DMARC Email Security & Monitoring in Financial Services Sector
The Cyber Security Threat to Financial Services Businesses
Businesses operating in the financial services sector are a prime target for cybercriminals. They will go where the money is, as they always have done. Some of the leading cyber attack methods used against financial services companies occur via email message. Examples of malicious emails include phishing attacks, email spoofing, email fraud attempts, BEC (business email compromise), and other types of fake emails.
Email is still an essential business communication tool. It follows from this that email security is a vital part of any broader cybersecurity strategy. However, the way developers initially designed email means that malicious third parties can spoof email addresses to mimic another organisation. This increases the risk to anyone receiving such a spoofed email falling victim to phishing attacks, malware deployments, and other cyber attacks based on tricking people into clicking links or disclosing data that they shouldn't. Such a successful attack against financial institutions can result in monetary loss or other financial and reputational damage due to GDPR enforcement and bad publicity.
What is DMARC?
DMARC (Domain Based Message Authentication, Reporting & Conformance) is an open industry standard. It allows email sending and receiving organisations mail servers to coordinate and check that the sender using a domain name is authentic. DMARC allows all email senders and receivers to verify that every email from a domain is really from whom the sender claims to be. It does this by augmenting DNS records with additional information that no one can spoof.
We won't go into the deep technical details of DMARC record checking here. But in summary, a DMARC policy works via a protocol called Sender Policy Framework (SPF) used to authenticate email senders, and the DKIM (DomainKeys Identified Mail) standard to sign emails digitally. These are then used between sending and recipient domains to verify the authenticity of incoming emails. See the Agari DMARC solution page for more details.
Any organisation and domain owner can adopt DMARC authentication to protect against email domain spoofing by cybercriminals. It is the only sure-fire way that email receivers can know that the emails they are receiving come from the organisation whose domain is in the sender's address. DMARC uses email authentication and associated authentication methods to ensure that only legitimate email is delivered. DMARC adoption is an effective way for organisations to filter out fraudulent emails and reduce sender fraud from unauthenticated emails.
How does DMARC Protect Financial Services Organisations?
Many global businesses have seen the benefits that flow from implementing DMARC. Household names such as Netflix, Apple, DHL, Facebook, Citi, Twitter, UPS, and many others have implemented DMARC, which now protects over 2.5 billion mailboxes worldwide. Government organisations such as the UK Government, NIST, and the Federal Trade Commission in the USA all recommend that a DMARC implementation protects email.
The benefits of DMARC protection for financial services organisations include:
- Brand protection - it is a question of when, not if, your business email domain will be used in a cyberattack against other organisations. Whether it's phishing, malware distribution, or nuisance SPAM, your brand suffers when perceived to be associated with these malicious emails.
- Increased email deliverability - modern email systems have powerful SPAM filters. They are often very aggressive in what they classify as SPAM. Implementing DMARC allows sending mail servers to inform receiving mail servers that the emails are legitimate. This reduces the likelihood that SPAM filters will flag them.
- Reduce service calls - preventing the ability to do email domain spoofing minimises the number of support calls that result from suspicious emails to your customers and business partners.
- Visibility into cyberattack risk - DMARC allows you to see the volume of third parties sending emails using your domain. If they are cybercriminals using the domain, then you can take steps to prevent this use. If they are legitimate third-party services that are allowed to send emails on your behalf, then DMARC will give you visibility to ensure they are complying with your email best practices.
- Business email compromise (BEC) protection - Most people have seen emails pretending to be from the CEO, CFO, or another executive in their organisation. Or a spoofed email from a business partner asking for confidential information. DMARC protects against these kinds of BEC attacks.
Agari Delivers Industry Leading DMARC
Agari transforms email authenticity scoring via their next-generation predictive machine learning based email protection solutions. DMARC is an integral part of their vision and solution offering. Agari automates DMARC implementation, simplifying the process of choosing which senders are authorised to send emails on your behalf, and reducing the task of maintaining an accurate enforcement policy. If you send emails via Salesforce, Mailchimp, HubSpot, or similar services, then implementing Agari DMARC will ensure that receivers do not block these emails as SPAM. One Agari customer reported that they were able to redeploy 60 support staff after putting DMARC in place due to the reduced number of email-related service calls they had to handle.
Find Out More
Implementing DMARC protection for an email domain is an essential and necessary part of a modern cybersecurity strategy. It can protect your users, your business partners, and your brand. Agari DMARC allows you to implement the protection you need quickly. Using advanced machine learning and real-time intelligence Agari detects, defends, and deters costly email attacks, including business email compromise, spear phishing and account takeover. See the Agari site for more details on their solutions and contact Renaissance to find out more.

