Research › The UK's ten largest banks
Nine of the UK's ten largest banks enforce DMARC. Six leave their .uk domain open.
The ten largest UK-owned banks and building societies, read from their DNS on 22 September 2026.
British retail banking is unusual in one way that matters for this study: a third of the biggest balance sheets belong to mutuals. Rank the country's deposit takers by group assets, keep the ones with a British parent, and the top ten is four banks, five building societies and one specialist lender. That mix turned out to be the story. The banks did what banks with security budgets do. The building societies, with a fraction of the money, did more of it, except for the one that did almost none.
We read each institution's public DNS for everything that governs its email: whether forged mail is refused, who signs the real thing and with what size key, whether a logo is shown next to it, whether delivery has to be encrypted, and whether the short .uk version of the name, which anyone could put in a From address, is guarded the way the main domain is.
The score
A DMARC record at p=reject tells every receiving mail server to refuse a message that claims the domain and cannot prove it.
9 of the ten publish exactly that, and none of them settles for quarantine, the halfway setting that sends forgeries to spam instead of refusing them. Every one of the nine asks for aggregate reports, so somebody at each of them can see who is sending as the bank. On the sending side, all ten SPF records resolve, none is near the ten-lookup ceiling that silently breaks the record, and eight end in a hard fail. NatWest's is nothing but IP ranges, with no lookups at all.
Two go further than the record needs. Skipton and Leeds are the 2 that set strict alignment, so a signature from a look-alike subdomain does not satisfy the check. Lloyds, Nationwide and Leeds are the 3 that state a subdomain policy instead of letting subdomains inherit one. Those are the settings of a team that read the specification, and the fact that a £32bn building society sets both while £1.5tn Barclays sets neither is the pattern this study keeps finding.
Where the big four stopped
Enforcement is where HSBC, Barclays, Lloyds and NatWest stop. Not one of the four publishes MTA-STS, the record that tells sending servers mail to the bank must travel encrypted, or TLS-RPT, its companion that asks for a report when encryption fails. Lloyds is the only one of the four with a logo in the inbox through BIMI, which Gmail and Apple Mail show next to authenticated mail when the domain enforces DMARC and holds a verified mark certificate.
Yorkshire Building Society and Leeds Building Society do all of it. They are the 2 on the list with MTA-STS in enforce mode and TLS-RPT alongside, and both carry a verified logo. With Lloyds and Nationwide that puts BIMI at 4 of ten. Australia's ten largest banks, scanned nine days earlier, managed one MTA-STS record between them and it was in testing mode. Two societies in Bradford and Leeds have finished the job that the four largest banks in the country have not begun.
Neither society has a perfectly clean sweep, and the reason is below, in the keys. But the point stands: below the top four, the most complete email setups on the list belong to institutions with a few percent of HSBC's assets.
The one at none
Coventry Building Society is the second-largest society in the country, £88bn in group assets, and since January 2025 the owner of The Co-operative Bank. Its DMARC record is p=none. It carries no reporting address, so the record does not even do the one thing a monitoring policy is for. Forged mail from coventrybuildingsociety.co.uk is delivered, and nobody at Coventry is told.
The rest of Coventry's DNS reads the same way. The only DKIM key we found under a well-known selector is a self-hosted 1024-bit key; two Microsoft 365 selectors point at keys Microsoft no longer publishes. The short coventrybuildingsociety.uk has no records at all, and coventrybuildingsociety.com is also at none. Meanwhile The Co-operative Bank, the subsidiary, is at reject with two reporting vendors reading its mail flow. The society bought a bank with a better email setup than its own and left both as they were.
Two records, no policy
Since June 2014 Nominet has sold the bare .uk alongside .co.uk, and
9 of the ten own theirs; Kent Reliance is the one that never registered it. A shorter domain that carries the bank's exact name is a convincing From address, so each one was checked for the same records as the main domain.
The banks locked theirs. barclays.uk, lloydsbank.uk and natwest.uk are at reject, which makes
3 protected, and any message from them is refused whether or not the domain ever sends mail.
HSBC's is the interesting failure. hsbc.uk publishes two DMARC records: one at reject, one at none, both routing reports to Proofpoint. The DMARC specification is unambiguous about what a receiver does when it finds more than one: it stops, and treats the domain as having no policy. A domain that looks locked from one angle and monitored from another is, to every mail server on the internet, open. This is the shape of a migration that added the new record and never removed the old one, and it is invisible from inside, because nothing about outbound mail changes when a receiver ignores you.
