Steps to improve data.worldbank.org's security grade, ranked by impact.
Without email authentication, anyone can send emails that appear to come from data.worldbank.org. This is the most common vector for phishing attacks targeting employees and customers. DMARC, SPF, DKIM are not configured.
data.worldbank.org scored 72/100, meeting baseline requirements but with 5 findings that require attention. The vendor can proceed with a remediation timeline agreement.
Critical gaps in: DMARC / Email Security, HSTS Header. Positive signals: MX Records & Mail Provider, TLS Protocol Support, TLS Configuration all passed.
3 action items identified, including 1 critical. The issues are configuration gaps, not architectural problems. A focused remediation effort of 2–5 days could address all findings.
Grade distribution across 2678 companies we've scanned. data.worldbank.org scores better than 46% of them.
Key data points from the scan.
Other domains with comparable security profiles.