• Latin American Email Security: State of DMARC & Email Authentication in LATAM 2026

Latin American Email Security: State of DMARC & Email Authentication in LATAM 2026

by

Last Updated:
8 min read
Latin American Email Security: State of DMARC & Email Authentication in LATAM 2026

Key Takeaways

  • PowerDMARC analyzed email authentication across five major LATAM markets in 2026 (Brazil, Mexico, Argentina, Ecuador, and Peru) and found a critical gap between foundational setup and actual enforcement.
  • Research shows SPF setup is quite high (86%–96%), but true DMARC enforcement (p=reject) peaks at just 24.9%.
  • Secure transport encryption is virtually nonexistent across Latin America, which leaves roughly 99% of outbound business email exposed to interception.
  • The media vertical is consistently the worst-performing industry in every country, which leaves public communication channels wide open to domain spoofing.
  • Ecuador leads the entire region in DMARC enforcement due to its proactive financial sector, while Brazil heavily dominates regional DNS security.

In 2025, Latin America faced a 108% year-over-year surge in cyberattacks. Brazil currently stands as the #1 most targeted market in the region, closely followed by Mexico at #2. Today, organizations across the territory deal with an average of 2,640 weekly attacks.

To map out how well organizations are defending their domains, PowerDMARC analyzed email authentication adoption across five major markets in 2026 (Brazil, Mexico, Argentina, Ecuador, and Peru) and a standalone 2024 analysis of Chile. The results uncover a striking regional paradox: even though foundational technical setups are solid, actual security enforcement is dangerously lagging. Across every 2026 market analyzed, Sender Policy Framework (SPF) adoption is quite high (86% to 96%), yet Domain-based Message Authentication, Reporting, and Conformance (DMARC) enforcement rates (p=reject) sit between a low 16.2% in Mexico and 24.9% in Ecuador. In short, companies are proving who they are, but they fail to block attackers from impersonating them.

This comprehensive guide breaks down the core vulnerabilities across these markets. For full sector heatmaps and complete compliance roadmaps, download the full LATAM email security report 2026.

Explore-the-LATAM-Email-Security-Report-2026

Why Is Email Security in Latin America Under Sustained Attack?

The fast pace of digital transformation across Latin America, fueled by explosive fintech growth, expanding e-government platforms, and cloud adoption, has expanded the digital attack surface much faster than defensive controls have evolved. This gap has made email security in Latin America a top priority for security leaders.

Three structural vulnerabilities are shared across PowerDMARC’s analyzed markets:

  • Organizations successfully configure foundational records but fail to implement strict DMARC policies. They identify themselves but leave the door open for brand impersonation.
  • Mail Transfer Agent Strict Transport Security (MTA-STS) is almost nonexistent across the entire region.
  • Inconsistent compliance systems means enforcement is uneven across borders and industries.

Argentina has seen a +44% phishing surge year-over-year according to Kaspersky data, while 43% of cyberattacks against Mexican organizations successfully breach their perimeters.

Email Security in Latin America: 5-Country Benchmark (2026 Data)

The following benchmark shows the state of email security in Latin America across the five countries analyzed in our 2026 cohort. This table excludes Chile, which is evaluated separately because of its historical 2024 dataset and alternative testing methodology.

CountrySPF CorrectDMARC p=rejectMTA-STSDNSSECLATAM Rank (p=reject)
Ecuador96.1%24.9%1.4%4.8%#1: LATAM Leader
Brazil92.1%20.7%0.7%21.9%#2: DNSSEC Leader
Peru86.1%17.9%0.6%4.6%#3: Lowest SPF
Argentina95.2%18.5%1.2%1.8%#4: Lowest DNSSEC
Mexico96.2%16.2%0.4%9.9%#5: Lowest Enforcement

DMARC-p=reject-enforcement-by-country-(2026)

Key Findings: Country by Country (2026 Data)

Brazil: DNSSEC Leader, Media Crisis

Brazil is Latin America’s most targeted market, yet only 20.7% of its organizations enforce a strict DMARC p=reject policy. On the bright side, its 21.9% Domain Name System Security Extensions (DNSSEC) adoption leads the region and beats global markets like Poland (15.7%) and Japan (16.4%). However, its 0.7% MTA-STS rate means practically all email traffic remains vulnerable to transport interception.

  • Finance: Leads the country with 39.2% p=reject enforcement, but faces a 100% MTA-STS coverage gap across the banking sector.
  • Government: Reaches an impressive 57.3% DNSSEC adoption (the highest of any sector in this study), but 53.7% of domains remain at a softer p=quarantine policy instead of blocking threats completely.
  • Media: A huge 41.8% of media domains have no DMARC record at all, and a tiny 6.4% enforce p=reject.

Read the deeper analysis in the Brazil DMARC Adoption Report 2026.

Mexico: Highest SPF, Lowest Enforcement

Mexico shows a big contrast in its email security in Latin America standing: it boasts the highest SPF configuration accuracy in the region at 96.2%, but sinks to the bottom for DMARC enforcement at just 16.2% p=reject. As many as 34.9% of analyzed domains are stuck in monitoring mode (p=none).

