Research / original data
India Email Authentication Census 2026: DMARC, SPF and BIMI at Banks, Insurers and the Nifty 100
By Madhurendra Sachan. Published by Hunto.
Published ; data as of .
Indian banks have mostly shut the door on exact-domain email spoofing; the rest of Indian finance and industry has not. On 2026-10-04, 38 of 45 domestic commercial banks (84%) published DMARC p=reject, against 57 of 96 Nifty 100 companies (59%) and 34 of 60 IRDAI-registered insurers (57%). The banks' newer .bank.in domains lag behind their main email domains.
Key numbers
- Of 45 Indian public sector, private, small finance and payments banks scanned on 2026-10-04, 38 (84%) publish a DMARC policy of p=reject, and all 45 enforce DMARC at either reject or quarantine.
- Of 113 scheduled commercial banks on the RBI list scanned on 2026-10-04 (including regional rural banks and the group domains of foreign banks), 74 (65%) publish p=reject and 5 (4%) publish no DMARC record at all.
- The .bank.in web domains lag the banks' main email domains: of the 49 .bank.in domains the RBI lists for domestic commercial banks, scanned on 2026-10-04, 8 (16%) have no DMARC record, even though all 8 of those banks publish DMARC on their main email domain. Across all 93 .bank.in domains that resolve, 20 (22%) have no DMARC record.
- Of 96 Nifty 100 companies scanned on 2026-10-04, 57 (59%) publish p=reject and 8 (8%) publish no DMARC record.
- Of 60 insurers registered with IRDAI scanned on 2026-10-04, 34 (57%) publish p=reject, 22 (37%) stop at p=quarantine and 2 (3%) have no DMARC record.
- Of 17 NBFCs in the RBI upper layer for 2026-27 scanned on 2026-10-04, 9 (53%) publish p=reject; 1 publishes a DMARC setup that mail receivers must ignore (two records on one domain).
- Brand logos in the inbox are still rare outside private banks: on 2026-10-04, 13 of 18 private sector banks (72%) publish a BIMI record, against 2 of 12 public sector banks (17%) and 26 of 96 Nifty 100 companies (27%).
- MTA-STS, which stops attackers from forcing mail in transit onto an unencrypted connection, is almost absent: on 2026-10-04, 1 of 45 domestic commercial banks, 3 of 96 Nifty 100 companies and 3 of 60 insurers publish it.
- SPF is near universal but often soft: on 2026-10-04, 28 of 45 (62%) domestic commercial banks end their SPF record with a hard fail (-all) and 17 use a soft fail (~all). Among insurers the split is 27 hard fail and 30 soft fail out of 60.
DMARC by sector
"Listed" is the number of organisations on the official list. "Scanned" is the number whose domain we could verify; only these count in the percentages. "Broken record" means a DMARC setup receivers must ignore, such as two records on one domain. "Enforced" means p=reject or p=quarantine applied to 100% of mail.
