Domain posture score · methodology v1.1
F5 Cyber calculates its own score from four public DNS signals. It does not import a SecurityScorecard or Bitsight rating. The weights and thresholds below are product choices for prioritizing review; they are not an industry standard or a validated prediction of a breach.
Score / 100 = SPF / 30 + DMARC / 40 + DNSSEC / 15 + CAA / 15
We add the awarded points directly. There is no additional weighting, vendor-size adjustment, or ranking against other companies. Email-policy signals account for 70 of the 100 available points.
Points awarded for each observed signal| Check | Public evidence | Calculation |
SPF Up to 30 | TXT records at the listed domain. SPF describes which senders may send email for that domain. | One recognized SPF policy with -all: 30. With ~all: 20. One recognized policy without either ending: 5. No recognized policy, or multiple SPF policies: 0. Where applicable, follow redirect= for up to five hops before scoring the effective policy. This is a policy-text check, not full SPF validation. |
DMARC Up to 40 | TXT records at _dmarc.domain. If no policy exists there, the checker also checks the organizational domain using the Public Suffix List and applies its subdomain policy (sp), or p when sp is absent. DMARC publishes how receivers should handle email that fails authentication alignment. | One recognized policy: p=reject gives 40, p=quarantine gives 25, and p=none gives 10 base points. Multiply by pct / 100, then round to the nearest whole point. Missing pct means 100%; values above 100 are capped at 100. Missing, multiple, or unrecognized policies: 0. The percentage adjustment is this model’s scoring convention. |
DNSSEC Up to 15 | The resolver’s authenticated-data (AD) flag on the domain’s A-record response. | AD=true: 15. A completed lookup without an authenticated response: 0. This describes the observed response, not every DNS record or subdomain. |
CAA Up to 15 | CAA records returned for the exact domain, used to publish certificate-issuance policy. | At least one record containing an issue or issuewild tag: 15. No such record: 0. This checks presence only; it does not validate the policy’s strength, issuer values, or inherited parent-domain CAA. |
Reading the colors
Green, 80–100: strong signals under this model. Amber, 50–79: review the findings. Red, 0–49: prioritize review. A red tile does not mean a domain is malicious or compromised. T1–T4 express your business priority and never change the security score.
Worked examples
Illustrative amber result: SPF ~all (20) + DMARC p=reject at 100% (40) + unauthenticated DNS response (0) + observed CAA issuance tag (15) = 75 / 100.
Percentage example: DMARC p=quarantine; pct=50 earns round(25 × 0.50) = 13 / 40. Each vendor’s scorecard shows its actual point-by-point sum.
Missing records versus unavailable evidence
A completed lookup with no applicable record earns zero for that check. A failed, timed-out, truncated, or otherwise unusable lookup is unavailable. If any check is unavailable, the total is withheld and the tile stays gray. We do not convert an outage into zero or inflate the remaining checks to 100. SPF redirect loops, unsupported redirect names, and depth-limit failures also leave the assessment incomplete.
Sources and freshness
Evidence comes from Google Public DNS’s DNS-over-HTTPS service. Open a vendor and expand each check to see the recorded finding and a link to the public query. The query link returns current DNS data, which may differ from the saved observation.
The catalog opens with the compiled snapshot or a newer saved assessment. The “Checked” time identifies when its evidence was gathered. Refreshes reuse results less than one hour old; results older than 24 hours are flagged. Refresh a scorecard, or open “Assess my tiers” and choose “Refresh selected scores”, to request an assessment. All vendor scores and live intelligence feeds refresh daily around 12:05 a.m. America/New_York, including when the dashboard is closed.
What the number cannot tell you
This model does not assess breaches, malware, exposed services, vulnerabilities, HTTPS/TLS configuration, HTTP security headers, internal controls, or compliance. It does not fully validate SPF includes, DKIM, or DMARC enforcement in actual mail delivery. A brand’s listed domain is only part of its infrastructure. Even 100 / 100 means only that these four checks received full points at the observation time.