  • High Threat Level: This sluggish enforcement persists despite a 74% ransomware hit rate across a peak 12-month cycle and a 43% perimeter breach success rate.
  • Finance: Outpaces other local sectors at 29.1% p=reject, but still suffers from a 99% MTA-STS deficit.
  • Commercial Exposure: The Transport sector sits at 9.5% p=reject (with 28.6% lacking DMARC), while Media drops to 5.2% p=reject and 31.1% entirely unprotected.

Read the full Mexico DMARC Adoption Report 2026.

Argentina: World-Class SPF, Critical Enforcement Gap

Argentina’s 95.2% accurate SPF adoption matches the United States and beats Australia, so the foundation is there. However, true domain protection falls off a cliff with only 18.5% enforcing p=reject. A combined 56.9% of Argentine domains remain entirely exposed to spoofing attacks (35.9% at p=none and 21.0% lacking a DMARC record).

  • Healthcare: 52.2% of healthcare domains sit at p=none, the highest monitoring-only exposure of any single sector in the 2026 cohort, compounded by 0% MTA-STS.
  • DNSSEC Deficit: Argentina features the region’s lowest national DNSSEC rate at 1.8%, with Government and Education dropping to an absolute 0%.
  • Public Sector Targets: CERT.ar logged 438 major incidents in 2024; 61% explicitly target government infrastructure.

Read the deeper analysis in the full Argentina DMARC Adoption Report 2026.

Ecuador: LATAM’s Enforcement Leader

Ecuador takes the crown as the regional DMARC leader with a national enforcement rate of 24.9% p=reject.

  • Finance: Ecuador’s financial sector hits 43.7% p=reject compliance, which makes it the highest single-sector enforcement metric recorded across all countries analyzed.
  • The Sector Split: Healthcare displays a total inverse reality at a tiny 4.4% p=reject; what’s more, 47.8% completely lack DMARC records, and 0% adoption for both MTA-STS and DNSSEC.
  • Threat Urgency: Advanced threat vectors like the Blind Eagle APT group actively leverage tailored localized campaigns here, while regional generative AI phishing lures have driven a 60% increase in recipient click rates.

Read the deeper analysis in the full Ecuador DMARC Adoption Report 2026.

Peru: Lowest Foundational Adoption

Peru has the lowest SPF adoption rate in the region at 86.1%, 10 percentage points behind Mexico and Ecuador.

  • Layered Risks: While its national DMARC enforcement rate of 17.9% p=reject technically beats Mexico, the underlying errors and gaps at the SPF level mean Peru’s overall infrastructure is highly vulnerable.
  • Encryption Gaps: Encryption and integrity standards match the broader regional flatline; MTA-STS is sitting at 0.6%, and DNSSEC is stalling at 4.6%.

Read the deeper analysis in the full Peru DMARC Adoption Report 2026.

Download the complete LATAM Email Security Report 2026 for all five 2026 country breakdowns.

Chile Spotlight: 2024 Historical Data

  • Important Methodology Note: PowerDMARC’s analysis of Chile reflects data captured in February 2024 across 1,004 domains. This data does not include modern MTA-STS or DNSSEC breakdowns and cannot be directly compared to the 2026 benchmarks.

As of February 2024, Chile lagged behind its regional peers significantly. 63.8% of Chilean domains had no DMARC record whatsoever, and only 9.9% enforced a strict p=reject policy, the lowest enforcement baseline analyzed in Latin America. Its SPF adoption sat at 70%.

  • The Energy sector performed the worst, with 77.4% of domains completely unprotected by DMARC. Media followed closely with a 74.6% total gap.
  • Over half (51.0%) of Chilean banking domains lacked DMARC protections entirely, despite being prime financial targets.
  • Note that this dataset predates Chile’s major regulatory updates. Ley 21.663 (the Cybersecurity Framework Law) came into full force in March 2025, introducing the National Cybersecurity Agency (ANCI), the first dedicated national cybersecurity agency in Latin America. Under this framework, Operators of Vital Importance (OIVs) are legally required to report incidents to CSIRT Nacional within 3 hours. Due to these strict compliance pressures, Chile’s actual 2026 security environment likely shows significant progress.

See PowerDMARC’s Chile DMARC page.

Cross-Country Comparison: Four Key Regional Patterns

The broader landscape of email security in Latin America reveals four undeniable trends that security leaders must address as soon as possible.

1. The SPF-Enforcement Paradox

Organizations are treating email authentication like a one-and-done setup task rather than a strategic protection model. While accurate SPF configuration ranges from 86% to 96% across the 2026 cohort, the top DMARC enforcement rate is Ecuador’s 24.9%, nearly half of international baselines like Australia’s 46.7%.

2. MTA-STS is an Absolute Blind Spot

Secure transport encryption is critically lagging across the continent. The 2026 data shows single-digit adoption everywhere: Ecuador leads at 1.4%, followed by Argentina (1.2%), Brazil (0.7%), Peru (0.6%), and Mexico (0.4%). ~99% of outbound business email in Latin America travels without enforced transport security, so successful man-in-the-middle (MitM) and SMTP downgrade attacks shouldn’t surprise.

