logo
Most high-traffic email domains still vulnerable to phishing

Most high-traffic email domains still vulnerable to phishing

Techday NZ30-05-2025
New research from EasyDMARC has found that 92% of the world's top 1.8 million email domains lack adequate protection against phishing attacks.
The EasyDMARC 2025 DMARC Adoption Report has revealed that only 7.7% of these domains are fully protected using the strictest DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy, known as 'p=reject'. This policy is designed to actively block malicious emails from being delivered to inboxes.
DMARC is an email authentication protocol that builds on existing standards such as SPF and DKIM, allowing domain owners to specify how they want mail servers to handle emails that fail authentication checks. The protocol also enables domain owners to receive reports on emails sent under their domain name, providing vital records of authentication attempts and potential abuse.
EasyDMARC's analysis demonstrates that although there has been a noticeable increase in DMARC adoption since 2023 — largely due to regulatory initiatives and mandates from major providers including Google, Yahoo, and Microsoft — most organisations opt for the weakest available configuration, 'p=none'. This setting only monitors for threats, rather than thwarting attacks by blocking illegitimate emails.
The report, which reviewed security practices across the most-visited websites globally as well as Fortune 500 and Inc. 5000 companies, shows a continued gap between DMARC adoption and meaningful implementation. More than half (52.2%) of the surveyed domains have not implemented DMARC at any level, leaving them exposed to phishing and spoofing risks. Among domains that do have a DMARC record, most have not configured enforcement policies or reporting mechanisms necessary for full protection.
The research also found that over 40% of the domains with a DMARC record did not include any reporting tags. This omission means these organisations have little to no visibility into authentication failures or an understanding of who might be sending emails on their behalf.
Gerasim Hovhannisyan, Chief Executive Officer of EasyDMARC, addressed the misconception surrounding DMARC adoption: "There's a growing perception that simply publishing a DMARC record is enough. But adoption without enforcement creates a dangerous illusion of security. In reality, most organisations are leaving the door wide open to attacks targeting customers, partners, or even employees."
Mandates have had a measurable effect. In the United States, where regulatory enforcement is strong, the proportion of phishing emails accepted dropped from 68.8% in 2023 to just 14.2% in 2025. Similar progress was noted in the UK and the Czech Republic, countries that also enforce DMARC usage. However, countries without strict requirements, such as the Netherlands and Qatar, showed minimal improvement in reducing phishing acceptance rates.
Recent high-profile cyber attacks, including those targeting retailers such as M&S and Co-op, serve as a backdrop for the report's release. In these incidents, attackers exploited weaknesses in email security through social engineering, costing affected businesses hundreds of thousands in losses. According to EasyDMARC, the increasing sophistication of phishing, partly driven by the use of AI, magnifies the risks for organisations that are inadequately protected.
Hovhannisyan further commented: "Misconfigurations, missing reporting, and passive DMARC policies are like installing a security system without ever turning it on. Phishing remains one of the oldest and most effective forms of cyberattack, and without proper enforcement, organisations are effectively handing attackers the keys to their business. As threats grow more sophisticated and compliance pressures mount, stopping halfway with DMARC enforcement is no longer an option."
The report methodology combined public DNS data with proprietary data collected through EasyDMARC's platform. It involved the review of aggregate DMARC reports from major mailbox providers and included a survey of 980 IT professionals across the United States, United Kingdom, Canada, and the Netherlands. This allowed for insights into regional differences in phishing trends, adoption challenges, and the varying influence of regulatory mandates.
The research concludes that while DMARC adoption has increased, genuine protection against phishing relies on both enforcement and visibility — elements still missing for the vast majority of high-traffic domains worldwide.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

ChatGPT got a big upgrade. Here's what to know about OpenAI's GPT-5
ChatGPT got a big upgrade. Here's what to know about OpenAI's GPT-5

