Medido el 2026-07-19 · DNS público

¿Está ing.es protegido contra la suplantación de correo?

Sí — ing.es aplica DMARC (p=reject).

Postura sin cambios desde el 2026-06-19

Más protegido que el 74 % de bancos en España

El 47 % del sector ya aplica p=reject

Ver el barómetro sectorial

A

DMARC

p=reject

SPF

-all

DKIM

2 selector(es)

Apto para BIMI: publica tu logo para mostrarlo en los buzones

Cómo corregirlo

Thomas, tu CISO virtual con IA, identifica cada fuente, escribe el DNS exacto y lleva tu dominio de p=none a p=reject con total seguridad.

Registro publicado

v=DMARC1;p=reject;rua=mailto:ejdvezzq@ag.eu.dmarcadvisor.com

Qué significa esto

  • Politique p=reject : protection maximale contre l’usurpation.
  • Au moins une clé DKIM valide publiée.
  • Clé DKIM RSA de 1024 bits : encore tolérée mais sous l’état de l’art — faire tourner vers 2048 bits. (selector1 : 1024 bits)
  • Pas de MTA-STS (_mta-sts) : les connexions SMTP entrantes restent exposées au downgrade TLS. Recommandé en complément de DMARC.
  • Pas de TLS-RPT (_smtp._tls) : les échecs TLS rencontrés par les émetteurs ne sont pas rapportés.

Historial

  • 2026-07-19DMARCProtegido (p=reject)
  • 2026-06-26Primera mediciónProtegido (p=reject)

Sobre ING España

ING España is the Spanish subsidiary of ING, the major Dutch banking group and one of Europe's largest financial institutions. Operating through the domain ing.es, the organization manages a complex email ecosystem encompassing internal communications to thousands of employees, customer interactions with retail and corporate clients, and official correspondence related to digital and traditional banking services. This financial institution faces critical email security challenges. The banking sector is a prime target for phishing campaigns and domain spoofing attacks, threatening customer trust and institutional reputation. Securing the ing.es domain through robust implementation of DMARC, SPF, and DKIM authentication is essential to prevent fraud, particularly spoofing attempts replicating official banking communications. As an EU-based financial entity, ING España must comply with stringent regulatory frameworks including NIS2 (the European cybersecurity directive applicable to critical sectors) and potentially DORA (Digital Operational Resilience Act), which strengthen authentication and electronic communication security obligations. Implementing a rigorous DMARC policy constitutes a fundamental element of these requirements. Weaknesses or absence of email authentication measures exposes ing.es to substantial risks: online fraud, damage to commercial credibility, and regulatory compliance violations. Securing this strategic domain therefore represents a priority investment for protecting sensitive data and maintaining institutional trust with customers and stakeholders.

En este sector