Proofpoint finds Southeast Asia firms lag on DMARC
Mon, 7th Sep 2026 (Today)
Proofpoint has found that 17% of companies on the Fortune Southeast Asia 500 enforce the strictest DMARC email authentication setting, highlighting a broad gap in email security across the region's largest businesses.
The study examined adoption of Domain-based Message Authentication, Reporting and Conformance, or DMARC, across 500 large companies in Southeast Asia. DMARC verifies an email sender and can help stop criminals from spoofing corporate domains in phishing and business email compromise attacks.
Proofpoint found that 83% of the companies it analysed do not use the recommended "reject" policy, the strictest DMARC setting. Another 17% have no DMARC record, while 38% are at "quarantine" and 28% remain at "monitor".
The figures mark a modest improvement from Proofpoint's earlier regional analysis, when 13% of companies used the "reject" setting. Even so, most of the largest listed groups in Southeast Asia have yet to move to the strongest level of enforcement.
Email remains a major route for cyber attacks, and Proofpoint linked the findings to a rise in AI-generated phishing and impersonation campaigns. In Singapore, 58% of organisations identified email as their most common attack vector, according to Proofpoint's 2026 AI and Human Risk Landscape report.
Results varied sharply by market.
Singapore recorded the highest rate of strict DMARC enforcement in the region at 28%, unchanged from Proofpoint's 2024 analysis. In the city-state, 34% of companies were at quarantine level and 10% had no DMARC record.
Malaysia showed the biggest improvement in strict enforcement. Its "reject" adoption rose from 11% to 21%, while only 7% of leading enterprises had no DMARC record, the lowest share in the region. A further 55% were operating at quarantine level.
Indonesia posted the second-largest gain, with "reject" enforcement rising from 10% to 18%. In Indonesia, 44% of companies used quarantine, while 18% had no DMARC record.
Thailand cut the share of unprotected domains more sharply than any other market in the survey. Companies with no DMARC record fell from 45% in the earlier study to 26%, though strict enforcement edged up only to 12%. Another 35% remained at monitor level.
Vietnam improved from a low base. "Reject" adoption rose from 4% to 11%, while the share of domains with no DMARC record dropped from 37% to 24%. Still, 38% of companies in Vietnam remained on monitor.
The Philippines did not improve on strict enforcement, holding at 11% since 2024. That left it level with Vietnam for the lowest "reject" rate in the region. In the Philippines, 36% of companies used quarantine and 23% had no email authentication record.
Email fraud risk
The findings underline how many major companies still rely on partial monitoring or filtering rather than outright rejection of unauthenticated messages. Under DMARC, monitor settings allow organisations to collect information on unauthorised email activity, while quarantine settings can divert suspicious messages. Only the reject setting is designed to block fraudulent emails from reaching inboxes altogether.
That matters because cyber criminals often impersonate trusted brands, suppliers or executives to steal money, credentials or sensitive information. Spoofed email domains are a common element in such attacks, particularly in business email compromise schemes that target employees or customers with apparently legitimate messages.
Proofpoint framed the issue as one of trust as much as technical control, arguing that stronger email authentication can help organisations protect customers, employees and stakeholders from fraudulent communications that misuse corporate identities.
"Trust is one of organisations' most valuable assets, yet it is still being exploited by cybercriminals and increasingly by AI-powered impersonation attacks. Our findings show that too many of Southeast Asia's largest enterprises are still leaving their domains vulnerable to spoofing, despite the availability of proven protections like DMARC," said Philip Sow, Head of Systems Engineering, Southeast Asia and South Korea at Proofpoint.
He added: "Enforcing DMARC at the 'Reject' level is one of the most effective ways organisations can prevent fraudulent emails from reaching customers and employees, while strengthening trust in their digital communications."