banks · France

22% of France's banks are not protected against email spoofing

Public DMARC posture of 51 banks. Edition of June 2026.

28

Protected

12

Enforcing

10

Monitoring only

1

No DMARC

Where each one stands

OrganizationDMARC statusGrade
AXA Banqueaxabanque.fr(corporate domain : axa.fr)Protected (p=reject)A
Banque BCPbanquebcp.frProtected (p=reject)A
Banque de Savoiebanque-de-savoie.frProtected (p=reject)A
Banque Delubac & Ciedelubac.comProtected (p=reject)A
Banque Palatinepalatine.frProtected (p=reject)A
Banque Populairebanquepopulaire.frProtected (p=reject)A
BforBankbforbank.comProtected (p=reject)A
BNP Paribasbnpparibas.fr(corporate domain : bnpparibas.com)Protected (p=reject)A
BRED Banque Populairebred.frProtected (p=reject)A
BTP Banquebtp-banque.frProtected (p=reject)A
Caisse d'Épargnecaisse-epargne.frProtected (p=reject)A
CASDEN Banque Populairecasden.frProtected (p=reject)A
CCFccf.frProtected (p=reject)A
Crédit Agricolecredit-agricole.fr(corporate domain : credit-agricole.com)Protected (p=reject)A
Crédit Agricole d'Île-de-Franceca-paris.com(corporate domain : credit-agricole.fr)Protected (p=reject)A
Crédit Coopératifcredit-cooperatif.coopProtected (p=reject)A
Crédit Maritimecreditmaritime.frProtected (p=reject)A
Crédit Mutuel de Bretagnecmb.frProtected (p=reject)A
Fortuneofortuneo.frProtected (p=reject)A
Hello bank!hellobank.frProtected (p=reject)A
HSBC Continental Europehsbc.frProtected (p=reject)A
Indosuez Wealth Managementca-indosuez.comProtected (p=reject)A
Neuflize OBCneuflizeobc.frProtected (p=reject)A
Nickelnickel.euProtected (p=reject)A
Oneyoney.frProtected (p=reject)A
Qontoqonto.comProtected (p=reject)A
Rothschild & Corothschildandco.comProtected (p=reject)A
Société Généralesg.fr(corporate domain : societegenerale.com)Protected (p=reject)A
Banque Hottinguerbanque-hottinguer.comEnforcing (p=quarantine)B
Banque Transatlantiquebanquetransatlantique.comEnforcing (p=quarantine)B
BoursoBankboursobank.comEnforcing (p=quarantine)B
CICcic.frEnforcing (p=quarantine)B
Crédit Mutuelcreditmutuel.frEnforcing (p=quarantine)C
Floafloabank.frEnforcing (p=quarantine)C
Manager.onemanager.oneEnforcing (p=quarantine)B
Milleis Banquemilleis.frEnforcing (p=quarantine)B
Monabanqmonabanq.comEnforcing (p=quarantine)B
Propulse by CApropulsebyca.frEnforcing (p=quarantine)C
Shineshine.frEnforcing (p=quarantine)B
Sumeriasumeria.eu(corporate domain : sumeria.fr)Enforcing (p=quarantine)B
Banque Richelieu Francebanquerichelieu.comMonitoring only (p=none)F
Banque Wormser Frèresbanquewormser.comMonitoring only (p=none)D
Blankblank.appMonitoring only (p=none)D
Bpifrancebpifrance.frMonitoring only (p=none)D
Chaabi Bankchaabibank.frMonitoring only (p=none)D
Green-Gotgreen-got.comMonitoring only (p=none)D
Helioshelios.doMonitoring only (p=none)D
La Banque Postalelabanquepostale.frMonitoring only (p=none)D
LCLlcl.frMonitoring only (p=none)D
Pixpaypixpay.frMonitoring only (p=none)D
Edmond de Rothschildedmond-de-rothschild.comNo DMARCF

Previous editions

Methodology

We read each organization’s public DNS — the DMARC record on its consumer-facing domain — and classify the published policy (none / quarantine / reject). “Protected” means an enforced p=reject policy. Only public data is used; figures reflect the edition date and can change as records are updated.