DMARC Continues To Confound Users, Report Says

  /     /     /  
Publicated : 22/11/2024   Category : security


DMARC Continues To Confound Users, Report Says


Almost three-quarters of those who deploy email authentication standard fail to get its full benefits, ValiMail says.



Relatively few companies are embracing DMARC email authentication, and of those that do, 75% of them arent using it correctly or getting the enforcement benefit it was designed to deliver, according to
a study released today
by email security vendor ValiMail.
The company says it examined the email authentication policies of the S&P 500, Fortune 1000, NASDAQ 100, FTSE 100, and three groups from Alexa (top 10,000, 100,000 and 1 million sites). DMARC adoption rates were below 50% for every measured segment, with percentages dipping into the single digits for some lists, according to ValiMail. Successful enforcement came in even lower, at 12%.
We were surprised by the large number of companies having a hard time with DMARC, says ValiMail CTO Peter Goldstein. We were also surprised by the consistency of the failure rate across the board -- youre not seeing an industry segment thats getting it mostly right. DMARC remains a challenge for companies of all sizes, regardless of their resources, he adds, in an interview with Dark Reading.
The Domain-based Message Authentication, Reporting, and Conformance (DMARC) standard works with Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) standards. Together, they enable domain owners to publish whitelists of approved senders, receive reports of senders attempting to use their domain names, and then block email from unapproved senders, a process also known as enforcement.
By adopting DMARC, organizations can blunt the impact of email-borne threats like phishing, ransomware, and other advanced attacks. DMARC also is supposed to help rein in shadow IT operations like unauthorized email distribution that can impact brand and undercut compliance efforts. The pairing of DMARC and email has been likened by some to SSL and ecommerce, which helped secure ecommerce transactions and fostered greater online use of credit cards.
But wrangling the back ends of email systems and their notoriously complex DNS tables isnt for the faint of heart. Goldstein acknowledges that DMARC is complicated to deploy, and partly explains why ValiMail developed an automated tool to simplify DMARC deployment.
Getting DMARC configured is difficult for large and small companies, Goldstein tells Dark Reading. In addition to their own internal domains, organizations are likely to use some combination of Office 365, Gmail, MailChimp, Salesforce.com and other third-party email services. But its a challenge to then retrofit them all with DMARC. Knowing what a MailChimp DNS looks like isn’t something the average IT person does, and there are hundreds of these to parse, Goldstein adds.
Still, DMARC adoption is relatively robust, according to Dan Ingevaldsen, CTO of Easy Solutions, another security vendor. DNS monitoring using DMARC has gone from 20,000 domains to 70,000-80,000 domains in the last year. Its a huge increase, but if you compare that to the Alexa 1 million, its obviously a lot smaller, he says.
Some of the new top-level domains (TLDs) like .bank and .secure require deployment of DMARC to use services on those domains, Ingevaldsen added, and more domain providers or registrars request DMARC be deployed by default.
With DMARC, you are trying to clean up a decentralized, complex environment thats existed for a long time, he explains. It then becomes a question of visibility into environment: How do you secure what you dont fully understand, or when you dont know where everything is? These are issues most large organizations grapple with regularly.
Ingevaldsen suggests that DMARC may follow a similar trajectory to the transition from intrusion detection to intrusion prevention. DMARC has a graduated deployment, like going from IDS to IPS, he says. So, many organizations may be content to remain in monitoring-only mode for an extended period so they can see where emails are going and whos sending them. Over time, you ratchet it up to reject fraudulent or malicious emails, he says. This will take time to measure and get to a full blocking policy.
Other relevant data points from the ValiMail DMARC report:
DMARC failure rate ranged from 62% to 80%, and had no correspondence to the organizations size; large organizations were as likely to fail at authentication as small ones.
DMARC adoption rates were less than 50% for every measured segment, with single-digit percentages for some entities.
The NASDAQ 100 checked in with the highest volume of attempted email authentication: 43%; smaller companies are less likely to authenticate, ValiMail finds.
Related Content:
How To Reduce Spam & Phishing With DMARC
Deleting Emails Original Sin: An Historical Perspective
How Many Layers Does Your Email Security Need?
 

Last News

▸ Nigerian scammers now turning into mediocre malware pushers. ◂
Discovered: 23/12/2024
Category: security

▸ Beware EMV may not fully protect against skilled thieves. ◂
Discovered: 23/12/2024
Category: security

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
DMARC Continues To Confound Users, Report Says