logo
#

Latest news with #GerasimHovhannisyan

Just 3% of New Zealand domains enforce top anti-phishing policy
Just 3% of New Zealand domains enforce top anti-phishing policy

Techday NZ

time13-06-2025

  • Business
  • Techday NZ

Just 3% of New Zealand domains enforce top anti-phishing policy

Only 3% of New Zealand domains have implemented full protection against phishing according to new research by EasyDMARC. EasyDMARC's analysis covered 141,242 domains registered in New Zealand, highlighting a low adoption rate of the strictest email authentication setting known as DMARC at p=reject. DMARC, or Domain-based Message Authentication, Reporting & Conformance, is a protocol designed to verify that emails are legitimately sent by the domain they claim to represent, with the p=reject policy providing the highest available security by blocking unauthorised emails outright. This scrutiny comes as the government introduces the Secure Government Email Framework, which will require all public sector domains to enforce DMARC at the p=reject setting by October 2025. The requirement targets government domains, but the implications reach across public and private sectors. Non-compliant vendors, councils, NGOs, and universities not only risk delivery failures for legitimate communications, but are also vulnerable to impersonation and phishing incidents. EasyDMARC's research found that just 24.5% of New Zealand domains have valid DMARC records. Of those, a significant 72.4% use the policy set to none, which only monitors for suspicious activity but does not take any blocking action. Only 3.1%, or 4,327 domains, enforce the p=reject setting, meaning the overwhelming majority of domains are not proactively preventing phishing attacks. The findings underscore concerns around email-based cyberattacks in the country. Phishing accounts for more than 90% of all cyberattacks globally, giving urgency to calls for more comprehensive enforcement of DMARC policies. Gerasim Hovhannisyan, CEO of EasyDMARC, stated: "Most organisations set up DMARC but don't enforce it. By mandating DMARC at its strictest level, p=reject, New Zealand is leading by example, showing that email security only works when enforcement is taken seriously. Too many organisations stop at 'p=none', the weakest DMARC setting, which merely monitors for fraudulent emails without taking action. This creates a false sense of security while leaving the door wide open to phishing attacks. Our research shows that only 9.5% of the top global 1.8 million domains have reached p=reject – the only DMARC policy that actively blocks spoofed emails. This gap between adoption and proper enforcement is exactly why email remains the most common attack vector. Today's phishing attacks aren't the clumsy scams we used to see. Thanks to AI, they're now flawless, highly targeted messages that look and feel legitimate. We can't expect employees to spot them in a flood of emails, and relying on outdated filters or passive monitoring just isn't enough. Organisations need a system that blocks unauthorised senders before their message even hits the inbox. By enforcing p=reject, New Zealand has built exactly that system for its public sector. Email is still how governments issue updates, how companies close deals, and how people reset passwords. If we can't trust what's in our inboxes, the whole system falters. New Zealand's new email security mandate sets a clear benchmark, and it puts pressure on others to stop pretending that partial implementation is progress." The Secure Government Email Framework's upcoming mandate intends to standardise security practice across government entities, but the new research suggests most domains - both public and private - are not yet in line with these requirements. EasyDMARC's data shows significant room for improvement if organisations are to protect email communications and comply with incoming regulations. With New Zealand's digital economy expanding rapidly, the research points to a gap between policy and practice regarding email security, highlighting ongoing challenges for organisations seeking to protect users and data from phishing attacks. Follow us on: Share on:

Most high-traffic email domains still vulnerable to phishing
Most high-traffic email domains still vulnerable to phishing

