The Fourths
Confidential Document
Johnson & Johnson
Public Email-Security Posture — May 2026

Johnson & Johnson — Public Email-Security Posture

SPF · DKIM · DMARC with WHOIS ownership verification · 29 May 2026

The Fourths
TF-REF:JNJ-EMAIL-001
Point-in-time: 29 May 2026
CONFIDENTIAL
◆ KEY FINDING Every domain we could prove is J&J-owned enforces DMARC. The exposure is in the brand-domain tail: 28 J&J-branded domains on J&J's own registrar publish no email authentication — and brand-domain ownership is inconsistent.
Overview
Confirmed J&J (19)
Likely J&J (29)
Not J&J / Review
Method & Scope
56
Domains examined
19
Confirmed J&J — all secured
29
Likely J&J — ownership unprovable
3
Confirmed owned by others

What we found — read this first

This assessment verifies ownership before drawing conclusions. Brand name is not proof of ownership: a J&J product name on a domain does not mean J&J controls that domain.

Where ownership is provable (DMARC reports flow to J&J's authentication tenant, or the registrant is named), the posture is uniformly strong — 19 of 19 confirmed domains enforce DMARC, almost all at the strongest setting (p=reject).

The real exposure is the brand-domain tail and its governance. 28 J&J-branded domains are registered through J&J's own registrar but have redacted ownership — and all 28 of them publish no DMARC at all. If J&J operates them, every one is exact-domain spoofable. We cannot prove they are J&J's from public data — and that ambiguity is itself the finding.

Why "we can't confirm" is the headline

Of the branded domains checked, several are confirmed to belong to other companies — imbruvica.com (AbbVie), ponvory.com (Juvisé Pharmaceuticals) — and others sit on consumer registrars (GoDaddy) inconsistent with J&J's estate. For a generative email-content platform, the trust layer underneath the content has to be both authenticated and governed. Today, across the J&J product portfolio, it is neither consistently.

Spotlight — spravato.com

spravato.com (the product in the Content·AI Studio demo scenario) is registered through J&J's own registrar (Key-Systems, the same registrar as jnj.com) yet publishes no SPF and no DMARC. It is very likely J&J-operated and, if so, freely spoofable — but note even here that public records do not prove the registrant. The content engine's trust layer cannot rest on an assumption.

Confirmed J&J domains (19) — ownership proven

Ownership confirmed because DMARC aggregate reports flow to J&J's authentication tenant (Red Sift OnDMARC inbox 5d14eac2 / b68acfa0) or the report address contains "jnj". Posture is strong across the board.

DomainSPFDMARCDKIMStatus
jnj.com-allp=rejectENFORCED
janssen.com-allp=rejectENFORCED
jnjinnovation.com-allp=rejectENFORCED
jnjmedtech.comnonep=rejectENFORCED
janssencarepath.com-allp=rejectENFORCED
jnjwithme.com-allp=rejectENFORCED
janssenmd.com-allp=rejectENFORCED
darzalex.com-allp=rejectENFORCED
darzalexhcp.com-allp=rejectENFORCED
carvykti.com-allp=rejectENFORCED
rybrevanthcp.com-allp=rejectENFORCED
depuysynthes.com-allp=rejectENFORCED
synthes.com-allp=rejectENFORCED
acclarent.com-allp=rejectENFORCED
abiomed.com~allp=rejectselector1ENFORCED
acuvue.com-allp=rejectENFORCED
biosensewebster.comnonep=noneMONITOR ONLY
actelion.com offlineno A record at assessment timeN/A
ENFORCED
jnjvision.com offlineno A record at assessment timeN/A
ENFORCED

Likely J&J — ownership not provable (29)

J&J product/brand names, registered through J&J's own registrar (Key-Systems GmbH), but with privacy-redacted registrant and no DMARC reporting to confirm operation. Treat as probable J&J assets pending internal confirmation. All live domains here publish no DMARC — exact-domain spoofable if J&J-operated. DKIM absence is not conclusive (selectors are private).

