82% of U.S. Campaign Domains Unprotected Against Email Impersonation Ahead of 2026 Midterms
Event summary
- DigiCert's analysis of 3,756 U.S. campaign domains found 82% lack full DMARC enforcement, leaving them vulnerable to email impersonation.
- Only 18% of campaign domains enforce DMARC, with 38% monitoring but not enforcing protections.
- The study was conducted on August 21, 2026, ahead of the 2026 midterms, highlighting a significant security risk for voter outreach and fundraising.
- DMARC enforcement can help block fraudulent emails before they reach voters, according to DigiCert's Industry Research and Community Engagement Lead Al Iverson.
The big picture
DigiCert's findings underscore the ongoing challenge of securing digital campaign infrastructure against impersonation attacks. As political campaigns increasingly rely on digital channels for fundraising and voter engagement, the lack of DMARC enforcement represents a critical vulnerability. This issue is particularly relevant given the growing concerns around election integrity and the potential for misinformation to influence voter behavior. The scale of the problem, with 82% of domains unprotected, highlights the need for broader adoption of email authentication protocols across the political landscape.
What we're watching
- Security Compliance
- Whether campaigns will prioritize DMARC enforcement as the midterms approach, given the potential for email-based misinformation and fraud.
- Regulatory Impact
- How CISA's recommendations for DMARC and SPF will influence campaign security practices in future elections.
- Technological Adoption
- The pace at which campaigns adopt additional email protection measures like BIMI and DigiCert Mark Certificates.
Related topics
