Skip to content
Calcrivo

Email Security Score Calculator

Score email security from SPF, DKIM and DMARC alignment plus MTA-STS, TLS reporting, filtering and impersonation controls.

Inputs

% of mail
%

Email Security Score

50.5/ 100

Rating

D — Weak

Spoofing Protection

15.0%

Authentication Strength

59.3/ 100

Ready for p=reject

No — too much legitimate mail is unaligned; fix third-party senders before enforcing

Next Step

Move DMARC to p=reject once alignment passes 99%

Step by step

  1. Values used

    SPF record = Present, ends in ~all — 3; DKIM signing = 3; DMARC policy = p=none — 2; DMARC policy applied to = 100 % of mail; Legitimate mail passing DMARC alignment = 88 %; MTA-STS and TLS-RPT = MTA-STS in testing mode — 1; Inbound filtering capability = Sandboxing of attachments and links — 3; Impersonation and BEC controls = Display-name and lookalike-domain rules — 2

  2. Email Security Score

    score = 0.34×authentication + 0.26×spoofingProtection + 0.30×inboundFiltering + 0.10×transportSecurity, where authentication combines SPF strictness, DKIM key strength and the DMARC policy applied to your mail.

  3. Why p=none scores near zero

    Outbound spoofing is only prevented when DMARC is at quarantine or reject and applied to 100% of mail; p=none provides reporting visibility only.

  4. Email Security Score

    = 50.5 / 100

  5. Rating

    = D — Weak

  6. Spoofing Protection

    = 15.0

  7. Authentication Strength

    = 59.3 / 100

  8. Ready for p=reject

    = No — too much legitimate mail is unaligned; fix third-party senders before enforcing

  9. Next Step

    = Move DMARC to p=reject once alignment passes 99%

How it works

SPF and DKIM prove that mail is authorised; DMARC is what tells the receiving world to act when it is not, which is why a p=none record earns almost no spoofing credit however good the underlying records are. Inbound controls are scored separately and weighted heavily, because authentication does nothing against a phish sent from a lookalike domain that passes its own SPF and DKIM perfectly. The alignment figure is the practical gate on enforcement. Publishing DMARC at p=none and stopping there is the most common email-security outcome, and it leaves your domain as spoofable as it was on day one.

Formulas

Email Security Score

score = 0.34×authentication + 0.26×spoofingProtection + 0.30×inboundFiltering + 0.10×transportSecurity, where authentication combines SPF strictness, DKIM key strength and the DMARC policy applied to your mail.

authentication
SPF, DKIM and DMARC configuration strength
spoofingProtection
Credit only for quarantine or reject — p=none protects nothing
inboundFiltering
Sandboxing, retraction and impersonation controls
transportSecurity
MTA-STS enforcement and TLS reporting

Why p=none scores near zero

Outbound spoofing is only prevented when DMARC is at quarantine or reject and applied to 100% of mail; p=none provides reporting visibility only.

p=none
Monitoring policy — receivers take no action
pct
Share of mail the policy applies to

Frequently Asked Questions

How is Email Security Score calculated?

score = 0.34×authentication + 0.26×spoofingProtection + 0.30×inboundFiltering + 0.10×transportSecurity, where authentication combines SPF strictness, DKIM key strength and the DMARC policy applied to your mail. SPF and DKIM prove that mail is authorised; DMARC is what tells the receiving world to act when it is not, which is why a p=none record earns almost no spoofing credit however good the underlying records are. Inbound controls are scored separately and weighted heavily, because authentication does nothing against a phish sent from a lookalike domain that passes its own SPF and DKIM perfectly. The alignment figure is the practical gate on enforcement.

Why does Email Security Score matter?

Publishing DMARC at p=none and stopping there is the most common email-security outcome, and it leaves your domain as spoofable as it was on day one.

What values do I need to enter?

This calculator takes 8 inputs: SPF record, DKIM signing, DMARC policy, DMARC policy applied to, Legitimate mail passing DMARC alignment, MTA-STS and TLS-RPT, Inbound filtering capability, Impersonation and BEC controls. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why is 99% alignment needed before p=reject?

Because the remaining percent is legitimate mail — usually marketing platforms, ticketing systems and payroll — that will silently vanish. Aggregate DMARC reports identify those senders so they can be brought into alignment first.

Does DMARC stop business email compromise?

No. Most BEC arrives from a lookalike domain or a compromised third-party mailbox, both of which authenticate correctly. DMARC stops the exact-domain spoof; impersonation rules, external-sender banners and a payment-change verification workflow address the rest.

You might also need