOf 100 companies in the Forbes Global 2000 top 100, scanned 7 September 2026
Dot plot showing how many of the 100 companies publish each email authentication and transport standardSPF recordSPF record: 93 of 10093DMARC recordDMARC record: 85 of 10085DMARC enforcedDMARC enforced: 74 of 10074BIMIBIMI: 25 of 10025TLS-RPTTLS-RPT: 9 of 1009MTA-STSMTA-STS: 7 of 1007MTA-STS enforcedMTA-STS enforced: 3 of 1003

DMARC protects the From address. It does nothing to stop a message being read or altered in transit, which is the job of two younger standards. MTA-STS tells sending servers that your domain requires encrypted delivery. TLS-RPT asks them to report when encryption fails.

Among the 100 largest companies in the world, 7 publish an MTA-STS record and 3 enforce it: Microsoft, Allianz and Petrobras. 9 publish TLS-RPT. Exactly 2 companies, Microsoft and Allianz, have the full stack of DMARC at reject, MTA-STS enforced and TLS-RPT.

BIMI, the standard that displays a verified logo next to authenticated email, does better: 25 companies publish a BIMI record, every one of them with a verified mark certificate. Logos in the inbox are a marketing benefit with a clear owner. Encrypted transport is a security benefit with no owner, and the numbers show which one gets done.

The full table

Every company on the list, with the domain we scanned. Click a column to sort, or filter by policy and region. The CSV carries the raw records and the reason for every domain substitution.

