Swiss Email Security Report 2026

7 in 10 Swiss company domains do not effectively protect against emails sent in their name with forged senders

An analysis of published email protection settings across 2'459'127 .ch domains.

Published 2026-08-25 · Updated 2026-09-06 · Peter Hadorn

In short: most Swiss company domains that receive email have no effective block against forged senders. Criminals could send emails that look as though they come from the company itself, for example for phishing, fake invoices or CEO fraud (someone impersonates the boss and asks for an urgent bank transfer).

Key findings

The following results cover 1'700'148 .ch domains examined and configured to receive email. These domains represent 100%.

  • 1'190'194 domains (70.01%) have no effective block against forged senders.
  • 226'957 domains (13.35%) use the strictest rule: block forged emails.
  • The figures show a missing technical safeguard. They do not mean that a company has been hacked.

Open data and methodology: Aggregate data and verification evidence are publicly available. Aggregate data and verification.

What does this mean?

DMARC is the rule that says what should happen to a forged email: do nothing, move it to spam or block it. If that rule is missing or set to do nothing, it requests no blocking. This does not mean a company has been hacked. It is a missing technical safeguard, not a security incident.

How do Swiss email domains protect themselves?

There are three settings: do nothing, move the message to spam or block it. Only the last two request active protection. The study did not test whether receiving mail servers apply the rules.

Block forged emails
13.35%
Move to spam
16.65%
Do not block
12.91%
No matching rule found
57.1%

The 70.01% combines no supported policy detected and p=none. These are observed policy tags, not full validity checks. Reporting and actual recipient handling were not verified.

View and download charts

What did we examine?

2'459'127
.ch domains examined
2'316'512
analysed (94.2%)
142'615
not evaluable (5.8%)
1'700'148
configured to receive email (73.39%)

Source: SWITCH .ch zone snapshot. Domains without evaluable results are excluded from substantive percentages, not counted as unprotected. Unless stated otherwise, SPF, DKIM and DMARC percentages refer to domains with a non-null MX record.

Detailed results and denominators

Show detailed table
Counts, denominators, populations and measurement limits.
MetricResultCountDenominatorPopulationLimitation
No effective block against forged senders70.01%1'190'1941'700'148configured to receive emailThe 70.01% combines no supported policy detected and p=none. These are observed policy tags, not full validity checks. Reporting and actual recipient handling were not verified.
Block forged emails13.35%226'9571'700'148configured to receive emailThere are three settings: do nothing, move the message to spam or block it. Only the last two request active protection. The study did not test whether receiving mail servers apply the rules.
SPF record detected86.75%1'474'9061'700'148configured to receive emailAn SPF record alone is not complete protection. This study does not fully resolve every include or redirect or perform complete recursive SPF evaluation under RFC 7208.
DKIM selector detected20.15%342'5081'700'148configured to receive emailDKIM detection probes known provider-associated selectors. Unlisted selectors can be missed, so the detected share is a lower bound. The short-key and testing-flag percentages use only domains with a detected selector as their denominator.
DS record detected53.84%1'247'3132'316'512analysedRecord presence only; no cryptographic DNSSEC validation or functional DANE test.

SPF and detectable DKIM


An SPF record alone is not complete protection. This study does not fully resolve every include or redirect or perform complete recursive SPF evaluation under RFC 7208.

86.75%
SPF record detected
33.64%
SPF -all
28.61%
SPF ~all
19.33%
No all mechanism detected

DKIM detection probes known provider-associated selectors. Unlisted selectors can be missed, so the detected share is a lower bound. The short-key and testing-flag percentages use only domains with a detected selector as their denominator.

The 31.65% is a count of short encoded public-key values among domains with a detected selector, not a measured share of weak cryptographic keys. The historical heuristic does not distinguish RSA from Ed25519, whose valid keys can be short.

20.15%
DKIM selector detected
31.65%
Short encoded key value
7.44%
Testing flag detected

Swiss email infrastructure


Provider categories match mail-server hostnames against known patterns. They do not measure market share, ownership or provider security.

Show detailed table
Hostname categories for domains with a non-null MX record.
Mail-server hostname categoryCountShareDenominatorPopulationLimitation
Unassigned / potentially self-hosted432'45525.44%1'700'148configured to receive emailHostname pattern only; does not establish actual operator, market share or security.
Unknown / not recognised405'38523.84%1'700'148configured to receive emailHostname pattern only; does not establish actual operator, market share or security.
Hostpoint348'34020.49%1'700'148configured to receive emailHostname pattern only; does not establish actual operator, market share or security.
Infomaniak178'07210.47%1'700'148configured to receive emailHostname pattern only; does not establish actual operator, market share or security.
Microsoft 365160'1299.42%1'700'148configured to receive emailHostname pattern only; does not establish actual operator, market share or security.
Google Workspace59'6833.51%1'700'148configured to receive emailHostname pattern only; does not establish actual operator, market share or security.
Other hostname categories116'0846.83%1'700'148configured to receive emailHostname pattern only; does not establish actual operator, market share or security.

