logo

Google's DMARC Push Pays Off, but Email Security Challenges Remain

ID: f5b0784e-9f65-5aee-96ff-4bae12f4b545

STIX ID: report--f5b0784e-9f65-5aee-96ff-4bae12f4b545

Feed Name: Dark Reading

Date Published: 2025-02-07

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Since Google and Yahoo required bulk senders to implement DMARC, adoption has roughly doubled and unauthenticated email volumes have dropped significantly, but attackers have adapted by using lookalike domains, SPF "include" misconfigurations, and orphaned subdomains to send authenticated phishing and spam. The article recommends moving organizations from "none" to "quarantine" and "reject", monitoring SPF/DNS records to prevent subdomain takeover, and adopting BIMI alongside DMARC to improve visibility and reduce impersonation risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.