Date of analysis: 24/07/2024
DMARC & MTA-STS Adoption in Malaysia: 2024 Report
2024 can be considered the year of email security revolution! Earlier this year, Google and Yahoo successfully rolled out their updated email authentication sender requirements making authentication mandatory for all senders. But the question remains, what pushed them to take such a drastic (yet necessary) step?
With the introduction of AI, email-based attacks including phishing, spoofing, ransomware, and BEC are now more common than ever before. According to this article by Harvard Business Review, research conducted in 2024 showed that 60% of participants fell victim to artificial intelligence (AI)-automated phishing emails. The article further explains how AI has reduced the cost associated with launching such cyber attacks by 95% while increasing their success rates.
DMARC (Domain-based Message Authentication, Reporting and Conformance)
DMARC is an email authentication security protocol that empowers domain owners to safeguard their domains from misuse, such as unauthorized usage, spoofing, and phishing attempts. By configuring your DMARC policy, you can reject emails that are not authorized and enable reporting to monitor email channels, identify sending sources, and review authentication outcomes.
MTA-STS (Mail Transfer Agent Strict Transport Security)
MTA-STS is an email authentication protocol offering protection on the receiving end this time. It is designed to enhance the security of email communications by mandating the use of Transport Layer Security (TLS) during email transmission. This protocol helps protect email traffic from being intercepted through passive eavesdropping and prevents active man-in-the-middle attacks.