Site navigation

Report: Half of Domains Still Lack Adequate Email Protection

Tom Quinn

,

email security
Despite growing adoption of email defence measures, new research shows millions of domains remain poorly protected, fuelling brand impersonation and disinformation campaigns.

Malicious actors are ramping up their exploitation of email-based attacks to impersonate brands, launch phishing campaigns, and spread false information, according to fresh research warning firms must step up their defences.

In its latest report, email authentication provider Valimail found that email is still the most exploited attack vector for cyber-criminals and disinformation campaigns, with almost every sector from financial services to government and education facing significant email-based threats, but with varying levels of preparedness.

Valimail’s 2025 Disinformation and Malicious Email Report revealed that online retail platforms lead the way with 94% of surveyed domains implementing basic Domain-based Message Authentication, Reporting, and Conformance (DMARC) measures, while healthcare lags behind, with just over one-third of firms having implemented the bare minimum protections.

DMARC is considered a critical security measure in the modern email landscape, matching email headers to sender’s domains and ensuring that only authorised senders can use a domain to send emails, protecting both brands and customers from external attacks.

Big names, including Microsoft, Google and Yahoo, already require bulk email senders to implement DMARC measures, with several US government agencies, such as the National Institute of Standards and Technology and the Department of Homeland Security, either recommending or mandating email senders implement DMARC.

The data from Valimail shows that many in the private sector are following suit, with financial service firms widely adopting DMARC defences (80%), although a third of domains lack enforcement policies to prevent spoofing.

Surprisingly, some information technology companies showed concerning gaps in their security, with nearly a third of surveyed domains lacking the ability to prevent the use of their domain name in spoofed email messages.


Recommended


Valimail’s analysis of 3.7 billion suspicious emails revealed that while over 7.2 million domains have adopted some form of email authentication, nearly half still lack adequate protection against domain spoofing.

Added to that, 3.4 million domains were found enacting a policy of p=none, indicating a ‘monitoring only’ policy that will generate any required DMARC reports but take no action against emails that fail authentication, leaving them to be delivered to vulnerable recipients.

“What’s particularly concerning is that while many organisations have taken initial steps toward securing their email domains, a significant percentage have implemented overly permissive or non-protective policies,” said Alexander García-Tobar Valimail CEO and co-founder. 

“This creates a false sense of security while leaving these organisations vulnerable to impersonation attacks that can damage reputation, erode customer trust, and compromise sensitive information.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data