It’s Time to Enforce DMARC Strictly

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

The State of DMARC Email Authentication and Security Standard: Promises and Challenges Ahead

The state of DMARC email authentication and security standard started the year with high expectations in 2024. Google and Yahoo set a deadline of February for bulk email senders to implement the Domain-based Message Authentication, Reporting, and Conformance (DMARC) policy. As a result, the number of email domains with a valid DMARC record saw a 60% increase in just two months, totaling nearly 6.8 million domains with email sender authentication configured by September.

Despite this initial surge, businesses have been slow to fully embrace email authentication on their domains. Many have yet to transition from DMARC’s basic policy of ‘p=none’ to more strict policies that enforce quarantining or rejecting non-authenticated emails. In fact, the share of DMARC-enabled domains with an enforced policy has decreased from 18% to less than 14% over the past year.

Concerns about potentially missing legitimate messages have deterred some companies from implementing stricter enforcement measures. The fear of losing out on crucial leads and customer communications has led to a conservative approach towards DMARC adoption.

With major email services likely to push for further DMARC compliance, organizations are advised to plan for transitioning their policies to higher levels of enforcement. Valimail’s Seth Blank emphasizes the importance of monitoring DMARC reports at every enforcement level to improve email security and prevent abuse. As the industry moves towards greater email authentication, companies will need to adapt to ensure the integrity of their email communications.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

US Senator Requests NSA Guidance on Best Practices for VPN Use Against Foreign Surveillance

A prominent US senator is urging the National Security Agency (NSA) to provide public guidance on best practices for using virtual private networks (VPNs)...

Cisco Patches Critical Nexus 9000 Vulnerability Allowing Remote Code Execution as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker...

BREEZE COMET Threat Actor Targets Brazilian Financial Sector with Sophisticated Attacks

BREEZE COMET: A Rising Threat to Brazil's Financial Sector In 2024, Mandiant began investigating a series of cyber compromises targeting Brazilian financial services, retail, and...

Dropbox Reports Compromise of 5,000 Accounts Due to Legacy Login Vulnerability

Dropbox has reported that approximately 5,000 accounts were compromised last month due to a legacy login vulnerability associated with Lenovo IDs. This breach allowed...