canada.ca scored 52/100 and does not meet the minimum security posture threshold. The most critical issue is: Set up email authentication (SPF). This must be addressed before the vendor can be approved for procurement or data processing activities.
Critical gaps in: DMARC / Email Security. Positive signals: Known Breaches, Certificate Hygiene, CVE Exposure all passed.
3 action items identified, including 1 critical. The issues are configuration gaps, not architectural problems. A focused remediation effort of 2–5 days could address all findings.
Grade distribution across 2520 companies we've scanned. canada.ca scores better than 15% of them.
Each check inspects a different part of canada.ca's public security setup. Green means healthy, yellow needs attention, red is a problem.
Steps to improve canada.ca's security grade, ranked by impact.
Key data points from the scan.