Home / Cybersecurity / Email security barometer 2026

Barometer · 2026-09-28 · 309 organisations · NL · BE · LU

More than 1 in 4 large organisations can still be impersonated by email.

We checked the public email protection of 333 organisations headquartered in the Netherlands, Belgium and Luxembourg. 26.9% of those that receive email have no enforced DMARC policy: anyone can send email in their name and it is delivered. Only 3.9% force encrypted delivery of their incoming mail. The smaller the organisation, the more exposed it is.

26.9%can be spoofed by email
44.0%block fake emails (DMARC reject)
3.9%enforce encrypted inbound mail
73/100median score

→ Check your own domain (free)

Grades

A · 29 (9%)B · 155 (50%)C · 82 (27%)D · 30 (10%)E · 10 (3%)F · 3 (1%)

What they have in place

Can be spoofed (DMARC missing or p=none)26.9%
DMARC enforced (quarantine or reject)73.1%
DMARC p=reject (strongest)44.0%
DKIM key found (common selectors)84.1%
SPF missing or too permissive4.5%
MTA-STS enforced (encrypted inbound mail)3.9%
TLS-RPT reporting9.4%
DNSSEC signed zone36.6%
Website sends HSTS67.3%
Website sends a Content-Security-Policy42.4%

By country

CountryOrganisationsSpoofableDMARC rejectDKIM foundMTA-STSDNSSECMedian score
Netherlands17625.0%46.0%85.8%3.4%44.9%74
Belgium10329.1%43.7%84.5%4.9%24.3%72
Luxembourg3030.0%33.3%73.3%3.3%30.0%74

By size

Mid-sized organisations are the most exposed — and they are exactly the ones NIS2 now brings into scope as important entities.

SizeOrganisationsSpoofableDMARC enforcedMTA-STSMedian score
50-999 staff13738.7%61.3%1.5%69
1,000-9,999 staff12218.9%81.1%4.9%77
10,000+ staff5014.0%86.0%8.0%75

What this means

Method

Related

Frequently asked questions

Which organisations were checked?

333 organisations headquartered in the Netherlands, Belgium or Luxembourg, with at least 50 staff and an official website listed in Wikidata (open data). 309 of them receive email (MX record) and are counted in the statistics.

Is this legal and non-intrusive?

Yes. We only read public DNS records and public website headers — the same data every mail server and browser reads. No system was scanned, probed or accessed.

Can I see the score of a specific company?

We never publish individual results. Any company can check its own domain for free with our email security check.

Can I quote these figures?

Yes, with a link to this page: “Email security barometer 2026, CyberNovaLabs.io”.

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

Free first call · English

Is your company in the red?

Tell us your domain: an English-speaking advisor replies within one business day with your result and the exact fixes.

  • Reply within one business day
  • Written scope and price before any work
  • Netherlands · Belgium · Luxembourg

Prefer email? Write to contact@cybernovalabs.io

→ Free cybersecurity call