| Group | Listed | Scanned (verified) | Any DMARC record | p=reject | p=quarantine | p=none | Broken record | No DMARC | Enforced (reject or quarantine, pct 100) | rua reporting set |
|---|---|---|---|---|---|---|---|---|---|---|
| All scheduled commercial banks on the RBI list (primary domain) | 121 | 113 | 108 (96%) | 74 (65%) | 24 (21%) | 10 (9%) | 0 | 5 (4%) | 98 (87%) | 97 (86%) |
| Domestic commercial banks (public, private, small finance, payments) | 49 | 45 | 45 (100%) | 38 (84%) | 7 (16%) | 0 (0%) | 0 | 0 (0%) | 45 (100%) | 43 (96%) |
| Public sector banks | 12 | 12 | 12 (100%) | 10 (83%) | 2 (17%) | 0 (0%) | 0 | 0 (0%) | 12 (100%) | 11 (92%) |
| Private sector banks | 21 | 18 | 18 (100%) | 17 (94%) | 1 (6%) | 0 (0%) | 0 | 0 (0%) | 18 (100%) | 18 (100%) |
| Small finance banks | 11 | 10 | 10 (100%) | 8 (80%) | 2 (20%) | 0 (0%) | 0 | 0 (0%) | 10 (100%) | 9 (90%) |
| Payments banks | 5 | 5 | 5 (100%) | 3 (60%) | 2 (40%) | 0 (0%) | 0 | 0 (0%) | 5 (100%) | 5 (100%) |
| Foreign banks in India (group domain) | 44 | 41 | 38 (93%) | 28 (68%) | 6 (15%) | 4 (10%) | 0 | 3 (7%) | 34 (83%) | 34 (83%) |
| Regional rural banks (.bank.in domain) | 28 | 27 | 25 (93%) | 8 (30%) | 11 (41%) | 6 (22%) | 0 | 2 (7%) | 19 (70%) | 20 (74%) |
| RBI-listed .bank.in website domains (all banks that have one) | 94 | 93 | 73 (78%) | 48 (52%) | 16 (17%) | 9 (10%) | 0 | 20 (22%) | 63 (68%) | 64 (69%) |
| .bank.in domains of domestic commercial banks | 49 | 49 | 41 (84%) | 35 (71%) | 4 (8%) | 2 (4%) | 0 | 8 (16%) | 38 (78%) | 39 (80%) |
| Nifty 100 companies | 100 | 96 | 88 (92%) | 57 (59%) | 25 (26%) | 6 (6%) | 0 | 8 (8%) | 82 (85%) | 85 (89%) |
| Insurers registered with IRDAI | 62 | 60 | 58 (97%) | 34 (57%) | 22 (37%) | 2 (3%) | 0 | 2 (3%) | 55 (92%) | 56 (93%) |
| Life insurers | 26 | 25 | 24 (96%) | 16 (64%) | 8 (32%) | 0 (0%) | 0 | 1 (4%) | 24 (96%) | 23 (92%) |
| General insurers | 28 | 27 | 27 (100%) | 15 (56%) | 10 (37%) | 2 (7%) | 0 | 0 (0%) | 24 (89%) | 27 (100%) |
| Standalone health insurers | 8 | 8 | 7 (88%) | 3 (38%) | 4 (50%) | 0 (0%) | 0 | 1 (12%) | 7 (88%) | 6 (75%) |
| NBFCs (RBI upper layer) | 17 | 17 | 16 (94%) | 9 (53%) | 5 (29%) | 1 (6%) | 1 | 1 (6%) | 14 (82%) | 13 (76%) |
SPF, BIMI, MTA-STS and DKIM by sector
The DKIM column is best effort: we looked for a key at five common selectors, and a domain can sign with a selector we did not try. Do not quote it as adoption.
| Group | Scanned | SPF record | SPF -all | SPF ~all | SPF ?all or +all | SPF without an all term | More than one SPF record | Over 10 SPF DNS lookups | MX | BIMI | MTA-STS | TLS-RPT | DKIM key at a common selector (best effort) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| All scheduled commercial banks on the RBI list (primary domain) | 113 | 112 (99%) | 78 (69%) | 32 (28%) | 0 | 0 | 2 | 3 | 113 | 29 (26%) | 2 (2%) | 2 (2%) | 62 (55%) |
| Domestic commercial banks (public, private, small finance, payments) | 45 | 45 (100%) | 28 (62%) | 17 (38%) | 0 | 0 | 0 | 1 | 45 | 19 (42%) | 1 (2%) | 1 (2%) | 30 (67%) |
| Public sector banks | 12 | 12 (100%) | 9 (75%) | 3 (25%) | 0 | 0 | 0 | 0 | 12 | 2 (17%) | 1 (8%) | 1 (8%) | 9 (75%) |