3. Media is the Most Vulnerable Sector Across the Board

Across every single market studied, the Media and Entertainment vertical is the weakest link in the region.

CountryMedia DMARC p=rejectMedia No DMARC Record
🇦🇷 Argentina2.7%35.8%
🇲🇽 Mexico5.2%31.1%
🇧🇷 Brazil6.4%41.8%
🇪🇨 Ecuador6.5%46.8%
🇨🇱 Chile (2024)N/A74.6%

Media-sector--domains-with-no-DMARC-record

Latin American media channels remain highly exposed to domain spoofing.

4. DNSSEC Highlights Brazil as an Outlier

Aside from Brazil’s regional-leading 21.9% DNSSEC adoption (powered heavily by its 57.3% adoption rate in the Government sector), Latin America’s DNS core remains largely unprotected. Argentina’s 1.8% national DNSSEC rate, paired with an absolute 0% across both Government and Education, leaves its digital services exposed to DNS cache poisoning.

  • Chile: Led by Ley 21.663 (March 2025), ANCI wields substantial enforcement authority over critical national infrastructure, backed by strict 3-hour incident notification rules. Ley 21.719 (LPPD data protection) becomes fully effective in December 2026.
  • Brazil: The National Data Protection Authority (ANPD) enforces LGPD aggressively. Because email serves as a primary data transmission line, any data breach stemming from domain spoofing triggers heavy compliance liabilities. The Central Bank of Brazil (BACEN) adds parallel pressure on financial groups.
  • Mexico & Argentina: Mexico leverages NOM-151 alongside INAI oversight, while Argentina uses Ley 25.326 via AAIP enforcement. While neither country has a direct national mandate specifically for email authentication, their frameworks increasingly treat unauthenticated email as an unacceptable corporate liability.
  • Ecuador & Peru: Ecuador enforces the LOPDP through its data protection authority, the SPDP, while Peru applies Ley 29733 through the ANPDP, with the SBS adding oversight for the banking sector. Neither country mandates email authentication outright yet, but both treat unauthenticated email as a data protection risk.
  • Global Mandates: Beyond local laws, global inbox provider requirements from Google, Yahoo, and Microsoft apply to any company sending high-volume international emails.

What Should Organizations in Latin America Do Now?

Here is what you can do now:

  1. Immediately verify the active deployment status of your DMARC, SPF, and DomainKeys Identified Mail (DKIM) protocols using an automated tool like our DMARC Record Checker.
  2. Enforce strict DMARC policies. Over a third of domains in Mexico (34.9%) and Argentina (35.9%) remain stuck at p=none. Move systematically from monitoring (p=none) to temporary quarantine (p=quarantine); your ultimate goal should be full p=reject enforcement.
  3. Implement MTA-STS alongside Transport Layer Security (TLS) Reporting to eliminate the near-zero adoption vulnerability that leaves regional email data exposed to downgrade attacks.
  4. If you manage infrastructure or vendor relationships within the Healthcare or Media sectors, implement immediate mitigation controls. These industries consistently display the highest risk factors in every country.
  5. Deploy cloud-based analytics via our DMARC Analyzer to monitor global sending sources, track alignment metrics, and quickly surface spoofing attempts.

Get the Complete 16-Page Security Report

Don’t let your corporate domain remain an open target for phishing actors. Download the complete LATAM Email Security Report 2026: DMARC & Email Authentication Across 6 Countries.

Frequently Asked Questions

Why is email security in Latin America under sustained attack?

The region’s rapid digital transformation, including explosive fintech growth, e-government expansion, and rapid cloud adoption, has expanded the corporate digital attack surface much faster than email security controls have evolved. This has resulted in a 108% surge in regional cyberattacks over the last year.

What is the primary issue highlighted in the 2026 LATAM email security report?

The main problem is a severe gap between the basic configuration and active security enforcement. The majority leave their DMARC policies at p=none or lack DMARC completely.

Why is the 2024 Chile data separated from the rest of the 2026 benchmark data?

The Chile dataset was captured in February 2024 using a different methodology that did not track MTA-STS or DNSSEC data. Because it represents an older security posture that predates the full enforcement of major local regulations like Chile’s Cybersecurity Framework Law (Ley 21.663), it cannot be accurately benchmarked against the 2026 data.

Which industrial sectors face the highest risk of domain impersonation?

The Media and Healthcare sectors consistently perform the worst across Latin America. Media organizations frequently display the highest rates of missing DMARC protection, while Argentina’s healthcare vertical represents a severe regional flashpoint with 52.2% of its domains stuck unprotected at a p=none policy.

What are the immediate steps a LATAM organization should take to secure its domain?

Organizations should first run an external audit using a DMARC Record Checker. From there, they must actively advance their DMARC policy from monitoring (p=none) to enforcement (p=reject), implement MTA-STS to safeguard email transport encryption, and continually monitor with a DMARC Analyzer.

email security Latin America