Email Security of DACH Municipalities

What is this?

A map of ~15,300 municipalities in Germany, Austria, and Switzerland showing how well their email domains are protected against spoofing, based on SPF and DMARC configuration.

SPF

Sender Policy Framework defines which mail servers are authorized to send email for a domain. "Good" means the record uses a hard fail (-all) policy, rejecting unauthorized senders.

DMARC

Domain-based Message Authentication, Reporting & Conformance tells receivers what to do with unauthenticated mail. "Good" means the policy is set to p=reject.

Open source & open data

Part of an ongoing research project currently in peer review. The code and data are on GitHub.

Loading map data…