DomainSPFDMARCDKIMStatus
spravato.comnonenoneUNAUTHENTICATED
spravatohcp.comnonenoneUNAUTHENTICATED
spravatowithme.com offlineno A recordN/A
stelarainfo.comnonenoneUNAUTHENTICATED
tremfya.comnonenoneUNAUTHENTICATED
tremfyahcp.comnonenoneUNAUTHENTICATED
tremfyawithme.comnonenoneUNAUTHENTICATED
invokana.comnonenoneUNAUTHENTICATED
invokanahcp.comnonenoneUNAUTHENTICATED
erleada.comnonenoneUNAUTHENTICATED
erleadahcp.comnonenoneUNAUTHENTICATED
rybrevant.comnonenoneUNAUTHENTICATED
simponi.comnonenoneUNAUTHENTICATED
simponihcp.comnonenoneUNAUTHENTICATED
invega.comnonenoneUNAUTHENTICATED
sirturo.comnonenoneUNAUTHENTICATED
symtuza.comnonenoneUNAUTHENTICATED
remicade.comnonenoneUNAUTHENTICATED
akeega.comnonenoneUNAUTHENTICATED
balversa.comnonenoneUNAUTHENTICATED
ethicon.comnonenoneUNAUTHENTICATED
cerenovus.comnonenoneUNAUTHENTICATED
mentorwwllc.comnonenoneUNAUTHENTICATED
opsumit.comnonenoneUNAUTHENTICATED
uptravi.comnonenoneUNAUTHENTICATED
depuy.comnonenoneUNAUTHENTICATED
janssenoncology.comnonenoneUNAUTHENTICATED
janssenscience.comnonenoneUNAUTHENTICATED
janssenwithme.comnonenoneUNAUTHENTICATED

Confirmed owned by other companies (3)

Carrying a J&J-associated product name but provably not J&J domains. Excluded from any J&J finding.

DomainOwnerNote
imbruvica.comAbbVie Inc.Co-marketed; domain owned by AbbVie
ponvory.comJuvisé PharmaceuticalsPonvory divested by J&J (2024)
ponvoryhcp.comJuvisé PharmaceuticalsPonvory divested by J&J (2024)

Ownership could not be confirmed (5)

Anomalous registration or shared/ambiguous ownership — not attributed to J&J without confirmation.

DomainRegistrationNote
stelara.comGoDaddy registrarAnomalous registration — not on J&J registrar; unconfirmed
velys.comGoDaddy / Domains By ProxyPrivacy-proxied; J&J MedTech brand but unconfirmed
xarelto.comCSC (Bayer co-marketed)Bayer-originated drug; ownership ambiguous
xareltohcp.comCSC (Bayer co-marketed)Bayer-originated drug; ownership ambiguous
janssenimmunology.comn/aDoes not resolve; unconfirmed

Method & scope

Passive, public-records only. Every result is read from published DNS and public WHOIS — exactly what a receiving mail server and a domain registry expose. No active scanning, no probing, no access to J&J systems. SPF and DMARC were resolved over public DNS (Cloudflare 1.1.1.1); CNAME-delegated DMARC was followed to the published policy.

Ownership verification. Each domain was checked by WHOIS (registrar + registrant) and by its DMARC aggregate-report address. A domain is marked confirmed J&J only where reports flow to J&J's authentication tenant or the registrant is named J&J/Janssen/Actelion/Abiomed. Brand name alone was never treated as proof — and that discipline surfaced domains that belong to AbbVie and Juvisé.

Limits & reading the results

SPF -all hard-fail · ~all soft-fail · none no record. DMARC p=reject blocks spoofing · p=none reports only · none no policy. DKIM shown only where a key was found on a common selector — absence is not proof of no DKIM (selectors are private and not externally enumerable). Most WHOIS registrant fields are privacy-redacted, so "likely J&J" cannot be upgraded to "confirmed" from public data — only J&J can confirm those internally.

Coverage & visible emails

Domain set: a representative sample of current J&J public-facing domains (corporate, Innovative Medicine, MedTech, patient/HCP portals). Kenvue consumer brands are excluded. This is not an exhaustive registry of every domain J&J owns — that is not obtainable from public data alone. Certificate-transparency enumeration of janssen.com returned 43 subdomains, which inherit the organisational DMARC policy and are not separately listed.

Visible email addresses: none found. Public pages were checked for visibly-published addresses. J&J product sites use contact forms, telephone and ISI documents rather than published emails, and the corporate domains return HTTP 403 to automated retrieval. No addresses were captured, inferred or invented. A manual page-by-page pass can be added on request.