Five short names, nothing on them
The building societies took a different path. nationwide.uk, coventrybuildingsociety.uk, ybs.uk, skipton.uk and leedsbuildingsociety.uk are registered and empty: no DMARC record, no SPF record,
5 domains with nothing at all. With HSBC's that is
6 of the nine registered short domains that a forger can use today without a receiving server having any reason to object. nationwide.uk also has a mail exchanger, so it accepts inbound mail, which usually means someone is using it.
It is not that the societies do not know how. Of the seven institutions whose .com is their own to lock,
4 have it enforced: hsbc.com, barclays.com and kentreliance.com at reject, ybs.com at quarantine. Coventry's is at none and Skipton's and Leeds's have no record. Nationwide's is out of its hands, because nationwide.com belongs to the unrelated American insurer of the same name. The .com was locked when it was registered; the .uk, a decade newer, was bought defensively and forgotten. The fix is two lines of DNS, a null SPF record and a reject DMARC record, and takes less time than reading this section. Our guides to writing a DMARC record and SPF cover both lines.
The keys
DKIM signatures are verified against a key published under a selector name the sender picks, so a scan can only look where senders usually put them. Probing the selector names that Microsoft 365, Google Workspace, Proofpoint, Mimecast, SendGrid, HubSpot and the other common platforms use by default found 18 live or retired keys across the ten, fewer than half the count the Australian banks exposed. The difference is the big banks. HSBC, Barclays, Lloyds and Skipton, 4 of the ten, have nothing under any default name, which is what a gateway-managed deployment with custom selectors looks like from outside and is not a weakness. Everything below is about what was found, not what was not.
4 of the ten still sign with at least one live 1024-bit RSA key: Nationwide, Coventry, Yorkshire and Leeds. Every major mailbox provider still accepts those, but 1024-bit RSA has been below the recommended floor since 2013 and every major mailbox provider now asks for 2048-bit. At Yorkshire and Leeds the short keys are the two corporate Microsoft 365 selectors, a tenant setting that rotates in an afternoon, and they are the only thing standing between those two societies and a clean sweep. At Nationwide it is SendGrid's second selector, which was 1024-bit at every Australian bank that used it too. Coventry's only key is a short one.
NatWest and Kent Reliance are the 2 with nothing to fix: every key found is 2048-bit and none is broken or revoked. None of this changes the headline. A forged message still fails DMARC at all nine enforcing institutions. Key hygiene is what you find when you look underneath a good policy, and it is the layer DMARC reports exist to show you.
Who does the work
In Australia two vendors received the DMARC reports for eight of the ten banks. Britain spreads the work across seven. Proofpoint takes 2, HSBC and Barclays. Agari, now part of Fortra, takes 2, Lloyds and Nationwide. Netcraft reads for NatWest, Red Sift for Yorkshire, Mimecast's DMARC Analyzer for Kent Reliance. Leeds sends its reports both to Valimail and to its own mailbox, Skipton keeps them entirely in-house, and Coventry asks for none.
Inbound mail is just as scattered. Proofpoint sits in front of HSBC and Barclays. Lloyds and Yorkshire route straight into Microsoft 365 with no third-party gateway. Mimecast fronts Skipton and Kent Reliance, Nationwide runs through Broadcom's former Symantec cloud, Coventry through Forcepoint, and NatWest and Leeds operate their own mail exchangers. Six arrangements for ten institutions, and no correlation we could find between the vendor at the door and the quality of the records behind it. The two societies with the best DNS use Microsoft's built-in filtering and a self-run mail server respectively.
The full table
Every institution, the domain scanned, and every record read. The CSV adds the DKIM selector inventory, the state of each .uk and .com twin, the inbound gateway and the reason behind every domain choice.
