OnDMARC Success Stories

We can all agree that January might be one of the most painful months of the year – the festive celebrations are over and, certainly for us in the UK, we’re stuck in an endless cycle of fog and rain with spring seeming an age away.

So to combat our blues, we thought we would be a little self-indulgent and look back at what has been a great 12 months for our OnDMARC product and our customers, highlighting some strong business results following DMARC deployment.

Numed Healthcare

Putting Cybersecurity at the top of the waiting list

Background

Medical distributor, Numed, provides innovative diagnostic and waiting room equipment to the NHS. Serving the medical backbone of the UK requires Numed to guarantee compliance with the UK Government’s Minimum Cyber Security Standards Framework, uphold its brand reputation as a safe supplier to the NHS, and attain exceptional levels of email deliverability. 

Organization challenge

Numed was aware of how susceptible it was to email impersonation given its close relationship to the NHS so we wanted to ensure it was protected against an inevitable attack leading to sophisticated phishing campaigns.

Technology solution

“We were very clear in what we were looking for in a DMARC partner: we needed a cost-efficient solution that didn’t skimp on usability or effectiveness.” Numed was looking for a product that could translate the complex DMARC reports and configuration issues into clear and concise graphs and actions, whilst avoiding onerous and expensive support contracts.

Organization results

By partnering with Red Sift, Numed reached full protection on its main email domains in just two weeks and near-doubled its email deliverability from 50% to 98-100% with OnDMARC.

“OnDMARC made the process simple and accessible, and uncovered vulnerabilities we could have never found by implementing DMARC on our own.”

Nick Kenyon, Head of Operations at Numed.

Greenhill

Financially-driven email content makes tasty phish bait

Background

Greenhill, a leading independent investment bank, provides financial advisory services. The firm operates globally with 15 offices and over 400 employees, sending over seven million emails a year. Email deliverability is vital, as well as maintaining high standards of brand reputation.

Organization challenge

Operating in the financial world means Greenhill deals with highly confidential and sensitive data and cannot risk having emails being spoofed and risking clients and partners experiencing breaches. Following a third-party review, Greenhill was alerted to a DMARC failing and left to implement the protocol without internal expertise.

Technology solution

After evaluating multiple vendors Greenhill found “OnDMARC was reasonably priced and very easy to use”, and able to tackle three key areas – visibility of email sources, expertise of configuration of protocols, and ongoing protection.

Organization results

Once OnDMARC was in place, Greenhill uncovered 2,734 unauthorized email sources sending 671,000 fake emails from a parked domain; in the first 90 days, a million spoof emails were blocked; its SPF pass rate increased from 79.7% to 100%, specifically due to OnDMARC’s Dynamic SPF feature.

Thanks to John Shaffer, Chief Information Officer at Greenhill.

Campos Mello Advogados

Laying down the law about email security

Background

Campos Mello Advogados works in cooperation with prominent global law firm, DLA Piper, offering legal solutions to global clients. As company partners, the two firms share IT infrastructure and generate at least 40,000 outbound emails a week to clients, partners, and suppliers – deliverability and secure communications are vital business practices.

Organization challenge

“We needed a DMARC tool to understand the fake email activity outside of our environment.” The firm was aware of DMARC’s ability to block email impersonation outside of the domain owner’s network boundary.

Technology solution

Brazil’s new data protection law, LGPD, brings in new compliance regulations from August 2020 so getting a tool that can stamp out domain impersonation as well as check a supplier’s email protection to protect CMA and its client’s personal data, was a bonus.

Organization results

“I was really impressed with how easy OnDMARC was to use”. Within a week, CMA fast-tracked its DMARC status from reporting to quarantine; in a month, 5,677 unauthorized emails were identified and placed in junk; within six months of diverting spoof emails, there was a 34% reduction in impersonation attempts.

Thanks to Ruy Fernando Calixto, IT Manager at CMA.

U.S. Government Agency

Reforming email security with modern security protocols

Background

This organization runs a US state’s official website providing public information and updates about services. Sending over two million emails a month to the public about government services means it’s essential that communications are secured to protect both sides.

Organization challenge

DMARC protection has become mandatory for US government agencies so this client needed to quickly evaluate a solution that could correctly implement DMARC, SPF, and DKIM.

Technology solution

“We tried DMARC Analyzer which lacked some information we felt should have been provided for effective insight, and Fraudmarc were ridiculously expensive. After comparing other providers, the general layout and simplicity of OnDMARC’s reports proved to be leaps and bounds better than most of what was out there.”

Organization results

In one month, 9,641 emails were sent from 104 email services and the 23% that were fake were blocked by OnDMARC; in under two months, 150 domains in reject; within 90 days 77,000+ emails were sent with a 100% delivery rate.

Try it out yourself

These quotes and figures are just a snapshot of how OnDMARC has helped a multitude of clients in many different sectors. With discounts for charities and sole traders and a free 14-day trial, make sure you sign up to secure your email domain!

PUBLISHED BY

Red Sift

28 Jan. 2020

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
Certificates

New in Certificates Lite: Active certificate scanning and smarter expiry alerts

Francesca Rünger-Field

A quick recap Earlier this year, we launched Red Sift Certificates Lite, the free TLS certificate expiration monitoring service recommended by Let’s Encrypt. Since launch, thousands of organizations have adopted it to track their certificates and avoid expiry-related outages. What we heard from customers At launch, we had adopted Let’s Encrypt’s approach for consistency…

Read more
AI

Red Sift’s AI Agent, Part II: Optimization for accuracy and scale

Phong Nguyen

In our previous blog post, we introduced Red Sift’s AI Agent for lookalike classification – an intelligent system that determines whether a suspicious domain has been deliberately crafted to mimic a legitimate one or if the resemblance is merely coincidental. That post focused on the what and why of the solution: why rule-based automation…

Read more
Brand Protection

Separating signal from noise when fighting brand spoofing

Rahul Powar

“Alert fatigue” must be the most common malady among cybersecurity professionals. According to a recent survey, 56% of large companies handle 1,000+ alerts each day. For 70% of security professionals, the volume of alerts has doubled in the past few years, with more than 51% of campaigns involving some form of AI-generated brand spoofing.…

Read more
Research

49% of Big Pharma companies are vulnerable to email phishing as weaponized…

Rahul Powar

New analysis from Red Sift of the 100 largest pharma companies shows nearly half of the sector is still open to domain spoofing. Only 51% of companies are at DMARC enforcement (p=reject)—the control that stops spoofed email at the door. Another 13% sit at p=quarantine, which offers limited filtering but does not equal enforcement.…

Read more