100 of 100 companies · Download CSV

1JPMorganChasejpmorganchase.comUnited StatesBankingrejectBIMI
2Amazonamazon.comUnited StatesRetail and WholesalequarantineBIMI
3Berkshire Hathawayberkshirehathaway.comUnited StatesInsurancereject
4Alphabetabc.xyzUnited StatesIT Software & Servicesnone
5Saudi Arabian Oil Company (Saudi Aramco)aramco.comSaudi ArabiaOil & Gas OperationsrejectTLS-RPT · BIMI
6ICBCicbc.com.cnChinaBankingnone
7Bank of Americabankofamerica.comUnited StatesBankingrejectBIMI
8Microsoftmicrosoft.comUnited StatesIT Software & ServicesrejectMTA-STS enforced · TLS-RPT
9China Construction Bankccb.comChinaBankingnone
10Agricultural Bank of Chinaabchina.comChinaBankingreject
11Appleapple.comUnited StatesTechnology Hardware & EquipmentquarantineBIMI
12Bank of Chinaboc.cnChinaBankingquarantine
13HSBC Holdingshsbc.comUnited KingdomBankingreject
14ExxonMobilexxonmobil.comUnited StatesOil & Gas Operationsreject
15Samsung Electronicssamsung.comSouth KoreaTechnology Hardware & Equipmentnone
16Meta Platformsmeta.comUnited StatesIT Software & Servicesreject
17Toyota Motortoyota.co.jpJapanConsumer Durablesno record
18Citigroupcitigroup.comUnited StatesBankingreject
19Goldman Sachs Groupgoldmansachs.comUnited StatesDiversified Financialsreject
20Wells Fargowellsfargo.comUnited StatesBankingrejectBIMI
21Morgan Stanleymorganstanley.comUnited StatesDiversified Financialsreject
22PetroChinapetrochina.com.cnChinaOil & Gas Operationsno record
23Walmartwalmart.comUnited StatesRetailingreject
24Royal Bank of Canadarbc.comCanadaBankingreject
25Santandersantander.comSpainBankingreject
26Ping An Insurance Grouppingan.comChinaInsuranceno record
27NVIDIAnvidia.comUnited StatesSemiconductorsrejectBIMI
28Shell Plcshell.comUnited KingdomOil & Gas OperationsquarantineMTA-STS testing · TLS-RPT · BIMI
29UnitedHealth Groupunitedhealthgroup.comUnited StatesDrugs & Biotechnologyreject
30Mitsubishi UFJ Financialmufg.jpJapanBankingrejectBIMI
31Taiwan Semiconductortsmc.comTaiwanSemiconductorsreject
32Allianzallianz.comGermanyInsurancerejectMTA-STS enforced · TLS-RPT · BIMI
33Tencent Holdingstencent.comChinaIT Software & Servicesquarantine
34TD Bank Grouptd.comCanadaBankingrejectBIMI
35Chevronchevron.comUnited StatesOil & Gas Operationsnone
36China Mobilechinamobileltd.comHong KongTelecommunications Servicesno record
37BNP Paribasbnpparibas.comFranceBankingrejectBIMI
38Verizon Communicationsverizon.comUnited StatesTelecommunications Servicesreject
39AT&Tatt.comUnited StatesTelecommunications ServicesrejectBIMI
40TotalEnergiestotalenergies.comFranceOil & Gas Operationsreject
41Alibaba Groupalibabagroup.comChinaRetailingnone
42China Merchants Bankcmbchina.comChinaBankingnone
43Johnson & Johnsonjnj.comUnited StatesDrugs & Biotechnologyreject
44BBVA-Banco Bilbao Vizcaya Argentariabbva.comSpainBankingreject
45Deutsche Telekomtelekom.comGermanyTelecommunications Servicesquarantine
46UBSubs.comSwitzerlandDiversified FinancialsrejectBIMI
47China Life Insurancechinalife.com.cnChinaInsuranceno record
48SK Hynixskhynix.comSouth KoreaSemiconductorsnone
49Sumitomo Mitsui Financialsmfg.co.jpJapanBankingrejectBIMI
50American Expressamericanexpress.comUnited StatesBusiness Services & SuppliesrejectBIMI
51AXA Groupaxa.comFranceInsurancereject
52Oracleoracle.comUnited StatesIT Software & Servicesreject
53Broadcombroadcom.comUnited StatesSemiconductorsrejectMTA-STS testing · TLS-RPT
54Softbankgroup.softbankJapanTelecommunications Servicesno record
55Reliance Industriesril.comIndiaOil & Gas Operationsreject
56Walt Disneythewaltdisneycompany.comUnited StatesMedianone
57LVMH Louis Vuitton Moet Hennessylvmh.comFranceHousehold & Personal Productsreject
58Bank of Communicationsbankcomm.comChinaBankingno record
59Nestlénestle.comSwitzerlandFood, Drink & Tobaccoreject
60Postal Savings Bank Of China (PSBC)psbc.comChinaBankingno record
61Siemenssiemens.comGermanyCapital GoodsrejectBIMI
62State Bank of Indiasbi.co.inIndiaBankingrejectMTA-STS testing · TLS-RPT · BIMI
63Petrobraspetrobras.com.brBrazilOil & Gas OperationsquarantineMTA-STS enforced · TLS-RPT
64Comcastcomcast.comUnited StatesMediareject
65Intesa Sanpaolointesasanpaolo.comItalyInsurancereject
66Procter & Gamblepg.comUnited StatesHousehold & Personal ProductsrejectTLS-RPT
67Mizuho Financialmizuho-fg.co.jpJapanBankingno record
68RTXrtx.comUnited StatesAerospace & Defensereject
69Home Depothomedepot.comUnited StatesRetailingreject
70HDFC Bankhdfcbank.comIndiaBankingrejectBIMI
71Contemporary Amperex Technologycatlbattery.comChinaCapital Goodsquarantine
72Eli Lillylilly.comUnited StatesDrugs & Biotechnologyreject
73Zurich Insurance Groupzurich.comSwitzerlandInsurancereject
74Commonwealth Bankcommbank.com.auAustraliaBankingrejectBIMI
75Hyundai Motorhyundaimotorgroup.comSouth KoreaConsumer Durablesno record
76Itaú Unibanco Holdingitau.com.brBrazilBankingreject
77Roche Holdingroche.comSwitzerlandDrugs & BiotechnologyrejectMTA-STS policy unreachable · TLS-RPT
78IBMibm.comUnited StatesIT Software & Servicesreject
79Chubbchubb.comSwitzerlandInsurancerejectBIMI
80BMObmo.comCanadaBankingreject
81Credit Agricolecredit-agricole.comFranceBankingreject
82Hon Hai Precisionhonhai.com.twTaiwanTechnology Hardware & Equipmentno record
83Cisco Systemscisco.comUnited StatesIT Software & ServicesrejectBIMI
84Sinopecsinopecgroup.comChinaOil & Gas Operationsno record
85CNOOCcnoocltd.comHong KongOil & Gas Operationsno record
86Volkswagen Groupvolkswagen-group.comGermanyConsumer Durablesnone
87Costco Wholesalecostco.comUnited StatesRetailingreject
88Merck & Co.merck.comUnited StatesDrugs & Biotechnologyreject
89Micron Technologymicron.comUnited StatesSemiconductorsreject
90PepsiCopepsico.comUnited StatesFood, Drink & TobaccorejectBIMI
91Pfizerpfizer.comUnited StatesDrugs & BiotechnologyrejectBIMI
92Bank of Nova Scotiascotiabank.comCanadaBankingreject
93Anheuser-Busch InBevab-inbev.comBelgiumFood, Drink & Tobaccoquarantine
94CITICgroup.citicChinaBusiness Services & Suppliesno record
95NTTntt.co.jpJapanTelecommunications Servicesno record
96Teslatesla.comUnited StatesConsumer DurablesrejectBIMI
97AIRBUSairbus.comNetherlandsAerospace & Defensereject
98UniCreditunicreditgroup.euItalyBankingquarantine
99Canadian Imperial Bankcibc.comCanadaBankingreject
100Mitsubishi Corporationmitsubishicorp.comJapanTrading Companiesnone

