Where French banks stand on DMARC
By Thomas · virtual CISO · August 22, 2026
No sector attracts impersonators the way banking does. An email that appears to come from a bank opens doors no other sender can open: it gets a "security alert" clicked, a "new payee" approved, an "advisor" called back who does not exist. In France, fake-bank-advisor fraud — a scourge of recent years — very often starts with a preparatory message dressed in the institution's colors, and the displayed sender address is precisely what DMARC knows how to authenticate. A bank's domain name is a trust asset; that trust is exactly what phishing hijacks.
"Where do French banks stand on DMARC" is therefore not an engineer's idle curiosity: it is an indicator of how safe the email channel really is for tens of millions of customers. And the question calls for measurement, not impressions. "The sector is ahead" and "the sector is lagging" circulate side by side, sometimes on the same day, with neither claim resting on an actual reading. The good news: the answer is publicly verifiable. A DMARC policy sits in public DNS, in plain sight of everyone; all it takes is reading it out, institution by institution, month after month.
That is precisely what dmarc.com's sector barometer does. This article does not copy out "this month's numbers" — frozen into a post, they would be stale within a quarter. It provides the reading grid instead: what gets measured and how, what the statuses actually mean, the structural patterns this kind of corpus keeps surfacing, what regulation changes — and then points to the monthly edition for the up-to-date measurement.
Why banking is DMARC's proving ground
Banking combines three characteristics that make it the ideal observation ground for DMARC deployment.
First, exposure. Phishing analyses place finance at the top of the most-imitated sectors year after year, across every geography. No surprise there: impersonating a bank monetizes directly — a diverted wire transfer, online-banking credentials, a card that "urgently needs reactivating". Where impersonating a retailer steals a loyalty account, impersonating a bank empties a current account. Offensive pressure on banking domains is therefore maximal, at all times.
Second, the deliverability stakes. A bank sends critical mail: statements, security alerts, regulatory notices, transaction confirmations. A legitimate message landing in spam is not a marketing annoyance, it is a service incident. Since 2024, Gmail and Yahoo have required DMARC authentication of bulk senders, and Microsoft followed suit in 2025: for a banking sender, authentication is no longer a technical option but a delivery condition.
Third, the means. The sector has well-staffed security teams, compliance budgets, an attentive regulator. If any sector can reach p=reject across its whole perimeter, it is this one. Its actual position therefore measures the ceiling of what other sectors can aim for: banking is DMARC's full-scale test. The sector's specific stakes — critical flows, sending vendors, subsidiary alignment — are examined in detail in the banking case, covered in detail.
What the Observatory measures, and how
The DMARC Observatory at dmarc.com tracks a corpus of French banking domains — the institutions' main domains, the ones customers know and fraudsters imitate — and reads them from public DNS. Nothing intrusive about the method: the measurement reads what any resolver sees. The TXT record at _dmarc.example.com, the p= policy it declares, the fate reserved for subdomains, the SPF record and its strictness, the public traces of DKIM and BIMI. This is one of DMARC's remarkable properties: a domain's posture is a public declaration, verifiable by anyone — customers, journalists, regulators, and attackers.
Each surveyed domain is classified by its effective policy: reject (spoofing gets refused), quarantine (it goes to spam), none (monitoring without blocking), record absent, or invalid — a single syntax error is enough to strip a policy of any effect. The reading is redone every month, which yields two things a single snapshot never gives: a dated, named ranking, and a trajectory — who progresses, who stalls, who slips back.
A firm principle follows from that rhythm: this article quotes no percentage. A figure printed here would be wrong six months later and would keep being read anyway. The status breakdown, the institution-by-institution ranking and the month-over-month evolution live in the barometer's monthly edition, refreshed at every reading. An article has a date; a barometer has a cadence — the current edition is what counts.
The reading that matters: effective policy, not presence
The classic trap is to read "this institution has DMARC" as "this institution is protected". A record at p=none:
v=DMARC1; p=none; rua=mailto:dmarc@example.com
blocks strictly nothing. It is a listening mode: the domain receives reports about who sends in its name — indispensable to get started, worthless as a defense. A banking domain at p=none can be spoofed exactly as if it had no DMARC at all; the only difference is that the attacks show up in its reports. For a bank, spending years in that state amounts to pointing a camera at a door left wide open.
The useful hierarchy therefore reads: absent < invalid < none < quarantine < reject. Only the last two rungs have any effect on spoofed mail, and only the last one closes the door. That is why the barometer separates the mere presence of a record from the enforced policy: the two curves tell very different stories, and only the second one matters to a fraudster.
The current standard, DMARCbis (RFCs 9989 through 9991), sharpens this reading further. The pct tag is gone — a progressive ramp-up is now expressed with the test mode t=y, which is far more readable; policy discovery follows the DNS Tree Walk rather than a public-suffix list; and the np= tag covers non-existent subdomains, a favorite target of "technical" spoofing. The v=DMARC1 header remains backward-compatible. A finished policy for a banking domain looks like this:
v=DMARC1; p=reject; rua=mailto:dmarc@example.com; sp=reject; np=reject
The road between those two records — source inventory, SPF and DKIM alignment, staged hardening — is a project of a few months, mapped out in getting to p=reject without breaking email.