Other DNS and transport signals

Record presence only. HTTPS policies, certificates, message transport, logo validation and reporting were not tested.

Show detailed table
Counts, denominators, populations and measurement limits.
DNS recordResultCountDenominatorPopulationLimitation
DS record detected53.84%1'247'3132'316'512analysedRecord presence only; no cryptographic DNSSEC validation or functional DANE test.
TLSA record detected38.41%652'9971'700'148configured to receive emailRecord presence only; no cryptographic DNSSEC validation or functional DANE test.
MTA-STS TXT detected0.15%2'5341'700'148configured to receive emailRecord presence only. HTTPS policies, certificates, message transport, logo validation and reporting were not tested.
TLS-RPT TXT detected0.16%2'7281'700'148configured to receive emailRecord presence only. HTTPS policies, certificates, message transport, logo validation and reporting were not tested.
BIMI TXT detected0.08%1'3121'700'148configured to receive emailRecord presence only. HTTPS policies, certificates, message transport, logo validation and reporting were not tested.
CAA record detected1.5%25'4911'700'148configured to receive emailRecord presence only. HTTPS policies, certificates, message transport, logo validation and reporting were not tested.

What this report does not measure


  • Actual delivery or spam filtering
  • Phishing incidents, data breaches or compromised mailboxes
  • Security or quality of individual organisations or providers
  • Exploitability of unresolvable mail-server names

How we measured


We queried publicly accessible domain settings. We sent no email, opened no mailboxes and made no assessments of individual companies.

We measured a fixed domain list from 12 April 2026 on 21–23 August 2026. This is not a list of all domains registered in August. The 142,615 excluded domains may differ systematically from those analysed; the findings cannot simply be extended to them.

The scanner identifies selected published tags; it does not fully validate DMARC records. It can select the first of multiple records and does not reject every malformed or duplicate tag. The percentages describe this detection method. Partial policy percentages do not prove full enforcement, and p=none does not prove that reporting is configured or monitored.

Technical terms explained

  • DNS: the public directory of technical domain information.
  • MX: a record naming a server for incoming email. Its absence does not always mean a domain cannot receive mail.
  • SPF: lists servers authorised to send using a domain.
  • DKIM: a digital signature on an outgoing message.
  • DMARC: a published request for how to handle messages that fail aligned authentication checks.
SourceSWITCH .ch zone snapshot (2026-04-12)
Measurement interval (UTC)
MethodDNS queries through public recursive resolvers; no HTTP or SMTP sessions, port scans, login attempts or email messages to the measured domains.
Resolvers1.1.1.1, 8.8.8.8, 9.9.9.9, 1.0.0.1, 8.8.4.4
Methodology repositoryswiss-email-security-report
PublicAggregate metrics, figures, code and verification evidence.
PrivateDomain-level inputs and observations.

Data and verification

Download the aggregate metrics, release manifest and machine-readable attestation from the dataset page. Open aggregate dataset · Download release archive · Permanent archive with DOI.

Interpretation limits

  • Known-selector DKIM probing is incomplete.
  • Encoded key length does not establish cryptographic strength; short Ed25519 keys may trigger the heuristic.
  • SPF include and redirect chains are not fully resolved.
  • MTA-STS observations concern TXT records only, not the HTTPS policy.
  • Aggregates do not assess individual organisations.

Corrections and methodology questions:

Cite this report

Hadorn, P. (2026). Swiss Email Security Report 2026. KI-Barometer.ch.
https://ki-barometer.ch/en/swiss-email-security-report/
DOI: 10.5281/zenodo.22116736

Questions and answers


How many .ch domains publish no enforcement request?

This combines no supported policy detected with p=none. 70.01% (1'190'194 domains / 1'700'148).

Does this prove an attack?

No. The study measured public DNS settings.

How do none, quarantine and reject differ?

p=none requests no special handling, p=quarantine requests quarantine, and p=reject requests rejection. The receiving system decides the outcome.

Is SPF alone enough?

No. SPF alone does not address every form of sender abuse.

How were domains measured?

Through non-invasive DNS queries to public recursive resolvers.

Why were some domains excluded?

They had no evaluable result in the measurement. Their exclusion may introduce bias. 142'615 domains / 2'459'127.

Is DKIM detection exhaustive?

No. Unknown or individual selectors may be missed.

Was message delivery tested?

No. No messages were sent or mailboxes inspected.

Which data are public?

Aggregate metrics and verification evidence are public. Domain-level observations remain private.

How should I cite this report?

Hadorn, P. (2026). Swiss Email Security Report 2026. KI-Barometer.ch.