banks · United States

10% of United States's banks are not protected against email spoofing

Public DMARC posture of 50 banks. Edition of June 2026.

40

Protected

5

Enforcing

4

Monitoring only

1

No DMARC

Where each one stands

OrganizationDMARC statusGrade
Allyally.comProtected (p=reject)A
American Expressamericanexpress.comProtected (p=reject)A
Associated Bankassociatedbank.comProtected (p=reject)A
Bank of Americabankofamerica.comProtected (p=reject)A
Bank OZKozk.comProtected (p=reject)A
Barclays USbarclaysus.comProtected (p=reject)A
BMObmo.comProtected (p=reject)A
Capital Onecapitalone.comProtected (p=reject)A
Cash Appcash.appProtected (p=reject)A
Charles Schwabschwab.com(corporate domain : schwabbank.com)Protected (p=reject)A
Chasechase.com(corporate domain : jpmorganchase.com)Protected (p=reject)A
Chimechime.comProtected (p=reject)A
Citibankciti.com(corporate domain : citigroup.com)Protected (p=reject)A
Citizens Bankcitizensbank.comProtected (p=reject)A
Fifth Third Bank53.comProtected (p=reject)A
First Citizens Bankfirstcitizens.comProtected (p=reject)A
First Horizonfirsthorizon.comProtected (p=reject)A
First National Bankfnb-online.comProtected (p=reject)A
Flagstar Bankflagstar.comProtected (p=reject)A
Huntingtonhuntington.comProtected (p=reject)A
KeyBankkey.comProtected (p=reject)A
M&T Bankmtb.comProtected (p=reject)A
Marcusmarcus.com(corporate domain : goldmansachs.com)Protected (p=reject)A
Navy Federalnavyfederal.orgProtected (p=reject)A
Pinnacle Financialpnfp.comProtected (p=reject)A
PNC Bankpnc.comProtected (p=reject)A
Regions Bankregions.comProtected (p=reject)A
SoFisofi.comProtected (p=reject)A
South State Banksouthstatebank.comProtected (p=reject)A
Synchrony Banksynchrony.comProtected (p=reject)A
Synovussynovus.comProtected (p=reject)A
TD Banktd.com(corporate domain : tdbank.com)Protected (p=reject)B
Truisttruist.comProtected (p=reject)A
U.S. Bankusbank.comProtected (p=reject)A
Umpqua Bankumpquabank.comProtected (p=reject)A
USAAusaa.comProtected (p=reject)A
Webster Bankwebsterbank.comProtected (p=reject)A
Wells Fargowellsfargo.comProtected (p=reject)A
Wintrustwintrust.comProtected (p=reject)A
Zions Bankzionsbank.comProtected (p=reject)A
Currentcurrent.comEnforcing (p=quarantine)B
Discoverdiscover.com(corporate domain : capitalone.com)Enforcing (p=quarantine)B
East West Bankeastwestbank.comEnforcing (p=quarantine)B
Valley Bankvalley.comEnforcing (p=quarantine)B
Varo Bankvaromoney.com(corporate domain : varo.com)Enforcing (p=quarantine)B
Comericacomerica.comMonitoring only (p=none)D
Frost Bankfrostbank.comMonitoring only (p=none)D
Old National Bankoldnational.comMonitoring only (p=none)D
Western Alliancewesternalliancebank.comMonitoring only (p=none)D
HSBC Bank USAus.hsbc.com(corporate domain : hsbc.com)No DMARCF

Previous editions

Methodology

We read each organization’s public DNS — the DMARC record on its consumer-facing domain — and classify the published policy (none / quarantine / reject). “Protected” means an enforced p=reject policy. Only public data is used; figures reflect the edition date and can change as records are updated.