preloader

· · email deliverability dmarc digital-security nis2 compliance europe

Countries With Mandatory DMARC Cut Phishing Success From 69% to 14%, Most of Europe Still Hasn’t Enforced It

Source: PowerDMARC

A DMARC record that only monitors and never rejects is a smoke detector with the battery removed. It will tell you a fire happened, eventually, after the fact.

The number that should worry every compliance officer

ENISA’s Threat Landscape reporting puts phishing behind roughly 60 percent of the initial intrusions observed across the European Union, which makes it by a wide margin the most common way attackers get their first foothold. The same body of research found something more actionable: in countries where national policy made DMARC enforcement mandatory, phishing success rates dropped from 69 percent to 14 percent. Countries without a mandate saw no comparable improvement. That is not a marginal gain from a minor technical control, it is a five-fold reduction in the success rate of the single most common attack vector, achieved by an email authentication standard that has existed for well over a decade.

NIS2 turned email into a supervised control, not a best practice

Under NIS2, email is now an explicitly supervised control surface for essential and important entities and financial institutions, with administrative fines that can reach 10 million euros or 2 percent of global annual turnover, alongside a 24-hour breach reporting obligation that is now fully in force. Germany’s national implementing law took effect on December 6, 2025, and other member states are rolling out their own enforcement on similar timelines. SPF, DKIM and DMARC are the mechanisms that close the domain-spoofing gap NIS2’s risk management requirements are aimed at, alongside DANE and MTA-STS for enforcing transport encryption. This is no longer a marketing-team concern about spam folder placement, it is a regulatory requirement with a real fine attached, and it applies to any organization that falls under NIS2’s essential or important entity categories.

Having a DMARC record is not the same as enforcing one

The gap that actually matters is the one between publishing a DMARC record and setting its policy to reject unauthenticated mail. A record set to none only observes and reports, it does nothing to stop a spoofed message from reaching an inbox, and plenty of organizations set up DMARC years ago, glanced at the reports once, and never moved the policy any further. That half-finished state satisfies an auditor’s checkbox question about whether DMARC “exists” while providing close to none of the phishing protection the standard is actually capable of. Given the direct line ENISA’s data draws between enforcement and phishing outcomes, and the direct line NIS2 draws between email security failures and fines, checking whether your organization’s DMARC policy is still sitting at none is one of the fastest compliance and security wins available right now.

If you are not sure whether your domain’s DMARC policy is actually enforcing anything, or you need help getting from a monitoring-only record to full NIS2-aligned enforcement without breaking legitimate mail flow in the process, contact Excello Digital. We help European businesses close this exact gap.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!