Email Security Score Calculator
Score email security from SPF, DKIM and DMARC alignment plus MTA-STS, TLS reporting, filtering and impersonation controls.
Inputs
Email Security Score
50.5/ 100
Rating
D — Weak
Spoofing Protection
15.0%
Authentication Strength
59.3/ 100
Ready for p=reject
No — too much legitimate mail is unaligned; fix third-party senders before enforcing
Next Step
Move DMARC to p=reject once alignment passes 99%
Step by step
Values used
SPF record = Present, ends in ~all — 3; DKIM signing = 3; DMARC policy = p=none — 2; DMARC policy applied to = 100 % of mail; Legitimate mail passing DMARC alignment = 88 %; MTA-STS and TLS-RPT = MTA-STS in testing mode — 1; Inbound filtering capability = Sandboxing of attachments and links — 3; Impersonation and BEC controls = Display-name and lookalike-domain rules — 2
Email Security Score
score = 0.34×authentication + 0.26×spoofingProtection + 0.30×inboundFiltering + 0.10×transportSecurity, where authentication combines SPF strictness, DKIM key strength and the DMARC policy applied to your mail.
Why p=none scores near zero
Outbound spoofing is only prevented when DMARC is at quarantine or reject and applied to 100% of mail; p=none provides reporting visibility only.
Email Security Score
= 50.5 / 100
Rating
= D — Weak
Spoofing Protection
= 15.0
Authentication Strength
= 59.3 / 100
Ready for p=reject
= No — too much legitimate mail is unaligned; fix third-party senders before enforcing
Next Step
= Move DMARC to p=reject once alignment passes 99%
How it works
SPF and DKIM prove that mail is authorised; DMARC is what tells the receiving world to act when it is not, which is why a p=none record earns almost no spoofing credit however good the underlying records are. Inbound controls are scored separately and weighted heavily, because authentication does nothing against a phish sent from a lookalike domain that passes its own SPF and DKIM perfectly. The alignment figure is the practical gate on enforcement. Publishing DMARC at p=none and stopping there is the most common email-security outcome, and it leaves your domain as spoofable as it was on day one.
Formulas
Email Security Score
score = 0.34×authentication + 0.26×spoofingProtection + 0.30×inboundFiltering + 0.10×transportSecurity, where authentication combines SPF strictness, DKIM key strength and the DMARC policy applied to your mail.
- authentication
- SPF, DKIM and DMARC configuration strength
- spoofingProtection
- Credit only for quarantine or reject — p=none protects nothing
- inboundFiltering
- Sandboxing, retraction and impersonation controls
- transportSecurity
- MTA-STS enforcement and TLS reporting
Why p=none scores near zero
Outbound spoofing is only prevented when DMARC is at quarantine or reject and applied to 100% of mail; p=none provides reporting visibility only.
- p=none
- Monitoring policy — receivers take no action
- pct
- Share of mail the policy applies to
Frequently Asked Questions
How is Email Security Score calculated?
score = 0.34×authentication + 0.26×spoofingProtection + 0.30×inboundFiltering + 0.10×transportSecurity, where authentication combines SPF strictness, DKIM key strength and the DMARC policy applied to your mail. SPF and DKIM prove that mail is authorised; DMARC is what tells the receiving world to act when it is not, which is why a p=none record earns almost no spoofing credit however good the underlying records are. Inbound controls are scored separately and weighted heavily, because authentication does nothing against a phish sent from a lookalike domain that passes its own SPF and DKIM perfectly. The alignment figure is the practical gate on enforcement.
Why does Email Security Score matter?
Publishing DMARC at p=none and stopping there is the most common email-security outcome, and it leaves your domain as spoofable as it was on day one.
What values do I need to enter?
This calculator takes 8 inputs: SPF record, DKIM signing, DMARC policy, DMARC policy applied to, Legitimate mail passing DMARC alignment, MTA-STS and TLS-RPT, Inbound filtering capability, Impersonation and BEC controls. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why is 99% alignment needed before p=reject?
Because the remaining percent is legitimate mail — usually marketing platforms, ticketing systems and payroll — that will silently vanish. Aggregate DMARC reports identify those senders so they can be brought into alignment first.
Does DMARC stop business email compromise?
No. Most BEC arrives from a lookalike domain or a compromised third-party mailbox, both of which authenticate correctly. DMARC stops the exact-domain spoof; impersonation rules, external-sender banners and a payment-change verification workflow address the rest.
You might also need
- Data Loss Prevention Coverage CalculatorCommonly used together
- Deepfake Risk CalculatorCommonly used together
- Phishing Risk CalculatorCommonly used together
- Security Awareness Coverage CalculatorCommonly used together
- LLM Prompt Injection Risk CalculatorAlso in Forensics & Emerging Threats
- Enterprise Cybersecurity Health Score CalculatorAlso in Forensics & Emerging Threats