What a monitoring-only policy means for a company this size

A p=none record is the correct first step for a domain that has never had DMARC. It costs nothing, breaks nothing, and produces the reports that show which services send legitimate mail. The problem is staying there. Our guide to choosing a DMARC policy covers when a domain is ready to move to quarantine and reject, and our guide to reading DMARC reports covers what the reports are telling you in the meantime.

23 companies in this list also still publish a pct= tag, which the May 2026 revision of the DMARC standard removed. It is not counted against anyone here, but it is a sign of records written years ago and not revisited.

Methodology

The list. The Forbes Global 2000 for 2026, published June 2026, positions 1 to 100. Forbes ranks on a composite of sales, profits, assets and market value.

The domain. Forbes lists a website for each company. We took the registrable domain of that website and scanned it. Where Forbes lists a regional or subsidiary site, we substituted the group's primary domain and recorded why; there are 21 such substitutions, all listed in the CSV. Alphabet is scanned as abc.xyz, the holding company's own domain, which is at monitoring only; google.com is at reject. Every subsidiary, brand and regional domain is out of scope. A company can be at reject on one domain and unprotected on another, and only the corporate domain is scored here.

The scan. On 7 September 2026 we queried each domain's DNS over Cloudflare's resolver for the DMARC record, the SPF record and its lookup count, the MTA-STS record and policy file, the TLS-RPT record and the BIMI record. Every domain reported as having no DMARC record was confirmed against Google's resolver. The grading rule is the same one our free DMARC checker applies, so checking any domain in the table yourself will show the same result.

What this does not say. A DNS record is a statement of policy at a moment in time. It says nothing about whether a domain has been spoofed, how a company's mail is filtered internally, or what other controls it runs. Records change; we will re-scan this list quarterly and publish the difference.

Licence. The dataset and charts are released under Creative Commons Attribution 4.0. Use them freely, including commercially, with a credit to Canny Pigeons and a link to this page.

Corrections. If you work at one of these companies and the domain we scanned is not the one your company is known by, tell us at gday@cannypigeons.com and we will re-check and amend the table.

Check your own domain in ten seconds

The free DMARC checker applies the same grading rule as this study. If reports are already arriving, paste one into the report analyzer to see who is sending as you.

Check a domain