Home / Cybersecurity / Email security barometer 2026
More than 1 in 4 large organisations can still be impersonated by email.
We checked the public email protection of 333 organisations headquartered in the Netherlands, Belgium and Luxembourg. 26.9% of those that receive email have no enforced DMARC policy: anyone can send email in their name and it is delivered. Only 3.9% force encrypted delivery of their incoming mail. The smaller the organisation, the more exposed it is.
→ Check your own domain (free)
Grades
What they have in place
By country
| Country | Organisations | Spoofable | DMARC reject | DKIM found | MTA-STS | DNSSEC | Median score |
|---|---|---|---|---|---|---|---|
| Netherlands | 176 | 25.0% | 46.0% | 85.8% | 3.4% | 44.9% | 74 |
| Belgium | 103 | 29.1% | 43.7% | 84.5% | 4.9% | 24.3% | 72 |
| Luxembourg | 30 | 30.0% | 33.3% | 73.3% | 3.3% | 30.0% | 74 |
By size
Mid-sized organisations are the most exposed — and they are exactly the ones NIS2 now brings into scope as important entities.
| Size | Organisations | Spoofable | DMARC enforced | MTA-STS | Median score |
|---|---|---|---|---|---|
| 50-999 staff | 137 | 38.7% | 61.3% | 1.5% | 69 |
| 1,000-9,999 staff | 122 | 18.9% | 81.1% | 4.9% | 77 |
| 10,000+ staff | 50 | 14.0% | 86.0% | 8.0% | 75 |
What this means
- Impersonation is the first step of invoice fraud and phishing. Without an enforced DMARC policy, a fraudster can send an email from finance@yourcompany that lands in your customers' inbox.
- NIS2 asks for it. Secured communications and basic cyber hygiene are among the ten minimum measures; email protection is one of the first things auditors and customers check.
- It is cheap to fix. SPF, DKIM and DMARC are DNS changes: a few hours of work, done in steps so that no legitimate email is blocked.
Method
- Population: 333 organisations with headquarters in NL, BE or LU, 50+ staff and an official website in Wikidata (open data, retrieved 2026-09-28); 309 receive email and are counted.
- Checks: SPF, DKIM (20 common selectors — a custom selector may be missed), DMARC, MTA-STS, TLS-RPT, DNSSEC and website headers (HTTPS, HSTS, CSP, X-Content-Type-Options, framing, Referrer-Policy), with the same engine as our free email security check.
- Passive only: public DNS (DNS-over-HTTPS) and a single request to the public website. No scan, no probe.
- Only aggregated results are published. Figures rounded to one decimal.
Related
Frequently asked questions
Which organisations were checked?
333 organisations headquartered in the Netherlands, Belgium or Luxembourg, with at least 50 staff and an official website listed in Wikidata (open data). 309 of them receive email (MX record) and are counted in the statistics.
Is this legal and non-intrusive?
Yes. We only read public DNS records and public website headers — the same data every mail server and browser reads. No system was scanned, probed or accessed.
Can I see the score of a specific company?
We never publish individual results. Any company can check its own domain for free with our email security check.
Can I quote these figures?
Yes, with a link to this page: “Email security barometer 2026, CyberNovaLabs.io”.
Security Briefing
One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.
Is your company in the red?
Tell us your domain: an English-speaking advisor replies within one business day with your result and the exact fixes.
- Reply within one business day
- Written scope and price before any work
- Netherlands · Belgium · Luxembourg