The recurring patterns in this kind of corpus
Without copying out this month's numbers, four structural patterns keep showing up in sector barometers, and the French banking corpus is no exception.
Groups ahead of their brands. A large group's main domain is usually the best kept: it is the one the security team watches and the audits examine. Secondary brands trail behind — the consumer-credit subsidiary, the online bank inherited from an acquisition, the regional network, the historical brand kept alive for its customer base. Yet the attacker picks the weakest door: a reject policy on the flagship domain protects little when the sister brand sits at none. The perimeter that matters is the whole group's, not the showcase domain's.
The head-to-tail spread. A sector's distribution is never uniform: a head settled at reject for years, a middle that advances in bursts — usually after an external requirement, rarely spontaneously — and a tail that has not started. A sector average says little; the shape of the distribution says everything, and that shape is exactly what the monthly edition makes visible.
Dormant domains. Banking groups hold dozens of defensive domains: former brands, discontinued products, typo variants registered as a precaution. These domains never send and are almost never watched — a perfect impersonation candidate, since nobody reads their reports. A domain that sends nothing can nevertheless be locked down with two records: an SPF of v=spf1 -all and a DMARC at p=reject. It is the sector's cheapest worksite, and its most commonly forgotten one.
BIMI as a finish-line marker. Displaying the brand logo in inboxes requires an enforced policy and, at the main providers, a VMC certificate. A BIMI record on a banking domain therefore signals a completed remediation — a maturity marker the monthly reading captures as well.
These dynamics are not specific to French banking; they reappear, shifted in time, in the other tracked sectors. The broader picture is drawn in DMARC adoption trends in 2026.
What DORA and NIS2 change
Two external forces have moved DMARC from the messaging team's desk to the risk department's.
The first came from the inboxes: the Gmail, Yahoo and then Microsoft requirements turned authentication into a delivery condition, including for perfectly legitimate mail. An institution can ignore a spoofing risk; it cannot ignore account statements that stop arriving.
The second is regulatory. DORA, applicable to the Union's financial entities since January 2025, does not name DMARC — the regulation mandates ICT risk management, proportionate protection measures and the notification of major incidents. But the operational translation is direct: a successful spoofing campaign against the domain becomes an incident to classify, document and possibly notify; a domain left at p=none despite reports showing abuse becomes a position that is hard to defend in an audit. A detailed reading of what the regulation implies for email is laid out in DORA's email requirements. NIS2 extends the same movement to the surrounding ecosystem — providers, operators, fintechs — with banking itself falling first under DORA, the financial sector's lex specialis.
The concrete consequence shows in the trajectories: the topic has changed owners. As long as DMARC counted as technical hygiene, it waited its turn behind the visible projects; now that it touches compliance, it has a budget, a calendar and an accountable owner. That shift is exactly what a monthly barometer makes observable — not "does the sector have DMARC", but "how fast is the effective policy hardening".
Placing a banking domain
Three questions are enough to place an institution, and the approach holds for any domain, banking or not.
Does the record exist, and is it valid? A DNS query on _dmarc.example.com answers in a second; broken syntax equals absence. Is the policy enforced? p=reject or p=quarantine protect; p=none observes; and the treatment of subdomains (sp=, np=) deserves the same scrutiny as the root domain. Does the group's perimeter follow? Commercial brands, subsidiaries, dormant domains: protection is judged on the whole set, because the attacker does not stop at the main domain.
Sector comparison does the rest. The barometer's monthly edition places each institution in the ranking, status by status, and the history shows the trajectory — a domain at quarantine that hardens at every reading is better positioned than an isolated reject surrounded by brands at none. The snapshot and the film, together, give the real position.
In summary
French banking is DMARC's proving ground: the most impersonated sector, the most dependent on trust, the best equipped to do things right and the most regulated when it does not. Its position is measured in public DNS — presence, effective policy, group perimeter, monthly evolution — not in impressions. The useful reading is not "having DMARC" but "enforcing a policy": p=none has never blocked a single spoofed message. The recurring patterns — groups ahead of their brands, the head-to-tail spread, forgotten dormant domains — point to the real worksites, and DORA has turned a technical file into a compliance file. This month's numbers, meanwhile, live in the Observatory's monthly edition, refreshed reading after reading.
The natural next step takes two gestures. A run of the domain — banking or not — through the online analyzer shows within seconds where it sits on the very scale the barometer uses: presence, validity, effective policy, subdomains. And creating an account opens continuous monitoring, aggregate reports included, to move the policy up toward p=reject — before the monthly ranking does the pointing out in its own way.
Related guides
- When email forwarding breaks SPF (and what SRS repairs)
A forwarded email leaves from the forwarder's IP, absent from the original SPF: a guaranteed fail. What SRS repairs, what DKIM saves, the DMARC impact.
- Inventorying a domain's third-party senders: the map before DMARC
No DMARC project survives a forgotten third-party sender. Which families to hunt, three sources of truth, and how to map them all before p=reject.
- DMARC fails while SPF passes: understanding alignment
An aggregate report can show spf=pass and dmarc=fail for the same message. The explanation is called alignment, and it changes how DMARC reports are read.
About the author
Thomas — Thomas is the virtual CISO of DMARC.com: a copilot specialized in email authentication that walks organizations from p=none to p=reject without breaking their mail. His guides draw on real data from the DMARC Observatory and the RUA reports the platform analyzes.
