DMARCPulse
All posts Phishing Volume Down 20% – Why the Risk Is Actually Growing

Phishing Volume Down 20% – Why the Risk Is Actually Growing

DMARCPulse Team

Fewer phishing emails, more damage – how does that add up?

The headline sounds like good news: global phishing volume has dropped by roughly 20%. Fewer attacks, less danger – right? Look closer and you’ll find the opposite. Attackers are sending fewer emails, but each one is more dangerous than ever.

The reason is straightforward: AI has dramatically lowered the barrier to high-quality attacks. What once required a seasoned team of social-engineering specialists can now be done by a well-configured language model in minutes.

From spray-and-pray to precision targeting

Classic phishing ran on volume: millions of generic messages, clumsy grammar, suspicious sender addresses, obvious red flags. Detection rates were high – both for technical filters and for the common sense of recipients.

That has fundamentally changed. AI-generated phishing emails now:

  • address recipients by name, role, and current project context
  • convincingly mimic the writing style of known colleagues or managers
  • contain no spelling or grammar mistakes
  • adapt tone and content to the target’s industry, company, and even time of day

The result is messages that make even experienced IT professionals pause. Spear-phishing, which once required hours of manual research, has become scalable.

Why email authentication is now a strategic priority

Many organisations still treat DMARC, SPF, and DKIM as spam hygiene – something you set up once and forget. That framing is dangerously outdated, especially as attacks become more targeted and convincing.

Email authentication solves a fundamental problem: it answers whether a message actually comes from the domain it claims to come from. No language model can bypass a correctly configured DMARC policy if it has no control over the sending domain.

In concrete terms:

  • SPF defines which servers are authorised to send on behalf of a domain.
  • DKIM cryptographically signs messages – any tampering becomes detectable.
  • DMARC ties both together and gives receiving servers clear instructions: deliver, quarantine, or reject.

An attacker crafting a convincing email from [email protected] will fail at a strict DMARC policy with p=reject – regardless of how well-written the message is.

The problem with “we already have DMARC”

Setting up DMARC is step one. Operating it correctly is the step that actually matters. In practice, the reality often looks like this:

  • Policy is set to p=none – monitoring mode, but no active protection
  • Aggregate reports go unread because the XML format is unwieldy
  • New services (newsletter tools, CRMs, cloud telephony) start sending email without being listed in the SPF record
  • DKIM keys have never been rotated

These are exactly the gaps that sophisticated attackers exploit. An AI-driven phishing campaign doesn’t need to find a technical vulnerability – it looks for domains that have DMARC but run p=none with stale SPF entries.

Aggregate reports as an early-warning system

DMARC aggregate reports are the early-warning system most organisations aren’t using. Receiving servers like Gmail, Microsoft 365, and Yahoo send daily reports back to you detailing which messages were delivered or rejected on behalf of your domain – and why.

Those reports contain valuable signals:

  • Unknown IP addresses sending in your domain’s name
  • Services that aren’t setting DKIM signatures correctly
  • Spoofing attempts that were blocked by p=reject

The catch: reports arrive as XML files that are nearly unreadable without tooling. If you’re not parsing them, you’re flying blind.

From p=none to p=reject – the path to real protection

Getting to robust email authentication isn’t a sprint, but it’s not a marathon either. A structured approach:

  1. Inventory: Which domains do you actively send from? Which are dormant but could be spoofed?
  2. Enable monitoring: Deploy DMARC with p=none and a reporting address, start collecting reports.
  3. Analyse reports: Identify all legitimate mail sources and make sure they’re covered by SPF and DKIM.
  4. Tighten the policy: Move gradually from p=none to p=quarantine to p=reject.
  5. Monitor continuously: New services, changed IP ranges, expiring DKIM keys – these things shift constantly.

Step 5 is the one most teams skip. It’s also the most important: a configuration that’s correct today won’t stay correct on its own.

Fewer emails, higher stakes

The drop in phishing volume isn’t a sign that attackers are losing interest. It’s a sign they’ve become more efficient. Less scatter, more precision – that’s the logic behind AI-assisted phishing.

For IT admins and security teams, this means the bar is higher. Technical controls like DMARC need to be not just present, but actively and correctly configured. And they need continuous monitoring, because the attack surface keeps shifting.

Check how your domain is positioned right now with the free domain check from DMARCPulse: dmarcpulse.io/en/free-domain-check