Swiss Email Security Report 2026
7 in 10 Swiss company domains do not effectively protect against emails sent in their name with forged senders
An analysis of published email protection settings across 2'459'127 .ch domains.
Published 2026-08-25 · Updated 2026-09-06 · Peter Hadorn
In short: most Swiss company domains that receive email have no effective block against forged senders. Criminals could send emails that look as though they come from the company itself, for example for phishing, fake invoices or CEO fraud (someone impersonates the boss and asks for an urgent bank transfer).
Key findings
The following results cover 1'700'148 .ch domains examined and configured to receive email. These domains represent 100%.
- 1'190'194 domains (70.01%) have no effective block against forged senders.
- 226'957 domains (13.35%) use the strictest rule: block forged emails.
- The figures show a missing technical safeguard. They do not mean that a company has been hacked.
Open data and methodology: Aggregate data and verification evidence are publicly available. Aggregate data and verification.
What does this mean?
DMARC is the rule that says what should happen to a forged email: do nothing, move it to spam or block it. If that rule is missing or set to do nothing, it requests no blocking. This does not mean a company has been hacked. It is a missing technical safeguard, not a security incident.
How do Swiss email domains protect themselves?
There are three settings: do nothing, move the message to spam or block it. Only the last two request active protection. The study did not test whether receiving mail servers apply the rules.
The 70.01% combines no supported policy detected and p=none. These are observed policy tags, not full validity checks. Reporting and actual recipient handling were not verified.
What did we examine?
Source: SWITCH .ch zone snapshot. Domains without evaluable results are excluded from substantive percentages, not counted as unprotected. Unless stated otherwise, SPF, DKIM and DMARC percentages refer to domains with a non-null MX record.
Detailed results and denominators
Show detailed table
| Metric | Result | Count | Denominator | Population | Limitation |
|---|---|---|---|---|---|
| No effective block against forged senders | 70.01% | 1'190'194 | 1'700'148 | configured to receive email | The 70.01% combines no supported policy detected and p=none. These are observed policy tags, not full validity checks. Reporting and actual recipient handling were not verified. |
| Block forged emails | 13.35% | 226'957 | 1'700'148 | configured to receive email | There are three settings: do nothing, move the message to spam or block it. Only the last two request active protection. The study did not test whether receiving mail servers apply the rules. |
| SPF record detected | 86.75% | 1'474'906 | 1'700'148 | configured to receive email | An SPF record alone is not complete protection. This study does not fully resolve every include or redirect or perform complete recursive SPF evaluation under RFC 7208. |
| DKIM selector detected | 20.15% | 342'508 | 1'700'148 | configured to receive email | DKIM detection probes known provider-associated selectors. Unlisted selectors can be missed, so the detected share is a lower bound. The short-key and testing-flag percentages use only domains with a detected selector as their denominator. |
| DS record detected | 53.84% | 1'247'313 | 2'316'512 | analysed | Record presence only; no cryptographic DNSSEC validation or functional DANE test. |
SPF and detectable DKIM
An SPF record alone is not complete protection. This study does not fully resolve every include or redirect or perform complete recursive SPF evaluation under RFC 7208.
DKIM detection probes known provider-associated selectors. Unlisted selectors can be missed, so the detected share is a lower bound. The short-key and testing-flag percentages use only domains with a detected selector as their denominator.
The 31.65% is a count of short encoded public-key values among domains with a detected selector, not a measured share of weak cryptographic keys. The historical heuristic does not distinguish RSA from Ed25519, whose valid keys can be short.
Swiss email infrastructure
Provider categories match mail-server hostnames against known patterns. They do not measure market share, ownership or provider security.
Show detailed table
| Mail-server hostname category | Count | Share | Denominator | Population | Limitation |
|---|---|---|---|---|---|
| Unassigned / potentially self-hosted | 432'455 | 25.44% | 1'700'148 | configured to receive email | Hostname pattern only; does not establish actual operator, market share or security. |
| Unknown / not recognised | 405'385 | 23.84% | 1'700'148 | configured to receive email | Hostname pattern only; does not establish actual operator, market share or security. |
| Hostpoint | 348'340 | 20.49% | 1'700'148 | configured to receive email | Hostname pattern only; does not establish actual operator, market share or security. |
| Infomaniak | 178'072 | 10.47% | 1'700'148 | configured to receive email | Hostname pattern only; does not establish actual operator, market share or security. |
| Microsoft 365 | 160'129 | 9.42% | 1'700'148 | configured to receive email | Hostname pattern only; does not establish actual operator, market share or security. |
| Google Workspace | 59'683 | 3.51% | 1'700'148 | configured to receive email | Hostname pattern only; does not establish actual operator, market share or security. |
| Other hostname categories | 116'084 | 6.83% | 1'700'148 | configured to receive email | Hostname pattern only; does not establish actual operator, market share or security. |
Other DNS and transport signals
Record presence only. HTTPS policies, certificates, message transport, logo validation and reporting were not tested.
