Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Email Security

Presidential Candidates’ Use of DMARC Improves, but Remains Short of Optimum

Presidential candidates’ protection of their domains is improving, but could improve further. More specifically, of the 15 current candidates, eight now protect their domains from email spoofing with enforced DMARC. In May 2019, when there were still 23 candidates, only three were protected by DMARC.

Presidential candidates’ protection of their domains is improving, but could improve further. More specifically, of the 15 current candidates, eight now protect their domains from email spoofing with enforced DMARC. In May 2019, when there were still 23 candidates, only three were protected by DMARC.

DMARC (Domain-based Message Authentication, Reporting, and Conformance) works with two other email standards (SPF, or Sender Policy Framework, and DKIM, or Domain Keys Identified Mail) to give domain owners control over which senders are allowed to send messages ‘as’ them. The effect is to specify which email servers can name the protected domain in the From field of their messages, thus preventing email spoofing.

Today, three domains have no DMARC (Bennet, Walsh and Wend), while four more have unenforced DMARC (Delaney, Patrick, Sanders and Trump). Although running DMARC in ‘unenforced’ mode is often an indication that DMARC is in process of implementation, for so long as it is unenforced, there is no protection. The authors of the survey, Valimail, note further that while Bloomberg has DMARC configured with an enforcement policy, a problem with the underlying SPF record (it exceeds the limit of 10 DNS lookups specified in the SPF standard) could cause problems with security, visibility and enforcement.

Almost all email servers now support DMARC. They check to see if the apparent source domain has DMARC configured, and if so, whether the sender is approved. If approved, the email is allowed. If not, the email server obeys one of the three DMARC policies: reject (ie, delete it), quarantine (send it to a spam or junk folder), or none (deliver it as normal).

Valimail highlights three potential email attacks on or spoofed from the candidates’ domains. Inbound hacking attempts could impersonate a senior member of the campaign to leverage trust in that person as part of a phishing attack. Outbound phishing attacks could be launched while spoofing the campaign domain to gain additional credibility. Such emails could be targeted against both large and small donors with the intention of redirecting donations to the hackers’ bank accounts.

The third attack could be politically motivated. “Rather than hacking attempts,” warns Valimail, “bad actors might try to impersonate the campaign with mass emails sent to U.S. citizens at large, delivering a message that the campaign would never assent to — thereby sowing confusion about the campaign’s true positions, or generating distrust in its platform altogether.”

Valimail believes that the improvements in the presidential candidates’ use of DMARC over the last nine months is promising; but that “election officials as well as the vendors of hardware and software used in elections are all still far too easy to impersonate. In short, email remains a weak link in election security. The first step in closing that gap is to implement DMARC authentication, just as the campaigns have done.”

Nevertheless, it concludes, “It’s a real sign of progress when more than half of the presidential campaigns have not only published DMARC records, but have configured them with effective enforcement policies.”

Advertisement. Scroll to continue reading.

Related: 2020 U.S. Presidential Candidates Vulnerable to Email Attacks 

Related: 2020 Presidential Candidate Campaign Websites Fail On User Privacy 

Related: DMARC Use is Growing, But Difficult to Configure Correctly and Completely 

Related: DMARC Fully Implemented on Two Thirds of U.S. Government Domains

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Cloud Security

Cloud security researcher warns that stolen Microsoft signing key was more powerful and not limited to Outlook.com and Exchange Online.

Compliance

Government agencies in the United States have made progress in the implementation of the DMARC standard in response to a Department of Homeland Security...

Email Security

Many Fortune 500, FTSE 100 and ASX 100 companies have failed to properly implement the DMARC standard, exposing their customers and partners to phishing...

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cybercrime

Enterprise users have been warned that cybercriminals may be trying to phish their credentials by luring them with fake emails that appear to be...

Cloud Security

Microsoft and Proofpoint are warning organizations that use cloud services about a recent consent phishing attack that abused Microsoft’s ‘verified publisher’ status.

Cloud Security

Proofpoint removes a formidable competitor from the crowded email security market and adds technology to address risk from misdirected emails.