Back to news
Cybersecurity Alert
July 19, 2026 by EmailMeNow IT Consulting

Password Manager Domain Security Audit 2026: Proton, LastPass, Bitwarden & Peers

Independent EmailMeNow audits of seven major password-manager domains find scores from 86% (Dashlane) to 65% (Keeper) — none reach the 100% ideal. Proton.me leads transport at 100%; LastPass sits at 66% with 15% transport amid 2026 phishing waves.

NewsPassword ManagersEmail SecurityLastPassBitwardenProtonCybersecurity
Ranked cybersecurity scoreboard comparing password manager domain security toward a 100 percent ideal

Password managers hold the keys to everything else — which makes their public email and domain security a high-stakes phishing surface. We independently audited seven widely recommended password-manager brands on July 19, 2026 using audit.emailmenow.com. Scores cover identity (SPF/DKIM/DMARC), transport (MTA-STS/TLS-RPT), and website headers. 100% is the ideal.

This is not a vault-crypto bake-off and not a repeat of our July phishing campaign alert or June LastPass / Klue supply-chain report. It answers a narrower question: how well do these brands’ own domains resist spoofed “security” mail while customers are already being hunted for master passwords?

Ranked cybersecurity scoreboard comparing password manager domain security toward a 100 percent ideal

Brands We Scanned

BrandDomain auditedWhy it is in scope
Dashlanedashlane.comMainstream commercial manager
Bitwardenbitwarden.comOpen-source; strong free tier / self-host option
Proton Passproton.mePrivacy-first Proton suite Pass product
NordPassnordpass.comNord Security ecosystem manager
1Password1password.comSecret Key + master password architecture
LastPasslastpass.comHigh-visibility brand; 2022 vault incident + 2026 phishing waves
Keeperkeepersecurity.comCompliance-focused enterprise / regulated-industry positioning

Local-only options such as KeePassXC and ecosystem vaults such as Apple Passwords do not present the same public marketing/email domain footprint, so they are discussed qualitatively below rather than ranked in the score table.

Ranked Domain Security Scores

Overall compliance scores from audit.emailmenow.com. 100% is the ideal. Re-run any domain at the link to verify.

RankBrandDomainOverallIdentityTransportWebsiteLevel
1Dashlanedashlane.com86%90%45%92%Strong
2Bitwardenbitwarden.com78%65%45%100%Good
3Proton Passproton.me74%50%100%98%Good
4NordPassnordpass.com70%95%15%37%Good
51Password1password.com68%45%15%98%Above Average
6LastPasslastpass.com66%50%15%100%Above Average
7Keeperkeepersecurity.com65%40%15%95%Above Average

Anonymous vault icons ranked on a comparative domain security scoreboard

Category Highlights

FindingDetail
Ideal score100% overall0 of 7 brands reached it
Best overallDashlane (dashlane.com) — 86% (Strong)
Best transportProton (proton.me) — 100% — only brand at the transport ideal
Best identityNordPass (nordpass.com) — 95%
Perfect website headersBitwarden and LastPass100% Website
Weakest overallKeeper (keepersecurity.com) — 65%
Shared transport gap4 of 7 score 15% Transport (1Password, LastPass, Keeper, NordPass)

What the scores mean (and do not mean)

LayerWhat the audit measuresWhat it does not measure
IdentitySPF / DKIM / DMARC spoofing resistance for @brand mailVault encryption, Secret Key design, open-source audits
TransportMTA-STS / TLS-RPT mail-path protectionDevice MFA, passkeys, session revocation UX
WebsitePublic security headers (HSTS, CSP, framing controls, etc.)Browser-extension supply chain or autofill bugs

A polished vault product can still sit below the 100% domain ideal — and a strong domain score does not erase past vault incidents or active phishing lookalikes. Domain hygiene matters because attackers already impersonate these brands to steal the one password that unlocks the rest.

Strong vault architecture contrasted with phishing hooks targeting password-manager brands

Brand Notes

Dashlane — strongest public domain score

86% overall leads this set, with 90% Identity. Transport at 45% still leaves room before the ideal. Strong public mail authentication is useful when customers receive “account” or “policy” notices.

Bitwarden — open source, solid domain posture

78% overall with a 100% Website score. Identity (65%) and transport (45%) trail Dashlane but beat several peers. Self-hosting and open-source audits address a different threat model than this domain table — both matter.

Proton Pass — only perfect transport score

74% overall, but proton.me hits 100% Transport — the standout in this pass. Identity at 50% is the drag on overall. Privacy positioning and Swiss hosting are product/trust attributes beyond this audit.

NordPass — strong identity, weak website/transport split

95% Identity is second to none here, but 15% Transport and 37% Website pull the overall score to 70%. A classic “uneven hardening” pattern.

1Password — vault reputation ≠ domain scoreboard lead

Widely praised for Secret Key architecture, yet 1password.com scores 68% overall with 45% Identity and 15% Transport. Customers should still treat unexpected 1Password-branded mail as high risk until verified in-app.

LastPass — above average domain score amid elevated phishing pressure

66% overall with 100% Website, but 50% Identity / 15% Transport. That gap is especially relevant after the July 2026 lookalike-domain campaign and the longer post-2022 trust recovery story. Domain score ≠ vault trust history.

Keeper — compliance brand, lowest domain overall here

65% overall with 40% Identity and 15% Transport. Enterprise certifications (SOC 2, HIPAA, FedRAMP, etc.) speak to organizational controls; this table only scores the public marketing/email domain.

Outside the Ranked Table

OptionDomain security takeaway
KeePassXC / KeePassLocal database — no cloud marketing domain in this ranking; sync/backup choices become your attack surface
Apple PasswordsTied to Apple ID / iCloud; evaluate Apple account MFA and Advanced Data Protection rather than a standalone PM marketing domain
Browser-built-in managersConvenient, but phishing and device-sync threats differ; still use unique passwords + MFA on high-value accounts

Website stack note

Passive website-tech probes on July 19, 2026 completed for 7 of 7 audited domains (0 notable public CMS/PHP/CVE/TLS-horizon alerts).

DomainPassive stack signal
dashlane.comWordPress detected; version hidden (common hardening)
keepersecurity.comHubSpot (SaaS-managed core updates)
1password.comNext.js (version not exposed)
nordpass.comNext.js (version not exposed)
bitwarden.com, proton.me, lastpass.comNo public CMS/version signal in this pass

These marketing-site fingerprints do not evaluate vault cryptography, client apps, or browser extensions. The operational risk for customers remains master-password phishing and account takeover — not a CMS-core headline on these hosts.

These passive observations are point-in-time public signals. They do not prove exploitability, identify a breach path, or establish that a detected major version is unsupported.

What Password-Manager Users Should Do

  1. Use a reputable manager anyway — reused browser passwords remain worse than any brand in this table.
  2. Protect the master password — unique, long, never typed from unexpected email; enable phishing-resistant MFA / passkeys where offered.
  3. Open the app or a typed bookmark — never “policy update” links from lookalike newsletter/compliance domains.
  4. Expect brand impersonation — especially LastPass and Bitwarden after the July 2026 campaign.
  5. For IT teams choosing a vendor — weigh vault architecture and require vendors to approach the 100% domain ideal (DMARC reject + MTA-STS enforce) on every customer-facing host.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for DMARC enforcement, MTA-STS deployment, and phishing-resistant identity hardening.


Sources: Independent EmailMeNow domain audits (July 19, 2026) · LastPass July 2026 phishing advisory · Industry 2026 password-manager roundups (Wirecutter, vendor security documentation)