Show detailed table
| DNS record | Result | Count | Denominator | Population | Limitation |
|---|---|---|---|---|---|
| DS record detected | 53.84% | 1'247'313 | 2'316'512 | analysed | Record presence only; no cryptographic DNSSEC validation or functional DANE test. |
| TLSA record detected | 38.41% | 652'997 | 1'700'148 | configured to receive email | Record presence only; no cryptographic DNSSEC validation or functional DANE test. |
| MTA-STS TXT detected | 0.15% | 2'534 | 1'700'148 | configured to receive email | Record presence only. HTTPS policies, certificates, message transport, logo validation and reporting were not tested. |
| TLS-RPT TXT detected | 0.16% | 2'728 | 1'700'148 | configured to receive email | Record presence only. HTTPS policies, certificates, message transport, logo validation and reporting were not tested. |
| BIMI TXT detected | 0.08% | 1'312 | 1'700'148 | configured to receive email | Record presence only. HTTPS policies, certificates, message transport, logo validation and reporting were not tested. |
| CAA record detected | 1.5% | 25'491 | 1'700'148 | configured to receive email | Record presence only. HTTPS policies, certificates, message transport, logo validation and reporting were not tested. |
What this report does not measure
- Actual delivery or spam filtering
- Phishing incidents, data breaches or compromised mailboxes
- Security or quality of individual organisations or providers
- Exploitability of unresolvable mail-server names
How we measured
We queried publicly accessible domain settings. We sent no email, opened no mailboxes and made no assessments of individual companies.
We measured a fixed domain list from 12 April 2026 on 21–23 August 2026. This is not a list of all domains registered in August. The 142,615 excluded domains may differ systematically from those analysed; the findings cannot simply be extended to them.
The scanner identifies selected published tags; it does not fully validate DMARC records. It can select the first of multiple records and does not reject every malformed or duplicate tag. The percentages describe this detection method. Partial policy percentages do not prove full enforcement, and p=none does not prove that reporting is configured or monitored.
Technical terms explained
- DNS: the public directory of technical domain information.
- MX: a record naming a server for incoming email. Its absence does not always mean a domain cannot receive mail.
- SPF: lists servers authorised to send using a domain.
- DKIM: a digital signature on an outgoing message.
- DMARC: a published request for how to handle messages that fail aligned authentication checks.
| Source | SWITCH .ch zone snapshot (2026-04-12) |
|---|---|
| Measurement interval (UTC) | – |
| Method | DNS queries through public recursive resolvers; no HTTP or SMTP sessions, port scans, login attempts or email messages to the measured domains. |
| Resolvers | 1.1.1.1, 8.8.8.8, 9.9.9.9, 1.0.0.1, 8.8.4.4 |
| Methodology repository | swiss-email-security-report |
| Public | Aggregate metrics, figures, code and verification evidence. |
| Private | Domain-level inputs and observations. |
Data and verification
Download the aggregate metrics, release manifest and machine-readable attestation from the dataset page. Open aggregate dataset · Download release archive · Permanent archive with DOI.
Interpretation limits
- Known-selector DKIM probing is incomplete.
- Encoded key length does not establish cryptographic strength; short Ed25519 keys may trigger the heuristic.
- SPF include and redirect chains are not fully resolved.
- MTA-STS observations concern TXT records only, not the HTTPS policy.
- Aggregates do not assess individual organisations.
Corrections and methodology questions: Email
Cite this report
https://ki-barometer.ch/en/swiss-email-security-report/
DOI: 10.5281/zenodo.22116736
Questions and answers
How many .ch domains publish no enforcement request?
This combines no supported policy detected with p=none. 70.01% (1'190'194 domains / 1'700'148).
Does this prove an attack?
No. The study measured public DNS settings.
How do none, quarantine and reject differ?
p=none requests no special handling, p=quarantine requests quarantine, and p=reject requests rejection. The receiving system decides the outcome.
Is SPF alone enough?
No. SPF alone does not address every form of sender abuse.
How were domains measured?
Through non-invasive DNS queries to public recursive resolvers.
Why were some domains excluded?
They had no evaluable result in the measurement. Their exclusion may introduce bias. 142'615 domains / 2'459'127.
Is DKIM detection exhaustive?
No. Unknown or individual selectors may be missed.
Was message delivery tested?
No. No messages were sent or mailboxes inspected.
Which data are public?
Aggregate metrics and verification evidence are public. Domain-level observations remain private.
How should I cite this report?
Hadorn, P. (2026). Swiss Email Security Report 2026. KI-Barometer.ch.