10 banks, ranked by group total assets · Download CSV
| # | Bank | DMARC | SPF | DKIM keys | BIMI | Transport | .uk domain | Inbound mail |
|---|---|---|---|---|---|---|---|---|
| 1 | HSBChsbc.co.uk · £2,404bn | rejectreports to Proofpoint | ✓ soft fail1 of 10 lookups | 1024 only0 × 2048-bit · 0 × 1024-bit | — | — | invalidhsbc.uk | Proofpoint |
| 2 | Barclaysbarclays.co.uk · £1,544bn | rejectreports to Proofpoint | ✓ hard fail1 of 10 lookups | 1024 only0 × 2048-bit · 0 × 1024-bit | — | — | rejectbarclays.uk · accepts mail | Proofpoint |
| 3 | Lloyds Banklloydsbank.com · £944bn | rejectsubdomains reject · reports to Agari | ✓ hard fail5 of 10 lookups | 1024 only0 × 2048-bit · 0 × 1024-bit | ✓ with VMC | — | rejectlloydsbank.uk · accepts mail | Microsoft 365 |
| 4 | NatWestnatwest.com · £715bn | rejectreports to Netcraft | ✓ hard fail0 of 10 lookups | clean1 × 2048-bit · 0 × 1024-bit | — | — | rejectnatwest.uk | other |
| 5 | Nationwidenationwide.co.uk · £382bn | rejectsubdomains reject · reports to Agari | ✓ soft fail5 of 10 lookups | mixed3 × 2048-bit · 1 × 1024-bit | ✓ with VMC | — | no recordnationwide.uk · accepts mail | Broadcom (Symantec) |
| 6 | Coventry Building Societycoventrybuildingsociety.co.uk · £88bn | nonereports to none | ✓ hard fail1 of 10 lookups | 1024 only0 × 2048-bit · 1 × 1024-bit · 2 retired | — | — | no recordcoventrybuildingsociety.uk | Forcepoint |
| 7 | Yorkshire Building Societyybs.co.uk · £66bn | rejectreports to Red Sift | ✓ hard fail2 of 10 lookups | mixed2 × 2048-bit · 2 × 1024-bit | ✓ with VMC | MTA-STS enforce · TLS-RPT | no recordybs.uk | Microsoft 365 |
| 8 | Skipton Building Societyskipton.co.uk · £41bn | rejectstrict alignment · reports to in-house | ✓ hard fail2 of 10 lookups | 1024 only0 × 2048-bit · 0 × 1024-bit | — | — | no recordskipton.uk | Mimecast |
| 9 | Leeds Building Societyleedsbuildingsociety.co.uk · £32bn | rejectsubdomains reject · strict alignment · reports to Valimail + in-house | ✓ hard fail6 of 10 lookups | mixed2 × 2048-bit · 2 × 1024-bit | ✓ with VMC | MTA-STS enforce · TLS-RPT | no recordleedsbuildingsociety.uk | other |
| 10 | OSB Group (Kent Reliance)kentreliance.co.uk · £31bn | rejectreports to DMARC Analyzer | ✓ hard fail6 of 10 lookups | clean2 × 2048-bit · 0 × 1024-bit | — | — | not registeredkentreliance.uk | Mimecast |
How the list was built
Who is on it. The Bank of England's lists of PRA-regulated banks and building societies, September 2026 editions, filtered to deposit-taking groups with a UK parent and ranked by consolidated group total assets at the latest financial year end. Bank figures are from the 2025 annual reports; society figures are the group assets column of the Building Societies Association's factsheet of July 2026. HSBC reports in dollars and is converted at the Bank of England's spot rate for 31 December 2025. Overseas-owned banks are out, which removes Santander UK, TSB, Bank of Ireland UK, Handelsbanken, Aldermore and Chase. Standard Chartered is British-owned but takes no retail deposits in Britain, and is out for that reason. A subsidiary counts with its parent, so Virgin Money sits inside Nationwide and The Co-operative Bank inside Coventry. OSB Group is listed under Kent Reliance, the trading name of its bank, OneSavings Bank plc.
Which domain. The customer-facing website domain of each group's UK bank or society, confirmed by fetching the homepage. HSBC and Barclays are read at hsbc.co.uk and barclays.co.uk, the domains of their ring-fenced retail banks, not the group sites. Each choice and its reason is a column in the CSV.
What was read. On 22 September 2026, over Cloudflare's resolver: the DMARC record, the SPF record and its lookup count, the MTA-STS record and policy file, the TLS-RPT record and the BIMI record, graded by the same rule as the free DMARC checker. DKIM keys were looked up under the default selector names of the common sending platforms and their sizes read from the published public key. The bare .uk, .com, .co.uk and .org.uk forms of each name were checked for DMARC, SPF and mail exchangers. Nominet no longer publishes registrant names, so a .uk twin is recorded as registered or not, and one .com known to belong to a different company is marked as such rather than counted.
What it cannot tell you. DNS is a statement of intent on one day. It does not show whether a domain has been spoofed, what filtering happens inside the institution, or which keys live under selector names we did not try. Records change, and we will re-read this list and publish what moved.
Reuse. The table, the CSV and the charts are CC BY 4.0: take them, including for commercial work, with a credit to Canny Pigeons and a link back here.
If we got you wrong. Write to gday@cannypigeons.com. We re-read the records and amend the table with a note of what changed.