Password managers hold the keys to everything else — which makes their public email and domain security a high-stakes phishing surface. We independently audited seven widely recommended password-manager brands on July 19, 2026 using audit.emailmenow.com. Scores cover identity (SPF/DKIM/DMARC), transport (MTA-STS/TLS-RPT), and website headers. 100% is the ideal.
This is not a vault-crypto bake-off and not a repeat of our July phishing campaign alert or June LastPass / Klue supply-chain report. It answers a narrower question: how well do these brands’ own domains resist spoofed “security” mail while customers are already being hunted for master passwords?

Brands We Scanned
| Brand | Domain audited | Why it is in scope |
|---|---|---|
| Dashlane | dashlane.com | Mainstream commercial manager |
| Bitwarden | bitwarden.com | Open-source; strong free tier / self-host option |
| Proton Pass | proton.me | Privacy-first Proton suite Pass product |
| NordPass | nordpass.com | Nord Security ecosystem manager |
| 1Password | 1password.com | Secret Key + master password architecture |
| LastPass | lastpass.com | High-visibility brand; 2022 vault incident + 2026 phishing waves |
| Keeper | keepersecurity.com | Compliance-focused enterprise / regulated-industry positioning |
Local-only options such as KeePassXC and ecosystem vaults such as Apple Passwords do not present the same public marketing/email domain footprint, so they are discussed qualitatively below rather than ranked in the score table.
Ranked Domain Security Scores
Overall compliance scores from audit.emailmenow.com. 100% is the ideal. Re-run any domain at the link to verify.
| Rank | Brand | Domain | Overall | Identity | Transport | Website | Level |
|---|---|---|---|---|---|---|---|
| 1 | Dashlane | dashlane.com | 86% | 90% | 45% | 92% | Strong |
| 2 | Bitwarden | bitwarden.com | 78% | 65% | 45% | 100% | Good |
| 3 | Proton Pass | proton.me | 74% | 50% | 100% | 98% | Good |
| 4 | NordPass | nordpass.com | 70% | 95% | 15% | 37% | Good |
| 5 | 1Password | 1password.com | 68% | 45% | 15% | 98% | Above Average |
| 6 | LastPass | lastpass.com | 66% | 50% | 15% | 100% | Above Average |
| 7 | Keeper | keepersecurity.com | 65% | 40% | 15% | 95% | Above Average |

Category Highlights
| Finding | Detail |
|---|---|
| Ideal score | 100% overall — 0 of 7 brands reached it |
| Best overall | Dashlane (dashlane.com) — 86% (Strong) |
| Best transport | Proton (proton.me) — 100% — only brand at the transport ideal |
| Best identity | NordPass (nordpass.com) — 95% |
| Perfect website headers | Bitwarden and LastPass — 100% Website |
| Weakest overall | Keeper (keepersecurity.com) — 65% |
| Shared transport gap | 4 of 7 score 15% Transport (1Password, LastPass, Keeper, NordPass) |
What the scores mean (and do not mean)
| Layer | What the audit measures | What it does not measure |
|---|---|---|
| Identity | SPF / DKIM / DMARC spoofing resistance for @brand mail | Vault encryption, Secret Key design, open-source audits |
| Transport | MTA-STS / TLS-RPT mail-path protection | Device MFA, passkeys, session revocation UX |
| Website | Public security headers (HSTS, CSP, framing controls, etc.) | Browser-extension supply chain or autofill bugs |
A polished vault product can still sit below the 100% domain ideal — and a strong domain score does not erase past vault incidents or active phishing lookalikes. Domain hygiene matters because attackers already impersonate these brands to steal the one password that unlocks the rest.

Brand Notes
Dashlane — strongest public domain score
86% overall leads this set, with 90% Identity. Transport at 45% still leaves room before the ideal. Strong public mail authentication is useful when customers receive “account” or “policy” notices.
Bitwarden — open source, solid domain posture
78% overall with a 100% Website score. Identity (65%) and transport (45%) trail Dashlane but beat several peers. Self-hosting and open-source audits address a different threat model than this domain table — both matter.
Proton Pass — only perfect transport score
74% overall, but proton.me hits 100% Transport — the standout in this pass. Identity at 50% is the drag on overall. Privacy positioning and Swiss hosting are product/trust attributes beyond this audit.
NordPass — strong identity, weak website/transport split
95% Identity is second to none here, but 15% Transport and 37% Website pull the overall score to 70%. A classic “uneven hardening” pattern.
1Password — vault reputation ≠ domain scoreboard lead
Widely praised for Secret Key architecture, yet 1password.com scores 68% overall with 45% Identity and 15% Transport. Customers should still treat unexpected 1Password-branded mail as high risk until verified in-app.
LastPass — above average domain score amid elevated phishing pressure
66% overall with 100% Website, but 50% Identity / 15% Transport. That gap is especially relevant after the July 2026 lookalike-domain campaign and the longer post-2022 trust recovery story. Domain score ≠ vault trust history.
Keeper — compliance brand, lowest domain overall here
65% overall with 40% Identity and 15% Transport. Enterprise certifications (SOC 2, HIPAA, FedRAMP, etc.) speak to organizational controls; this table only scores the public marketing/email domain.
Outside the Ranked Table
| Option | Domain security takeaway |
|---|---|
| KeePassXC / KeePass | Local database — no cloud marketing domain in this ranking; sync/backup choices become your attack surface |
| Apple Passwords | Tied to Apple ID / iCloud; evaluate Apple account MFA and Advanced Data Protection rather than a standalone PM marketing domain |
| Browser-built-in managers | Convenient, but phishing and device-sync threats differ; still use unique passwords + MFA on high-value accounts |
Audit Links
Website stack note
Passive website-tech probes on July 19, 2026 completed for 7 of 7 audited domains (0 notable public CMS/PHP/CVE/TLS-horizon alerts).
| Domain | Passive stack signal |
|---|---|
| dashlane.com | WordPress detected; version hidden (common hardening) |
| keepersecurity.com | HubSpot (SaaS-managed core updates) |
| 1password.com | Next.js (version not exposed) |
| nordpass.com | Next.js (version not exposed) |
| bitwarden.com, proton.me, lastpass.com | No public CMS/version signal in this pass |
These marketing-site fingerprints do not evaluate vault cryptography, client apps, or browser extensions. The operational risk for customers remains master-password phishing and account takeover — not a CMS-core headline on these hosts.
These passive observations are point-in-time public signals. They do not prove exploitability, identify a breach path, or establish that a detected major version is unsupported.
What Password-Manager Users Should Do
- Use a reputable manager anyway — reused browser passwords remain worse than any brand in this table.
- Protect the master password — unique, long, never typed from unexpected email; enable phishing-resistant MFA / passkeys where offered.
- Open the app or a typed bookmark — never “policy update” links from lookalike newsletter/compliance domains.
- Expect brand impersonation — especially LastPass and Bitwarden after the July 2026 campaign.
- For IT teams choosing a vendor — weigh vault architecture and require vendors to approach the 100% domain ideal (DMARC reject + MTA-STS enforce) on every customer-facing host.
Related Coverage
- LastPass & Bitwarden phishing campaign (July 2026)
- LastPass Klue supply-chain breach (June 2026)
- Breach monitoring resources guide
Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for DMARC enforcement, MTA-STS deployment, and phishing-resistant identity hardening.
Sources: Independent EmailMeNow domain audits (July 19, 2026) · LastPass July 2026 phishing advisory · Industry 2026 password-manager roundups (Wirecutter, vendor security documentation)