Opens in a new tab
vmblog logo 2024 wht (updated)

Midyear 2026: Email Security Gaps Persist as AI Raises Impersonation Risk

Share: 

David Marshall | Published: August 27, 2026

With summer drawing to a close, many organizations still have not fully adopted basic email authentication policies designed to prevent domain impersonation, according to a new midyear analysis from Red Sift.

The new findings come as generative AI makes phishing and spoofing attempts easier to scale and harder for recipients to distinguish from legitimate communications. Attackers can now produce convincing messages that imitate executives, agencies, brands and suppliers with little manual effort.

“Today, email authentication and account authentication are two of the most critical layers of modern cybersecurity, essentially acting as dual partners. As 2026 reaches its midyear point, new email security standards are helping organizations across the U.S. prevent domain impersonation and protect customers from phishing, while heightened account security measures protect user identities and accounts,” said Brian Westnedge, director of alliances and partnerships at Red Sift. “Together, as AI empowered attacks increase in their sophistication, these defenses create a robust security posture by reducing the risk of both fraudulent communications and compromised access for the business community as well as individual consumers.”

Red Sift’s 2026 U.S. DMARC Adoption Report found that just 38.4% of leading U.S. organizations have implemented the email security controls required to block domain spoofing and impersonation attacks. While nearly 90% have taken initial steps by publishing a DMARC record, most have not reached the enforcement level needed to stop attackers from sending fraudulent emails that appear to come from trusted brands, institutions, and businesses.

DMARC is the global email authentication standard used to verify legitimate senders and prevent email impersonation. Yet among 5,000 leading organizations analyzed across all 50 states and Washington, D.C., only 1,919 domains had reached full enforcement (p=reject), the only DMARC policy that actively blocks spoofed messages from reaching inboxes.

The report found stark gaps by geography and industry. North Carolina led all states with 55% enforcement, while Montana and New Mexico ranked last at 25%. New York City posted the highest city-level adoption rate at 73%.

Across industries, higher education emerged as one of the weakest sectors, with nearly half of colleges and universities still relying on monitoring-only policies that provide no protection against spoofing. Only 6% of organizations analyzed achieved the highest level of email authentication maturity, including advanced protections that help recipients verify legitimate communications.

Critical infrastructure remains particularly exposed. More than half of water and waste organizations lack full DMARC enforcement, while 42% of companies across the water, waste, chemical, and energy sectors have yet to implement the protections needed to stop domain impersonation attacks. As nation-state and AI-driven phishing campaigns continue to escalate, the findings underscore how many of the organizations Americans rely on every day remain vulnerable to email-based fraud.

“When nation-state actors target critical infrastructure, they rarely begin with sophisticated attacks. More often, they exploit overlooked weaknesses such as phishing emails, domain impersonation, and compromised credentials to gain a foothold inside an organization. Water utilities have become an increasingly attractive target because they provide essential public services and often operate with limited cybersecurity resources. The recent incidents in Minnesota and beyond are a reminder that organizations responsible for critical infrastructure cannot afford to treat email security as a secondary concern. Strengthening defenses against impersonation and phishing attacks remains one of the most effective ways to reduce risk from both nation-state and criminal threat actors,” added Westnedge.