Self-Regulation In The Email Provider Market

In a recent webinar, Microsoft's Principal PM Architect, Ross Adams, hinted at plans for Microsoft to join Google, Apple, and Yahoo and require email authentication for bulk senders. This encompasses any email domain that sends over 5,000 emails daily, giving millions of businesses a stark choice: comply with the new standards or risk their security and email deliverability.

Businesses that fall into the 'bulk sender' category are required to implement a DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy. This policy outlines how to handle emails that fail authentication checks - whether they should be accepted, rejected, or sent to the junk folder.

By ensuring only legitimate emails are delivered, DMARC enhances email security and reduces the risk of phishing and other email-based attacks.

With Microsoft now precariously agreeing with the need for this email requirement, the four largest email providers globally are on board with eventually implementing this policy. But what has brought about this unanimous agreement? After all, DMARC isn’t a legal requirement. 

Secure Inboxes, Secure Customer Base

While we can't know the exact motivations behind the implementation of DMARC without regulatory influence, it’s an understandable decision. In a world with dozens of communication channel choices, maintaining the integrity of email, especially for professional communications, is crucial. As of May 2024, the UK's National Cybersecurity Centre had received over 32 million reports of phishing scams from the public. This surge is likely unsurprising to many email users, as the AI boom has enabled cybercriminals to create more frequent and sophisticated scams that are harder to detect.

As AI-driven scams continue to rage, email providers must maintain their grip on professional communications.

With cyberattacks on the rise and businesses prioritizing cybersecurity more than ever, protecting the email sphere from significant losses in trust is in the best interest of these providers. While they can’t stop the sophistication of phishing emails from improving, they can allow customers to control whose emails are being delivered to their inboxes. By adopting DMARC, the four largest email providers globally are not just enhancing security but also ensuring they remain the trusted backbone of professional and personal communication. This unanimous agreement highlights a proactive approach to safeguarding their customer base and preserving the reliability of email as a communication tool.

Importantly, however, this move isn't just beneficial to email providers - it's beneficial to organizations and their customers too. It's a win-win-win!

As frequent targets of phishing attacks, customers are eager to secure their inboxes, especially with scams continuing to increase. As a result, implementing DMARC allows businesses to show their commitment to protecting customers' personal information and financial assets, fostering trust and brand loyalty.

These changes have also created an atmosphere where organizations are incentivized to proactively get ahead of the competition. This is because DMARC doesn't just reduce the chances of imitation or attack; it also means improved deliverability, resulting in happier, more engaged customers. 

Given these mutual benefits, it's surprising this shift towards self-regulation hasn't happened sooner. But it makes sense - it's a rare case where self-regulation provides a competitive edge in the long run. Cyber attacks are only going in one direction, and providers that offer the most reliable and secure email experiences will ultimately prevail.

Strength in numbers: How the collaborative shift towards self-regulation brought to light the seriousness of phishing

The collective shift towards self-regulation signals that top email providers now see DMARC as a critical line of defense. By announcing cybersecurity protocols collectively, email providers have established a consistent standard across the industry, which tells us that curbing the threat of phishing is a top priority. Importantly, this uniformity simplifies compliance for businesses and users, ensuring that everyone adheres to the same security practices and is equally protected as a result. 

On top of this, the decisive move has put pressure on other organisations to follow suit. Smaller email providers and businesses are more likely to adopt these standards to remain competitive and compliant, helping drive the industry’s cybersecurity forward exponentially.  

A New Era Of Email Security

Ultimately, these regulatory changes go a long way in combatting the rapidly rising issue of phishing and spoofing. As cyber criminals refine and multiply their phishing techniques with AI tools, lowering the barrier to entry significantly, DMARC remains a crucial defense against malicious email content. This increased protection helps end-users avoid falling victim to scams, thereby safeguarding their personal information and financial assets.

Google has signaled plans to continue rejecting non-compliant emails in the coming months, meaning that businesses have a short window to prepare. With Microsoft and Yahoo likely to follow shortly, there has never been a better time to re-evaluate approaches to cybersecurity as we enter this new era of digital protection.   

Gerasim Hovhannisyan is Founder and CEO of EasyDMARC

Image: Ideogram

You Might Also Read: 

DMARC Email Validation: Cracking Down On Fraud:


If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

 

« Google Will Pay $23B To Acquire Cyber Security Firm Wiz
The Top Nine API Security Vulnerabilities »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

MD5

MD5

MD5 is a leading UK provider of Digital Forensic & eDiscovery services to large multi-national corporate businesses, Law Enforcement & Government Agencies, high profile legal firms.

VKANSEE

VKANSEE

VKANSEE offer the world's thinnest optical fingerprint sensor for mobile device protection.

Private Internet Access

Private Internet Access

Private Internet Access is a Virtual Private Network services provider offering secure encrypted access to the internet.

Lumen Technologies

Lumen Technologies

Lumen is an enterprise technology platform that enables companies to capitalize on emerging applications and power the 4th Industrial Revolution (4IR).

BlueFiles

BlueFiles

BlueFiles enables users to send encrypted files securely while maintaining full control over recipients, access periods, downloads, and printing.

NGS (UK)

NGS (UK)

NGS (UK) Ltd are independent, vendor agnostic, next generation security trusted advisors, providing all-encompassing solutions from the perimeter to the endpoint.

KnectIQ

KnectIQ

Building Trust Environments in a Zero-Trust World. KnectIQ offers KIQAssure, an Ultra High Security Solution for Data in Flight.

Infopercept Consulting

Infopercept Consulting

Infopercept is a leading cybersecurity company in India, providing a critical layer of security to protect business information, infrastructure & assets across the organization.

Amvia

Amvia

Amvia is a fast-growing telecoms, Internet and Microsoft service provider. We supply voice, data and cyber security services to 100s of small and large companies.

Picnic

Picnic

Picnic is a gritty, pioneering team of intelligence and cybersecurity specialists focused on solving the security challenge of our time - social engineering.

Appalachia Technologies

Appalachia Technologies

Appalachia is a full service Managed Services Provider with a focus on cybersecurity, backed by the best engineers.

Limes Security

Limes Security

Limes Security GmbH is the leading OT Security expert in the German-speaking region of Europe.

Cyber Ranges

Cyber Ranges

Cyber Ranges is the next-generation cyber range for the development of cyber capabilities and the validation of cyber security skills and organizational cyber resilience.

Zama

Zama

Zama - pioneering homomorphic encryption. We believe people shouldn't care about privacy. Not because it doesn't matter, but because it shouldn't be an issue!

Downdetector

Downdetector

Downdetector helps people all over the world understand disruptions to vital services such as the internet, social media, web hosting platforms, banks, games, entertainment, and more.

Screwloose IT

Screwloose IT

Screwloose IT are a national provider of information technology services. We specialise in managed IT, cloud services, cyber security, website design and digital marketing for businesses of all sizes.