Making risk vectors more impactful
Bitsight's annual Ratings Algorithm Update (RAU) has been in effect as of July 16, 2026. In preparation, RAU 2026 Preview was made available in April 2026. As in the past, RAU 2026 is an effort to account for the continuous evolution of the threat landscape the Bitsight security ratings seek to quantify.
This year's update is focused on modernizing the rating by improving how it is composed from various risk vectors (RVs). In particular, this entails the following:
- Patching Cadence (PC) has been supplanted by Critical Vulnerability Management (CVM), with no change in weight (20% of the Bitsight rating).
- DMARC begins to impact ratings at a weight of 1%, while the impact of Compromised Systems is reduced to 26% from 27%.
- SPF and DKIM use a more refined scoring approach in the absence of findings.
DMARC is now a ratings-impacting part of Bitsight's E-Mail Security
In addition to Sender Policy Framework (SPF) and Domain Keys Identified Mail (DKIM), Domain-based Message Authentication, Reporting, and Conformance (DMARC) constitutes a pillar of modern e-mail security. Specifically, DMARC requires that the domains used for delivering messages (SPF's Mail From or DKIM's d= tag) align with the visible domain in the "From" field of the email, and dictates how receiving servers should handle messages that fail authentication. Details of Bitsight's evaluation of DMARC are available here, with guidance on how to set up a DMARC policy discussed here. Starting in RAU 2026, DMARC accounts for 1% of the Bitsight rating, bringing its impact in line with those of SPF and DKIM. On a related note, Compromised Systems now accounts for 26% of the ratings, instead of the 27% before RAU 2026.
SPF and DKIM no longer penalize entities without domains
For the evaluation of E-Mail Security, an absence of appropriately configured security elements for a domain constitutes a vulnerability. In light of this, the security ratings algorithm is designed to penalize the absence of detectable SPF and DKIM records — previously awarding an F and a C grade, respectively — for these situations.
However, not all entities have domains registered to them. As a result, they cannot send or receive e-mails, nor can they be expected to have SPF and DKIM records that administer e-mails.
To account for this nuance and in keeping with the grading of DMARC, entities with no domains will receive 'N/A' grades for these risk vectors (while entities with domains but no SPF and/or DKIM records will be penalized per usual for e-mail misconfiguration).