banks · Germany

40% of Germany's banks are not protected against email spoofing

Public DMARC posture of 50 banks. Edition of June 2026.

19

Protected

11

Enforcing

16

Monitoring only

4

No DMARC

Where each one stands

OrganizationDMARC statusGrade
1822direkt1822direkt.deProtected (p=reject)A
apoBankapobank.deProtected (p=reject)A
Bankhaus Metzlermetzler.comProtected (p=reject)B
bunq Deutschlandbunq.comProtected (p=reject)A
C24 Bankc24.deProtected (p=reject)A
comdirectcomdirect.deProtected (p=reject)A
Commerzbankcommerzbank.deProtected (p=reject)A
Consorsbankconsorsbank.deProtected (p=reject)A
Deutsche Bankdeutsche-bank.de(corporate domain : db.com)Protected (p=reject)A
ING Deutschlanding.deProtected (p=reject)A
KfWkfw.deProtected (p=reject)A
LBBWlbbw.deProtected (p=reject)A
M.M.Warburg & COmmwarburg.comProtected (p=reject)A
N26n26.comProtected (p=reject)A
norisbanknorisbank.deProtected (p=reject)A
Santander Deutschlandsantander.deProtected (p=reject)A
Sparkasse KölnBonnsparkasse-koelnbonn.deProtected (p=reject)A
Trade Republictraderepublic.comProtected (p=reject)A
Triodos Bank Deutschlandtriodos.deProtected (p=reject)B
Berenbergberenberg.deEnforcing (p=quarantine)B
Hanseatic Bankhanseaticbank.deEnforcing (p=quarantine)D
Hauck Aufhäuser Lampehal-privatbank.comEnforcing (p=quarantine)B
Helabahelaba.deEnforcing (p=quarantine)B
HypoVereinsbankhypovereinsbank.deEnforcing (p=quarantine)B
ODDO BHFoddo-bhf.comEnforcing (p=quarantine)B
Schwäbisch Hallschwaebisch-hall.deEnforcing (p=quarantine)B
Solarissolarisgroup.comEnforcing (p=quarantine)B
Targobanktargobank.deEnforcing (p=quarantine)B
Tomorrowtomorrow.oneEnforcing (p=quarantine)B
Volkswagen Bankvolkswagenbank.de(corporate domain : vwfs.de)Enforcing (p=quarantine)B
Aareal Bankaareal-bank.comMonitoring only (p=none)D
Berliner Sparkasseberliner-sparkasse.deMonitoring only (p=none)D
Deutsche Pfandbriefbank (pbb)pfandbriefbank.comMonitoring only (p=none)D
DKBdkb.deMonitoring only (p=none)D
Donner & Reuscheldonner-reuschel.deMonitoring only (p=none)D
DZ Bankdzbank.deMonitoring only (p=none)D
GLS Bankgls.deMonitoring only (p=none)F
Hamburg Commercial Bankhcob-bank.comMonitoring only (p=none)D
Hamburger Sparkassehaspa.deMonitoring only (p=none)D
NORD/LBnordlb.deMonitoring only (p=none)D
Oldenburgische Landesbankolb.deMonitoring only (p=none)D
Postbankpostbank.deMonitoring only (p=none)D
SaarLBsaarlb.deMonitoring only (p=none)D
Sparkasse (Sparkassen-Finanzgruppe)sparkasse.deMonitoring only (p=none)D
Stadtsparkasse Münchensskm.deMonitoring only (p=none)D
UmweltBankumweltbank.deMonitoring only (p=none)F
BayernLBbayernlb.deNo DMARCF
Sparda-Banksparda.deNo DMARCF
TeamBank (easyCredit)easycredit.deNo DMARCF
Volksbanken Raiffeisenbankenvr.de(corporate domain : dzbank.de)No DMARCF

Previous editions

Methodology

We read each organization’s public DNS — the DMARC record on its consumer-facing domain — and classify the published policy (none / quarantine / reject). “Protected” means an enforced p=reject policy. Only public data is used; figures reflect the edition date and can change as records are updated.