| Private sector banks | 18 | 18 (100%) | 14 (78%) | 4 (22%) | 0 | 0 | 0 | 0 | 18 | 13 (72%) | 0 (0%) | 0 (0%) | 12 (67%) |
| Small finance banks | 10 | 10 (100%) | 3 (30%) | 7 (70%) | 0 | 0 | 0 | 0 | 10 | 3 (30%) | 0 (0%) | 0 (0%) | 7 (70%) |
| Payments banks | 5 | 5 (100%) | 2 (40%) | 3 (60%) | 0 | 0 | 0 | 1 | 5 | 1 (20%) | 0 (0%) | 0 (0%) | 2 (40%) |
| Foreign banks in India (group domain) | 41 | 40 (98%) | 29 (71%) | 10 (24%) | 0 | 0 | 1 | 2 | 41 | 9 (22%) | 1 (2%) | 1 (2%) | 16 (39%) |
| Regional rural banks (.bank.in domain) | 27 | 27 (100%) | 21 (78%) | 5 (19%) | 0 | 0 | 1 | 0 | 27 | 1 (4%) | 0 (0%) | 0 (0%) | 16 (59%) |
| RBI-listed .bank.in website domains (all banks that have one) | 93 | 72 (77%) | 53 (57%) | 16 (17%) | 0 | 1 | 2 | 0 | 68 | 13 (14%) | 0 (0%) | 0 (0%) | 45 (48%) |
| .bank.in domains of domestic commercial banks | 49 | 39 (80%) | 28 (57%) | 9 (18%) | 0 | 1 | 1 | 0 | 37 | 13 (27%) | 0 (0%) | 0 (0%) | 26 (53%) |
| Nifty 100 companies | 96 | 93 (97%) | 63 (66%) | 28 (29%) | 1 | 1 | 0 | 5 | 96 | 26 (27%) | 3 (3%) | 2 (2%) | 75 (78%) |
| Insurers registered with IRDAI | 60 | 58 (97%) | 27 (45%) | 30 (50%) | 0 | 1 | 0 | 4 | 60 | 17 (28%) | 3 (5%) | 3 (5%) | 47 (78%) |
| Life insurers | 25 | 24 (96%) | 11 (44%) | 12 (48%) | 0 | 1 | 0 | 1 | 25 | 8 (32%) | 1 (4%) | 1 (4%) | 21 (84%) |
| General insurers | 27 | 27 (100%) | 13 (48%) | 14 (52%) | 0 | 0 | 0 | 2 | 27 | 8 (30%) | 2 (7%) | 2 (7%) | 21 (78%) |
| Standalone health insurers | 8 | 7 (88%) | 3 (38%) | 4 (50%) | 0 | 0 | 0 | 1 | 8 | 1 (12%) | 0 (0%) | 0 (0%) | 5 (62%) |
| NBFCs (RBI upper layer) | 17 | 17 (100%) | 10 (59%) | 7 (41%) | 0 | 0 | 0 | 3 | 17 | 3 (18%) | 0 (0%) | 1 (6%) | 15 (88%) |
The groups overlap on purpose. Banks, insurers and NBFCs that are also in the Nifty 100 appear in both their sector row and the Nifty 100 row. The .bank.in rows are a second view of the same banks, using the web domain the RBI links to rather than the main email domain.
Download the sector table (CSV)Sector rows only, no organisation names. Licensed CC BY 4.0.
What this means for a bank or insurer security team
- Finish the move to p=reject. Quarantine sends spoofed mail to the spam folder, where a customer can still find it and act on it. If your aggregate reports show every legitimate sender passing, going from quarantine to reject is a one-line DNS change. Among insurers, 22 of 60 stopped at quarantine.
- Put DMARC on every domain you own, starting with .bank.in. A domain with no DMARC record gives receivers no instruction to refuse mail that claims to come from it. A domain that never sends mail can carry p=reject and an SPF record of v=spf1 -all from day one.
- Keep reporting on. A rua address is how you see who is sending as you, including the vendor nobody told you about.
- Publish MTA-STS and TLS-RPT. They are two small DNS records and a policy file, and they stop a network attacker from quietly stripping encryption off mail sent to you.
- Add BIMI once you are at enforcement. BIMI only works with DMARC at quarantine or reject, and most large mailbox providers also want a mark certificate before they show the logo. A verified logo is a cue customers can check at a glance.
