These Countries Take Gold, Silver and Bronze In Email Authentication 

Given the world is currently competing for gold, silver and bronze, Red Sift has taken a similar approach to see how certain countries compete when it comes to levels of email authentication. 

The Competition 

This year’s Summer Games have cybersecurity teams across the world on high alert, as threat actors leverage phishing, hacktivism, malware and exploitation to wreak havoc. While cyber defenders prepare for a wide variety of attacks, two strategic plays exist to fortify their cyber resilience strategies: DMARC and BIMI. 

“The 2024 Summer Games in Paris presents prime opportunities for the gamut of threat actors seeking profit, fame, or national advantage. Competing teams as well as cyber defenders must understand the pressing threats to maintain resilience during the games. Defenders need to be prepared for a wide range of attacks, from low-level scams and DDoS attacks to doxxing against athletes and ransomware targeting critical infrastructure. It’s the Summer Games of cyber defense,” says Sean Costigan PhD, Managing Director of Resilience Strategy, Red Sift.

The Warmup 

DMARC stands for Domain-based Message Authentication, Reporting & Conformance. It’s an outbound email security protocol that allows domain owners to take back control of their email identity by telling receiving inboxes to reject spoofed emails.

DMARC allows domain owners to obtain visibility to email services that are sending on their behalf, and to block unauthorized senders. DMARC stops impersonation, by telling recipient servers not to accept any emails which aren’t authenticated to have come from you. So, bad actors cannot use your domain to send phishing emails and carry out Business Email Compromise (BEC).

BIMI (Brand Indicators for Message Identification) was introduced in 2021 and allows businesses to show their brand logo in the avatar slot of emails they send. BIMI can only be implemented and honored for organizations that have a DMARC enforcement policy of quarantine or reject at the root level and for all subdomains.

To completely take advantage of the benefits of BIMI logo display in email clients, companies must obtain a Verified Mark Certificate (VMC) from an approved certificate authority such as Entrust for their primary/corporate domain. This is the last mile, so to speak, and rewarded gold amongst the judges. 

The Games

For our purposes, the competing teams will be large public companies by country, as measured by the Fortune 500, (i.e. large public companies in France), and the events will be varying levels of email authentication – DMARC Reporting, BIMI Ready, and BIMI with VMC.  

  • DMARC Reporting:  These domains have started their DMARC implementation but have not yet progressed to a policy that is secure enough to qualify for BIMI.
  • BIMI Ready:  These domains have the DMARC policy required to deploy BIMI
  • BIMI with VMC: These market leaders have completed all the steps above and have obtained a Verified Mark Certificate for their registered trademarks.

Using proprietary data from Red Sift’s BIMI Radar, based on an analysis of 2,380 domains, Red Sift has unveiled the readiness of countries globally to see who is best prepared to combat the cyber threats carried out at the Summer Games. 

DMARC Reporting 🥉

  • Gold – Japan 50%
  • Silver – Italy 46.15%
  • Bronze – Turkey 39.18%

BIMI Ready 🥈

  • Gold – Netherlands 64.36%
  • Silver – UK 62.5% 
  • Bronze – Australia 59.8% 

BIMI with VMC 🥇

  • Gold – US 11.96%
  • Silver –  India 10.47%
  • Bronze – Canada 6.19%

*Red Sift is not affiliated, associated, authorized, endorsed by or in any way officially connected to the 2024 Summer Games.

PUBLISHED BY

Francesca Rünger-Field

7 Aug. 2024

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
DMARC

400,000 DMARC boost after Microsoft’s high-volume sender update

Jack Lilley

Microsoft’s decision to join Google and Yahoo in enforcing stricter rules for high-volume senders has triggered an immediate response across the internet. In the last 30 days alone, 406,042 new domains have deployed Domain‑based Message Authentication, Reporting & Conformance (DMARC), pushing the global total to 10.9 million. While not all domains will be exclusive Outlook users,…

Read more
DMARC

Red Sift partners with Gradian to strengthen email security through OnDMARC

Jack Lilley

Today Red Sift launches a new partnership with Gradian, a leading data protection provider, to offer its award-winning applications, including Red Sift OnDMARC, to new and existing customers. Established through Red Sift’s relationship with UK distributor E92plus, the two companies look to strengthen defences against phishing and Business Email Compromise (BEC) attacks. Allowing organisations…

Read more
Cybersecurity

DMARCbis: What are the changes and how to be ready

Jack Lilley

Executive Summary: DMARCbis, also known as DMARC 2.0, is the forthcoming update to the DMARC email authentication protocol, designed to address limitations and ambiguities in the original standard, with an expectation to be finalized and published in 2025. The update introduces clearer guidelines, a new method for determining organizational domains, and streamlined record management.…

Read more
Certificates

TLS certificates are changing: What you need to know

Jack Lilley

Executive summary: TLS certificates are about to get significantly shorter-lived. Starting 15 March 2026, newly issued public-trust certificates will max out at 200 days—and just three years later, that lifespan drops to 47 days. Backed by Google, Apple, and Mozilla, this shift aims to make the web safer through fresher data, faster failover, and…

Read more