The Global Cyber Alliance and DMARC Manager have published a report on “Strengthening Trust on the Internet: Protecting the Postal Sector from Email Fraud.” It highlights gaps in email security, specifically DMARC, within the postal sector and provides practical recommendations to keep their domains — and their customers — safer.
We rely on postal operators to deliver packages, process payments, and communicate important updates, with interactions happening increasingly online. That makes the Internet infrastructure behind them, including the systems that authenticate email, as important to secure as the physical networks that move mail and packages around the world.
Postal operators are prime targets for phishing precisely because their brands are trusted. Customers expect emails about deliveries, failed delivery attempts, customs fees, and invoices, so a message that looks like it comes from a trusted postal brand can be enough to convince someone to click a malicious link or hand over sensitive information.
DMARC (Domain-based Message Authentication, Reporting and Conformance) is the mechanism domain owners should use to protect their domains from email spoofing and impersonation. It is a free, open email authentication protocol implemented through a DNS record on the domain. Once enabled, DMARC provides visibility into who is sending email on behalf of a domain, helping domain owners identify legitimate senders as well as unauthorized or potentially malicious activity.
DMARC also gives domain owners control over how receiving mail systems should handle messages that fail authentication through three policy levels.
- A policy of p=none provides visibility without asking receiving systems to act, making it the starting point for identifying and resolving authentication issues.
- p=quarantine asks receiving systems to treat messages that fail DMARC as suspicious, typically directing them to a spam or quarantine folder.
- p=reject provides the strongest level of protection by instructing receiving systems to reject messages that fail DMARC, preventing them from being delivered to the recipient’s inbox.
A recent benchmark study conducted by DMARC Manager assessed DMARC adoption across all 191 Designated Postal Operators worldwide. The headline finding: 81% are not fully protected against email spoofing. Only 37 operators, 19% of the sector, have reached p=reject, the only policy level that actually stops forged mail from being delivered.
This report walks through that benchmark, the threat landscape driving it, and a practical path any operator can follow toward full enforcement. DMARC Manager’s sector-wide scan pairs naturally with GCA’s work on DMARC and domain security through Domain Trust and its Cybersecurity Toolkits.
Key Findings At a Glance
| 81% | 19% | #2 |
| of postal operators are not protected 154 of 191 operators worldwide | have reached full DMARC enforcement 37 of 191 at p=reject | most impersonated sector 22+% of global brand phishing |
