Proofpoint has released research showing that only 17% of Fortune Southeast Asia 500 companies have implemented the recommended DMARC “Reject” policy, the strictest level of email authentication designed to actively block fraudulent emails. This marks an increase from 13% in Proofpoint’s 2024 analysis, though the majority of the region’s largest enterprises remain without this level of protection.
Email Remains The Primary Attack Vector, Says Proofpoint
The findings are based on an analysis of Domain-based Message Authentication, Reporting and Conformance (DMARC) records across the 500 largest companies in Southeast Asia listed on the Fortune Southeast Asia 500. DMARC authenticates a sender’s identity before an email reaches its destination, helping detect and prevent domain spoofing used in phishing and business email compromise (BEC). The protocol offers three protection levels – Monitor, Quarantine and Reject – with “Reject” considered the most secure setting.
According to Proofpoint’s 2026 AI and Human Risk Landscape report, 58% of organizations in Singapore identified email as their most common attack vector. As generative AI enables more convincing impersonation and phishing campaigns, Proofpoint said stronger email authentication has become increasingly important for protecting customers, employees and stakeholders from fraudulent communications.

Overall, 83% of Fortune Southeast Asia 500 companies do not enforce the strictest DMARC level, while 17% have no DMARC record at all; the remaining companies sit at Quarantine (38%) or Monitor (28%). Singapore continues to lead the region in strict enforcement at 28%, though this figure is unchanged since 2024, with 34% at Quarantine and 10% lacking any DMARC record. Malaysia recorded the region’s largest improvement, rising from 11% in 2024 to 21%, with only 7% lacking a DMARC record (the lowest in the region) and 55% at Quarantine.
Indonesia posted the second-largest gain, with strict enforcement rising from 10% to 18%, while 44% remain at Quarantine and 18% have no DMARC record. Thailand recorded the sharpest drop in unprotected domains (from 45% to 26% with no DMARC record), though strict enforcement rose only marginally to 12%, with 35% still at the Monitor level.
Vietnam improved from the region’s lowest base, with strict enforcement rising from 4% to 11% and unprotected domains falling from 37% to 24%, while 38% remain at Monitor. The Philippines recorded no progress on strict enforcement, holding at 11% since 2024 and slipping from joint-second to fifth in regional ranking, with 36% at Quarantine and 23% carrying no email authentication record. Vietnam and the Philippines now share the region’s lowest strict enforcement rate, at 11% each.
“Our findings show that too many of Southeast Asia’s largest enterprises are still leaving their domains vulnerable to spoofing, despite the availability of proven protections like DMARC,” said Philip Sow, Head of Systems Engineering, Southeast Asia and South Korea at Proofpoint. “Enforcing DMARC at the ‘Reject’ level is one of the most effective ways organizations can prevent fraudulent emails from reaching customers and employees, while strengthening trust in their digital communications.”
Proofpoint recommends that organizations verify the validity of email communications and remain cautious of messages impersonating trusted brands, colleagues, suppliers or stakeholders. It also advises caution around communications requesting login credentials or threatening account suspension, and recommends adopting phishing-resistant multifactor authentication methods, such as passkeys.
Pokdepinion: Malaysia’s jump from 11% to 21% is decent progress, but 55% still sitting at quarantine is a lot of exposure.