NZ Herald

time20 hours ago

  • NZ Herald

ChatGPT got a big upgrade. Here's what to know about OpenAI's GPT-5

How much does it cost to access GPT-5? All ChatGPT users will get access to GPT-5, even those using the free version. But only those with a US$200-a-month ($335) 'Pro' subscription get unlimited access to the newly released system. GPT-5 will be the default mode on all versions. Users not paying for ChatGPT will only be able to ask a certain number of questions answered by GPT-5 before the chatbot switches back to using an older version of OpenAI's technology. How will GPT-5 change ChatGPT? GPT-5 responds to questions faster than OpenAI's previous offerings and is less likely to 'hallucinate' or make up false answers, OpenAI executives said at a news briefing before its release. It gives ChatGPT 'better taste' when generating writing, said Nick Turley, who leads work on the chatbot. OpenAI's new AI software can also answer queries using a process dubbed reasoning that shows the user a series of messages attempting to break down a question into steps before giving its final answer. 'GPT-5 is the first time that it really feels like talking to an expert, a PhD-level expert,' OpenAI CEO Sam Altman said. Altman said GPT-5 is particularly good at generating computer programming code, a feature that has become a major selling point for OpenAI and rival AI developers and has transformed the work of programmers. In a demo, the company showed how two paragraphs of instruction was enough to have GPT-5 create a simple website offering tutoring in French, complete with a word game and daily vocabulary tests. Execs say ChatGPT users can now connect the app with their Google calendars and email accounts. Photo / Getty Images Altman predicted that people without any computer science training will one day be able to quickly and easily generate any kind of software they need to help them at work or with other tasks. 'This idea of software on demand will be a defining part of the new GPT-5 era,' Altman said. Turley also claimed the upgrade made ChatGPT better at connecting with people. 'The thing that's really hard to put into words or quantify is the fact that just feels more human,' he said. In a livestream Thursday, OpenAI execs said ChatGPT users could now connect the app with their Google calendars and email accounts, allowing the chatbot to help people schedule activities around their existing plans. What does it mean for an AI chatbot to 'reason?' GPT-5 could give many people their first encounter with AI systems that attempt to work through a user's request step-by-step before giving a final answer. That so-called 'reasoning' process has become popular with AI companies because it can result in better answers on complex questions, particularly on math and coding tasks. Watching a chatbot generate a series of messages that read like an internal monologue can be alluring, but AI experts warn users not to confuse the technique with a peek into AI's black box. The self-chatter doesn't necessarily reflect an internal process like that of a human working on a problem, but designing chatbots to create what are sometimes dubbed 'chains of thought' forces the software to allocate more time and energy to a query. OpenAI released its first reasoning model in September for its paying users, but Chinese start-up DeepSeek in January released a free chatbot that made its 'chain of thought' visible to users, shocking Silicon Valley and temporarily tanking American tech stocks. The company said ChatGPT will now automatically send some queries to the 'reasoning' version of GPT-5, depending on the type of conversation and complexity of the questions asked. Is GPT-5 the 'super intelligence' or 'artificial general intelligence' OpenAI has promised? No. Tech leaders have for years been making claims that AI is improving so fast it will soon become able to learn and perform all tasks that humans can at or better than our own ability. But GPT-5 does not perform at that level. Super intelligence and artificial general intelligence, or AGI, remain ill-defined concepts because human intelligence is very different from the capabilities of computers, making comparisons tricky. OpenAI CEO Altman has been one of the biggest proponents of the idea that AI capabilities are increasing so rapidly that they will soon revolutionise many aspects of society. 'This is a significant step forward,' Altman said of GPT-5. 'I would say it's a significant fraction of the way to something very AGI-like.' Some people have alleged that loved ones were driven to violence, delusion or psychosis by hours spent talking to ChatGPT. Photo / Getty Images Does GPT-5 change ChatGPT's personality? Changes OpenAI made to ChatGPT in April triggered backlash online after examples of the chatbot appearing to flatter or manipulate users went viral. The company undid the update, saying an attempt to enhance the chatbot's personality and make it more personalised instead led it to reinforce user beliefs in potentially dangerous ways, a phenomenon the industry calls 'sycophancy'. OpenAI said it worked to reduce that tendency further in GPT-5. As AI companies compete to keep users engaged with their chatbots, they could make them compelling in potentially harmful ways, similar to social media feeds, The Washington Post reported in May. In recent months, some people have alleged that loved ones were driven to violence, delusion or psychosis by hours spent talking to ChatGPT. Lawsuits against other AI developers claim their chatbots contributed to incidents of self-harm and suicide by teens. OpenAI released a report on GPT-5's capabilities and limits Thursday that said the company looked closely at the risks of psychosocial harms and worked with Microsoft to probe the new AI system. It said the reasoning version of GPT-5 could still 'be improved on detecting and responding to some specific situations where someone appears to be experiencing mental or emotional distress'. Earlier this week, OpenAI said in a blog post it was working with physicians across more than 30 countries, including psychiatrists and paediatricians, to improve how ChatGPT responds to people in moments of distress. Turley, the head of ChatGPT, said the company is not optimising ChatGPT for engagement.

