The most viable way to protect against fraudulent emails is the validation system, Domain-based Message Authentication, Reporting & Conformance (DMARC), which detects and prevents against unsolicited emails.
Most organisations use Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) to authenticate email, but DMARC is an additional system and is more effective. DMARC verifies whether an email is from the domain it claims and provides a report on the messages which are rejected and why.
In recent years, the UK’s National Cyber Security Centre has increased its recommendation of the importance of using DMARC – the Active Cyber Defense programme advocates that the UK government and public sector should use DMARC. Following this, the US Department of Homeland Security and large companies such as Google and Microsoft have also started utilising DMARC as protection.
DMARC works by checking for the authentication instructions for a given domain. If an email is deemed legitimate it is delivered as normal, and if not the recipient is sent a notification and chooses to monitor, quarantine or reject the message. As DMARC authenticates legitimate emails rather than tries to guess at blocking fraudulent emails, it is more likely that genuine messages will be delivered.
There are clear reasons to use DMARC, such as returning trust in email communication and potential higher ROI due to deliverability. The efficiency has also been proven; a strong example is when HM Revenue & Customs (HMRC) implemented DMARC onto their domain and reduced spoofed emails by half a billion! The implementation also improved delivery rates of genuine emails from 18% to 98%.
Fraudulent emails are extremely common and, because of this, email communication is becoming untrusted. There is huge value in taking effective precautions to protect against fraud. DMARC has been proven to be beneficial to implement and, once set, will protect your domain against spoofing and protect you from receiving illegitimate emails (which could otherwise lead to a leak of confidential data). Contact us on how to implement DMARC.