- Tighten SPF to -all once your reports are clean. With DMARC at reject a soft fail is not an open door, but a hard fail is clearer to receivers that do not apply DMARC.
None of this stops lookalike domains, which pass every check because the attacker owns them. That needs monitoring and takedown, covered by our DMARC+ and brand protection agents.
Email spoofing is one exposure class among several. To track it next to exposed assets, leaked credentials and supplier risk, see exposure management (UEMP) and our guide to continuous threat exposure management (CTEM).
Method
Who is in scope. All lists were fetched on 2026-10-04 unless noted.
- Banks: every bank in the scheduled commercial banks section of the RBI page Banks in India: 12 public sector, 21 private sector, 11 small finance, 5 payments, 28 regional rural and 44 foreign banks.
- Nifty 100: the constituent file ind_nifty100list.csv from niftyindices.com.
- Insurers: the IRDAI lists of life, general and standalone health insurers. Reinsurers are not included.
- NBFCs: the 17 companies in the RBI press release of 2026-08-06 naming the NBFC upper layer for 2026-27.
Which domain we scan. For each organisation we scan its primary email domain, the domain its staff and customer mail comes from. A candidate domain counts only if it has an MX record and at least one piece of ownership evidence: it is the domain on the official list; its website redirects to the listed site; the official site publishes email addresses or links on that domain; the domain's own home page names the organisation; or a recorded manual check (23 rows). For banks we also scan, as a separate row, the .bank.in domain the RBI page links to. Those rows are verified by the RBI listing and a DNS answer and do not need MX.
What we query. Public DNS only: Cloudflare 1.1.1.1 first, Google 8.8.8.8 as fallback, three tries per resolver on timeouts. The DMARC lookup is repeated against 8.8.8.8 and the answers compared; they matched for every scanned domain. Per domain we read the _dmarc record (count, p, sp, pct, rua and whether the setup is broken); SPF (count, the all qualifier, following redirect= when there is no all term, and a recursive count of DNS-querying terms against the limit of 10); MX; BIMI at default._bimi; MTA-STS at _mta-sts; TLS-RPT at _smtp._tls; and, best effort only, a DKIM key at the selectors google, selector1, selector2, default or k1.
Date. Every lookup ran on 2026-10-04 (UTC).
Limitations
- A snapshot. Records can change any day. Every figure is as of 2026-10-04.
- Policy is not protection. DMARC tells receivers what to do with mail that fails checks. It does not prove a domain is never spoofed, and it does nothing about lookalike domains.
- Unverified rows are excluded. 15 rows could not be verified and are not counted: 8 bank primary domains, 1 bank .bank.in domain, 2 insurers and 4 Nifty 100 companies. Most are sites that block automated requests, or a listed website domain with no MX where we could not tie a mail domain to the site.
- Parent and group domains. Foreign banks are scanned on their global group domain, so those rows describe the parent group, not an India-only setup. The same applies to Nifty 100 subsidiaries of global companies that use the parent's domain.
- One domain per organisation. Large groups send from several domains. A strong record on the main one does not mean every brand or subsidiary domain is covered.
- Shared domains. Some organisations share an email domain, and each one counts separately. In the Nifty 100, 96 scanned companies map to 89 distinct domains; among insurers, 60 map to 58.
- DKIM is best effort. Selectors cannot be listed through DNS. A domain with no key at our five selectors may still sign every message with another one.
- List coverage. The RBI page as fetched lists 5 payments banks; any bank missing from that page is missing here.
- Not mapped to regulation. We report what the DNS says, not whether any organisation meets a regulator's expectations.
We publish sector totals only. We have not named any organisation and will not.
How to cite
The data on this page is licensed CC BY 4.0. Quote any key number with its date and link back here. Suggested citation:
Sachan, M. (2026). India Email Authentication Census 2026: DMARC, SPF and BIMI at Banks, Insurers and the Nifty 100. Hunto. Published 2026-10-05; data as of 2026-10-04. https://hunto.ai/research/india-dmarc-census-2026/
Found an error? Write to [email protected] with the page URL. See also our research methodology.