Vendor Dashboard
The vendor dashboard shows all vendor domains detected in your Abnormal VendorBase
Overview
The vendor dashboard shows all vendor domains detected in your Abnormal VendorBase, enriched with Sendmarc's email-security scoring and ATO Scoring, and allows you to classify each vendor individually or in bulk to keep your vendor list focused on the ones that matter.
![]()
Summary Statistics
At the top of the dashboard, the summary statistics give a quick health overview of your vendor landscape:
|
Statistic |
What it means |
|
Total Vendors |
The number of active vendors (excluding Archived and Not a Vendor). |
|
Average Overall Sendmarc Score |
The average Sendmarc overall email-security score across all active vendors that have been enriched with a sendmarc score. Displayed as a number out of 100 — higher is better. |
|
Can Be Impersonated |
The percentage of vendors that could be impersonated by attackers. A vendor is considered impersonatable if its domain has no DMARC enforcement policy (i.e. DMARC is set to |
|
Sendmarc At-Risk Vendors |
The number of vendors with a High/Medium Sendmarc risk level. These vendors represent the greatest immediate concern. |
Vendor Classification
Vendor Classification lets you triage the third-party vendors surfaced by the Sendmarc–Abnormal integration so your vendor list reflects the real state of your supply chain. Each vendor is assigned a status that controls where it appears in the listing.
Vendor Statuses
Every vendor synced from Abnormal starts as None (unclassified). You can then assign one of the following statuses:
Authorized — Vendor has been reviewed and approved.
Unauthorized — Vendor has not been approved or is still under review.
Onboarding — Vendor is in the process of being approved.
Archived — Previously classified but no longer active; hidden from view.
Not a Vendor — No vendor relationship exists (false positive).

Bulk Vendor Classification
For accounts with a large number of unclassified vendors, you can update those vendors in bulk
- Click Bulk Update in the top-right of the vendor listing.
- Paste up to 500 vendor domain names into the text area, one per line.
- Select the target clasification status to apply from the dropdown
- Mark remaining vendors as 'Not a Vendor'.
- Click Update. The drawer reports the outcome in four groups:
- Updated — vendors that were changed to the selected status.
- Not Found — supplied domains that don't match a vendor on this account.
- Failed — vendors that could not be updated because they are currently Archived or Not a Vendor. Use the single-vendor update to revive them first.
- Marked as Not a Vendor — number of domains marked as Not a Vendor. This only applies to domains that were previously unclassified

Vendor Detailed View
When selecting a vendor, you can observe the risk scores in more detail. It can be broken down as follows:
Sendmarc's Overall Domain Score
A 0–100 rating of the vendor's email-security posture, derived from their DMARC, MTA-STS, and BIMI configuration. Higher scores indicate stronger protection against impersonation, interception, and brand abuse. The drawer breaks the score down into its three sub-ratings: Impersonation, Privacy, and Marketing.
Sendmarc Account Takeover Score
A 0–100 measure of how exposed the vendor's employees are to credential theft and active device compromise, weighted by how recently those threats were detected. Lower is better — 0 means no detected exposure, 100 means severe exposure. The score is banded as Low, Moderate, High, or Critical and split into two sub-scores: Credentials Exposed (breached and phished credentials in circulation) and Infection Footprint (infected machines and infostealer activity).
Abnormal Vendor Analysis
Abnormal Security's own assessment of the vendor. This includes behavioural signals Abnormal Security has observed for this vendor across their customer base — for example, Vendor Compromise Seen in Abnormal Community, Vendor Impersonation in Abnormal Community, Vendor recently seen impersonated etc
