Self-Regulation In The Email Provider Market

In a recent webinar, Microsoft's Principal PM Architect, Ross Adams, hinted at plans for Microsoft to join Google, Apple, and Yahoo and require email authentication for bulk senders. This encompasses any email domain that sends over 5,000 emails daily, giving millions of businesses a stark choice: comply with the new standards or risk their security and email deliverability.

Businesses that fall into the 'bulk sender' category are required to implement a DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy. This policy outlines how to handle emails that fail authentication checks - whether they should be accepted, rejected, or sent to the junk folder.

By ensuring only legitimate emails are delivered, DMARC enhances email security and reduces the risk of phishing and other email-based attacks.

With Microsoft now precariously agreeing with the need for this email requirement, the four largest email providers globally are on board with eventually implementing this policy. But what has brought about this unanimous agreement? After all, DMARC isn’t a legal requirement. 

Secure Inboxes, Secure Customer Base

While we can't know the exact motivations behind the implementation of DMARC without regulatory influence, it’s an understandable decision. In a world with dozens of communication channel choices, maintaining the integrity of email, especially for professional communications, is crucial. As of May 2024, the UK's National Cybersecurity Centre had received over 32 million reports of phishing scams from the public. This surge is likely unsurprising to many email users, as the AI boom has enabled cybercriminals to create more frequent and sophisticated scams that are harder to detect.

As AI-driven scams continue to rage, email providers must maintain their grip on professional communications.

With cyberattacks on the rise and businesses prioritizing cybersecurity more than ever, protecting the email sphere from significant losses in trust is in the best interest of these providers. While they can’t stop the sophistication of phishing emails from improving, they can allow customers to control whose emails are being delivered to their inboxes. By adopting DMARC, the four largest email providers globally are not just enhancing security but also ensuring they remain the trusted backbone of professional and personal communication. This unanimous agreement highlights a proactive approach to safeguarding their customer base and preserving the reliability of email as a communication tool.

Importantly, however, this move isn't just beneficial to email providers - it's beneficial to organizations and their customers too. It's a win-win-win!

As frequent targets of phishing attacks, customers are eager to secure their inboxes, especially with scams continuing to increase. As a result, implementing DMARC allows businesses to show their commitment to protecting customers' personal information and financial assets, fostering trust and brand loyalty.

These changes have also created an atmosphere where organizations are incentivized to proactively get ahead of the competition. This is because DMARC doesn't just reduce the chances of imitation or attack; it also means improved deliverability, resulting in happier, more engaged customers. 

Given these mutual benefits, it's surprising this shift towards self-regulation hasn't happened sooner. But it makes sense - it's a rare case where self-regulation provides a competitive edge in the long run. Cyber attacks are only going in one direction, and providers that offer the most reliable and secure email experiences will ultimately prevail.

Strength in numbers: How the collaborative shift towards self-regulation brought to light the seriousness of phishing

The collective shift towards self-regulation signals that top email providers now see DMARC as a critical line of defense. By announcing cybersecurity protocols collectively, email providers have established a consistent standard across the industry, which tells us that curbing the threat of phishing is a top priority. Importantly, this uniformity simplifies compliance for businesses and users, ensuring that everyone adheres to the same security practices and is equally protected as a result. 

On top of this, the decisive move has put pressure on other organisations to follow suit. Smaller email providers and businesses are more likely to adopt these standards to remain competitive and compliant, helping drive the industry’s cybersecurity forward exponentially.  

A New Era Of Email Security

Ultimately, these regulatory changes go a long way in combatting the rapidly rising issue of phishing and spoofing. As cyber criminals refine and multiply their phishing techniques with AI tools, lowering the barrier to entry significantly, DMARC remains a crucial defense against malicious email content. This increased protection helps end-users avoid falling victim to scams, thereby safeguarding their personal information and financial assets.

Google has signaled plans to continue rejecting non-compliant emails in the coming months, meaning that businesses have a short window to prepare. With Microsoft and Yahoo likely to follow shortly, there has never been a better time to re-evaluate approaches to cybersecurity as we enter this new era of digital protection.   

Gerasim Hovhannisyan is Founder and CEO of EasyDMARC

Image: Ideogram

You Might Also Read: 

DMARC Email Validation: Cracking Down On Fraud:


If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

 

« Google Will Pay $23B To Acquire Cyber Security Firm Wiz
The Top Nine API Security Vulnerabilities »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

FireEye

FireEye

FireEye delivers unmatched detection, protection and response technology through an extensible and flexible cloud-based XDR platform.

Fortinet

Fortinet

Fortinet is a provider of network security systems. Our products provide protection against dynamic security threats while simplifying the IT security infrastructure.

Secure India

Secure India

Secure India provides Forensic Solutions that help Government and Business in dealing with prevention and resolution of Cyber related threats.

Sepior

Sepior

Our vision is to make Sepior the leading provider of cloud-encryption software in the world.

Verlingue

Verlingue

Verlingue (formerly ICB Group) is a leading corporate insurance broker providing Insurance, Risk Management and related advice to businesses and private clients.

WetStone Technologies

WetStone Technologies

WetStone develops software solutions that support investigators and analysts engaged in eCrime Investigation, eForensics and incident response activities.

Salt Communications

Salt Communications

Salt communications is a global leader in secure communications. Our bespoke platform is the secure communications solution that uniquely gives complete control to our customers.

Swiss CyberSecurity

Swiss CyberSecurity

Swiss CyberSecurity is a non-profit group based in Geneva, set up to provide information and as a forum for discussion of topics related to CyberSecurity.

MAD Security

MAD Security

MAD Security is a premier provider of information and cybersecurity solutions that combine technology, managed security services, support and training.

InstaSafe Technologies

InstaSafe Technologies

InstaSafe®, a Software Defined Perimeter based (SDP) one-stop Secure Access Solution for On-Premise and Cloud Applications.

Forta

Forta

Forta is a real-time detection network for security & operational monitoring of blockchain activity.

Centre for Cyber Security Research & Innovation

Centre for Cyber Security Research & Innovation

The Centre for Cyber Security Research & Innovation is Nepal's First Academic Research Institute to focus on understanding the overall Information Security of Nepalese Organizations.

Exiger

Exiger

Exiger is revolutionizing the way corporations, government agencies and banks navigate risk and compliance in their third-parties, supply chains and customers.

ConvergePoint

ConvergePoint

ConvergePoint is the leading compliance software provider on the Microsoft Office 365 SharePoint platform.

Cyber Industrial Networks

Cyber Industrial Networks

Cyber Industrial Networks objective is to service the needs of industry in achieving reliable, robust and secure infrastructure that supports productivity.

ITRM

ITRM

ITRM are one of the UK’s top managed service providers and offer a range of award-winning IT solutions, from ad-hoc consultancy to cyber security.