Self-Regulation In The Email Provider Market

In a recent webinar, Microsoft's Principal PM Architect, Ross Adams, hinted at plans for Microsoft to join Google, Apple, and Yahoo and require email authentication for bulk senders. This encompasses any email domain that sends over 5,000 emails daily, giving millions of businesses a stark choice: comply with the new standards or risk their security and email deliverability.

Businesses that fall into the 'bulk sender' category are required to implement a DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy. This policy outlines how to handle emails that fail authentication checks - whether they should be accepted, rejected, or sent to the junk folder.

By ensuring only legitimate emails are delivered, DMARC enhances email security and reduces the risk of phishing and other email-based attacks.

With Microsoft now precariously agreeing with the need for this email requirement, the four largest email providers globally are on board with eventually implementing this policy. But what has brought about this unanimous agreement? After all, DMARC isn’t a legal requirement. 

Secure Inboxes, Secure Customer Base

While we can't know the exact motivations behind the implementation of DMARC without regulatory influence, it’s an understandable decision. In a world with dozens of communication channel choices, maintaining the integrity of email, especially for professional communications, is crucial. As of May 2024, the UK's National Cybersecurity Centre had received over 32 million reports of phishing scams from the public. This surge is likely unsurprising to many email users, as the AI boom has enabled cybercriminals to create more frequent and sophisticated scams that are harder to detect.

As AI-driven scams continue to rage, email providers must maintain their grip on professional communications.

With cyberattacks on the rise and businesses prioritizing cybersecurity more than ever, protecting the email sphere from significant losses in trust is in the best interest of these providers. While they can’t stop the sophistication of phishing emails from improving, they can allow customers to control whose emails are being delivered to their inboxes. By adopting DMARC, the four largest email providers globally are not just enhancing security but also ensuring they remain the trusted backbone of professional and personal communication. This unanimous agreement highlights a proactive approach to safeguarding their customer base and preserving the reliability of email as a communication tool.

Importantly, however, this move isn't just beneficial to email providers - it's beneficial to organizations and their customers too. It's a win-win-win!

As frequent targets of phishing attacks, customers are eager to secure their inboxes, especially with scams continuing to increase. As a result, implementing DMARC allows businesses to show their commitment to protecting customers' personal information and financial assets, fostering trust and brand loyalty.

These changes have also created an atmosphere where organizations are incentivized to proactively get ahead of the competition. This is because DMARC doesn't just reduce the chances of imitation or attack; it also means improved deliverability, resulting in happier, more engaged customers. 

Given these mutual benefits, it's surprising this shift towards self-regulation hasn't happened sooner. But it makes sense - it's a rare case where self-regulation provides a competitive edge in the long run. Cyber attacks are only going in one direction, and providers that offer the most reliable and secure email experiences will ultimately prevail.

Strength in numbers: How the collaborative shift towards self-regulation brought to light the seriousness of phishing

The collective shift towards self-regulation signals that top email providers now see DMARC as a critical line of defense. By announcing cybersecurity protocols collectively, email providers have established a consistent standard across the industry, which tells us that curbing the threat of phishing is a top priority. Importantly, this uniformity simplifies compliance for businesses and users, ensuring that everyone adheres to the same security practices and is equally protected as a result. 

On top of this, the decisive move has put pressure on other organisations to follow suit. Smaller email providers and businesses are more likely to adopt these standards to remain competitive and compliant, helping drive the industry’s cybersecurity forward exponentially.  

A New Era Of Email Security

Ultimately, these regulatory changes go a long way in combatting the rapidly rising issue of phishing and spoofing. As cyber criminals refine and multiply their phishing techniques with AI tools, lowering the barrier to entry significantly, DMARC remains a crucial defense against malicious email content. This increased protection helps end-users avoid falling victim to scams, thereby safeguarding their personal information and financial assets.

Google has signaled plans to continue rejecting non-compliant emails in the coming months, meaning that businesses have a short window to prepare. With Microsoft and Yahoo likely to follow shortly, there has never been a better time to re-evaluate approaches to cybersecurity as we enter this new era of digital protection.   

Gerasim Hovhannisyan is Founder and CEO of EasyDMARC

Image: Ideogram

You Might Also Read: 

DMARC Email Validation: Cracking Down On Fraud:


If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

 

« Google Will Pay $23B To Acquire Cyber Security Firm Wiz
The Top Nine API Security Vulnerabilities »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Voyager Networks

Voyager Networks

Voyager Networks is an IT solutions business with a focus on Enterprise Networks, Security and Collaborative Communications.

Swivel Secure

Swivel Secure

Swivel Secure is an award winning provider of multi-factor authentication solutions.

Paladion

Paladion

Paladion is a provider of managed IT security services.

CERT-IS

CERT-IS

CERT-IS is the national Computer Emergency Response Team for Iceland.

FinlayJames

FinlayJames

FinlayJames supports cyber security companies to meet the increasing demand and pressure on them by finding top talent within the industry for their sales, marketing and technical teams.

Ensign InfoSecurity

Ensign InfoSecurity

Ensign InfoSecurity is Southeast Asia’s largest pure-play cybersecurity firm.

Secure Recruitment

Secure Recruitment

Secure Recruitment is a specialist Executive Search business that focuses its efforts on attracting specific exceptional talent in Cyber Security.

Savanti Consulting

Savanti Consulting

Savanti provides practitioner-led cyber security services tailored to meet each organisation’s unique requirements.

Cyber Risk Aware

Cyber Risk Aware

Cyber Risk Aware provide a security awareness and phishing simulation platform that focuses on real threats and educates and empowers employees to be the first line of defence.

ValueMentor

ValueMentor

ValueMentor is a leading cyber security service provider in the Middle East. We enable clients to reduce risk by taking a strategic approach to cybersecurity.

IDX

IDX

IDX is the leading consumer privacy platform built for agility in the digital age.

Ridge Security

Ridge Security

Ridge Security enables enterprise and web application teams, ISVs, governments, education, DevOps, anyone responsible for ensuring software security to affordably and efficiently test their systems.

Wib

Wib

Wib is an API security leader. We are the only company providing a solution for the entire API development lifecycle.

xdr.global

xdr.global

Xdr.global is a cybersecurity consulting firm, focused on promoting and aligning Extended Detection and Response (XDR) security solutions.

Centric Consulting

Centric Consulting

Centric Consulting is an international management consulting firm with unmatched expertise in business transformation, AI strategy, cyber risk management, technology implementation and adoption. 

Coalition for Secure AI (CoSAI)

Coalition for Secure AI (CoSAI)

CoSAI is an open ecosystem of AI and security experts from industry leading organizations dedicated to sharing best practices for secure AI deployment and collaborating on AI security research.