Platform guides course decisions
Platform guides course decisions

Otago Daily Times

time2 days ago

  • Otago Daily Times

Platform guides course decisions

It is hard to fathom how he does it. Final-year University of Otago medical student Josiah Bugden has somehow also found time to establish a rapidly growing platform to help students navigate university life with confidence. Mr Bugden (25) is a finalist in the Momentum student entrepreneur category in the KiwiNet Research Commercialisation Awards for CourseSpy, which is about creating transparency in higher education. What started as a side project has evolved into a platform with more than 250,000 visits, which helps students make better and more informed decisions about their tertiary study. CourseSpy was born of Mr Bugden's own frustrations as a student. Prior to embarking on his medical studies, he did a science degree. He said while there were some necessary papers, it required having to "build your degree" and he found it tricky figuring out which papers to take. All he had to go off was the paper title and maybe a couple of sentences, yet there were so many options available, he said. In his hall of residence, friends would pass around Google documents, sharing course advice, and it got him thinking — and tinkering. Teaching himself to code, he built a basic website for students to leave course reviews and also tips and tricks and discovered people liked it. While the website was very unpolished, he saw how students were using it and decided it might be worth putting in more effort and seeing if he could expand the offering and make a viable business. Over last year, he became involved with Startup Dunedin and the Audacious business challenge and Momentum, the national student-led investment committee programme. That provided him with advice on how to take the "next steps" and included getting a team around him, which included his brother Sam, to work on it. What the team wanted to create was a one-stop hub for students to get course advice and it had evolved to be more than a review site, he said. It allowed students to plan their degrees, calculate entrance scores, manage timetables, choose accommodation and access curated study resources. CourseSpy now hosted more than 15,000 course reviews across all eight New Zealand universities and had had about 250,000 page visits, he said. In a recent user survey, the overwhelming majority of student users reported they had changed their future course selections based on insights gained through the platform. In the past year, CourseSpy had also launched Mastery Modules — interactive, adaptive question banks designed to guide students through each lecture and improve their long-term retention and grades. Those modules were built by a team of tutors and high-achieving students to ensure high-quality, course-specific learning support. Mr Bugden said his goal was to continue the rapid growth of CourseSpy by adding tutors and textbooks and further developing Mastery Modules for CourseSpy's proprietary learning platform while looking to expand overseas soon. He acknowledged the juggle between his medical studies and CourseSpy had been "tricky" to manage but said he had enjoyed learning about business and having a great team around him had been pivotal. He now wanted to involve more people in the project to ensure it was sustainable into the future. He was passionate about medicine and was looking forward to working as a doctor next year and it was likely he would take on more of a consulting role with CourseSpy. The winners will be announced at a function in Auckland on October 22.

Social media firms 'turning a blind eye' to child abuse material: watchdog
Social media firms 'turning a blind eye' to child abuse material: watchdog

Otago Daily Times

time3 days ago

  • Otago Daily Times

Social media firms 'turning a blind eye' to child abuse material: watchdog

Australia's internet watchdog has said the world's biggest social media firms are still 'turning a blind eye' to online child sex abuse material on their platforms, and said YouTube in particular had been unresponsive to its enquiries. In a report released on Wednesday, the eSafety Commissioner said YouTube, along with Apple AAPL.O, failed to track the number of user reports it received of child sex abuse appearing on their platforms and also could not say how long it took them to respond to such reports. The Australian government decided last week to include YouTube in its world-first social media ban for teenagers, following eSafety's advice to overturn its planned exemption for the Alphabet-owned Google's GOOGL.O video-sharing site. 'When left to their own devices, these companies aren't prioritising the protection of children and are seemingly turning a blind eye to crimes occurring on their services,' eSafety Commissioner Julie Inman Grant said in a statement. 'No other consumer-facing industry would be given the licence to operate by enabling such heinous crimes against children on their premises, or services.' A Google spokesperson said 'eSafety's comments are rooted in reporting metrics, not online safety performance', adding that YouTube's systems proactively removed over 99% of all abuse content before being flagged or viewed. 'Our focus remains on outcomes and detecting and removing (child sexual exploitation and abuse) on YouTube,' the spokesperson said in a statement. Meta META.O - owner of Facebook, Instagram and Threads, three of the biggest platforms with more than 3 billion users worldwide - has said it prohibits graphic videos. The eSafety Commissioner, an office set up to protect internet users, has mandated Apple, Discord, Google, Meta, Microsoft MSFT.O, Skype, Snap SNAP.N and WhatsApp to report on the measures they take to address child exploitation and abuse material in Australia. The report on their responses so far found a 'range of safety deficiencies on their services which increases the risk that child sexual exploitation and abuse material and activity appear on the services'. Safety gaps included failures to detect and prevent livestreaming of the material or block links to known child abuse material, as well as inadequate reporting mechanisms. It said platforms were also not using 'hash-matching' technology on all parts of their services to identify images of child sexual abuse by checking them against a database. Google has said before that its anti-abuse measures include hash-matching technology and artificial intelligence. The Australian regulator said some providers had not made improvements to address these safety gaps on their services despite it putting them on notice in previous years. 'In the case of Apple services and Google's YouTube, they didn't even answer our questions about how many user reports they received about child sexual abuse on their services or details of how many trust and safety personnel Apple and Google have on-staff,' Inman Grant said.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store