Techday NZ

time30-05-2025

  • Business
  • Techday NZ

Most high-traffic email domains still vulnerable to phishing

New research from EasyDMARC has found that 92% of the world's top 1.8 million email domains lack adequate protection against phishing attacks. The EasyDMARC 2025 DMARC Adoption Report has revealed that only 7.7% of these domains are fully protected using the strictest DMARC (Domain-based Message Authentication, Reporting, and Conformance) policy, known as 'p=reject'. This policy is designed to actively block malicious emails from being delivered to inboxes. DMARC is an email authentication protocol that builds on existing standards such as SPF and DKIM, allowing domain owners to specify how they want mail servers to handle emails that fail authentication checks. The protocol also enables domain owners to receive reports on emails sent under their domain name, providing vital records of authentication attempts and potential abuse. EasyDMARC's analysis demonstrates that although there has been a noticeable increase in DMARC adoption since 2023 — largely due to regulatory initiatives and mandates from major providers including Google, Yahoo, and Microsoft — most organisations opt for the weakest available configuration, 'p=none'. This setting only monitors for threats, rather than thwarting attacks by blocking illegitimate emails. The report, which reviewed security practices across the most-visited websites globally as well as Fortune 500 and Inc. 5000 companies, shows a continued gap between DMARC adoption and meaningful implementation. More than half (52.2%) of the surveyed domains have not implemented DMARC at any level, leaving them exposed to phishing and spoofing risks. Among domains that do have a DMARC record, most have not configured enforcement policies or reporting mechanisms necessary for full protection. The research also found that over 40% of the domains with a DMARC record did not include any reporting tags. This omission means these organisations have little to no visibility into authentication failures or an understanding of who might be sending emails on their behalf. Gerasim Hovhannisyan, Chief Executive Officer of EasyDMARC, addressed the misconception surrounding DMARC adoption: "There's a growing perception that simply publishing a DMARC record is enough. But adoption without enforcement creates a dangerous illusion of security. In reality, most organisations are leaving the door wide open to attacks targeting customers, partners, or even employees." Mandates have had a measurable effect. In the United States, where regulatory enforcement is strong, the proportion of phishing emails accepted dropped from 68.8% in 2023 to just 14.2% in 2025. Similar progress was noted in the UK and the Czech Republic, countries that also enforce DMARC usage. However, countries without strict requirements, such as the Netherlands and Qatar, showed minimal improvement in reducing phishing acceptance rates. Recent high-profile cyber attacks, including those targeting retailers such as M&S and Co-op, serve as a backdrop for the report's release. In these incidents, attackers exploited weaknesses in email security through social engineering, costing affected businesses hundreds of thousands in losses. According to EasyDMARC, the increasing sophistication of phishing, partly driven by the use of AI, magnifies the risks for organisations that are inadequately protected. Hovhannisyan further commented: "Misconfigurations, missing reporting, and passive DMARC policies are like installing a security system without ever turning it on. Phishing remains one of the oldest and most effective forms of cyberattack, and without proper enforcement, organisations are effectively handing attackers the keys to their business. As threats grow more sophisticated and compliance pressures mount, stopping halfway with DMARC enforcement is no longer an option." The report methodology combined public DNS data with proprietary data collected through EasyDMARC's platform. It involved the review of aggregate DMARC reports from major mailbox providers and included a survey of 980 IT professionals across the United States, United Kingdom, Canada, and the Netherlands. This allowed for insights into regional differences in phishing trends, adoption challenges, and the varying influence of regulatory mandates. The research concludes that while DMARC adoption has increased, genuine protection against phishing relies on both enforcement and visibility — elements still missing for the vast majority of high-traffic domains worldwide.

HiCamp Partners Joins EasyDMARC's MSP Program to Enhance Email Security and Deliverability for Clients
HiCamp Partners Joins EasyDMARC's MSP Program to Enhance Email Security and Deliverability for Clients

Associated Press

time11-04-2025

  • Business
  • Associated Press

HiCamp Partners Joins EasyDMARC's MSP Program to Enhance Email Security and Deliverability for Clients

DOVER, DE, UNITED STATES, April 11, 2025 / / -- EasyDMARC, a vendor of the cloud-native email security and deliverability platform, announced today a strategic partnership with HiCamp Partners, a leading email marketing agency, based in New York, USA. This partnership will help HiCamp Partners protect their clients' email domains from being used for phishing and other fraudulent activities, as well as improve their email deliverability rate. Email security has become a significant concern for businesses of all sizes as cyberattacks, such as phishing and spoofing, are becoming increasingly sophisticated. Verizon DBIR mentions that 93% of all successful cyberattacks begin with a phishing email. In light of this, HiCamp Partners has taken a proactive approach to help its clients secure their email domains and protect their sensitive information. 'At HiCamp Partners, ensuring flawless email deliverability is a top priority for our clients. EasyDMARC has been instrumental in streamlining authentication protocol setup and optimization, helping us fix DNS misalignments that could otherwise block crucial emails. Their platform makes what can be a complex process significantly more manageable, allowing us to focus on driving results for eCommerce brands., ' said Nolan Butler, Co-Founder at HiCamp Partners. 'We are thrilled to welcome HiCamp Partners to our growing partner network. Their commitment to delivering exceptional IT services and support to their clients aligns perfectly with our mission to make email safer for everyone,' said Gerasim Hovhannisyan, CEO of EasyDMARC. The DMARC standard enables the automatic flagging and removal of receiving emails that are impersonating senders' domains. It is a crucial way to prevent outbound phishing and spoofing attempts. About HiCamp Partners HiCamp Partners is a lifecycle marketing agency specializing in email and SMS for eCommerce brands. The company focuses on optimizing deliverability, crafting high-converting campaigns, and building retention strategies that drive long-term revenue. About EasyDMARC EasyDMARC is a cloud-native B2B SaaS to solve email security and deliverability problems in just a few clicks. With advanced tools, such as its AI-powered DMARC Report Analyser, DMARC, SPF, DKIM cloud management solutions, and email source reputation monitoring, EasyDMARC's platform helps customers stay safe and maintain the health of their domains without risk. Anush Yolyan EasyDMARC Inc. +1 8885635277 Legal Disclaimer:

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store