Proofpoint: Four in Five of Fortune Southeast Asia 500 Companies Still Leave Customers and Stakeholders Exposed to Email Fraud
- Only 17% of Fortune Southeast Asia 500 enterprises enforce the recommended DMARC "Reject" policy to actively block fraudulent emails — up from 13% in Proofpoint's 2024 analysis.
-
Malaysia’s progress outpaced every other market, while Singapore's leading 28% enforcement rate remains stagnant.
SINGAPORE – 27 August 2026 – Proofpoint, Inc., a global leader in human and agent cybersecurity, today released new research highlighting a persistent security gap among Southeast Asia’s largest enterprises, with only 17% of Fortune Southeast Asia 500 having implemented the recommended and most stringent level of email authentication. As AI-generated phishing and business email compromise campaigns accelerate across the region, proper email authentication is essential to prevent cybercriminals from spoofing corporate identities and reducing the risk of email fraud.
These findings are based on an analysis of the Domain-based Message Authentication, Reporting and Conformance (DMARC) records of the 500 largest companies in Southeast Asia listed on the Fortune Southeast Asia 500. DMARC is a widely adopted email validation protocol that protects domain names from being misused by malicious actors by authenticating the sender's identity before an email reaches its intended destination. This system detects and prevents domain spoofing, a primary technique used for phishing and business email compromise (BEC). DMARC features three protection levels—monitor, quarantine, and reject—with "reject" being the most secure setting to actively block fraudulent emails from reaching users' inboxes.
Email remains the primary threat vector globally and across the region. In Singapore, for example, 58% of organisations identified email as their most common attack vector, according to Proofpoint's 2026 AI and Human Risk Landscape report. As generative AI enables cybercriminals to create more convincing impersonation and phishing campaigns at unprecedented speed and scale, organisations need stronger defences. Implementing robust email authentication standards such as DMARC is a critical step in protecting customers, employees and stakeholders from fraudulent communications and domain impersonation.
"Trust is one of organisations’ most valuable assets, yet it is still being exploited by cybercriminals and increasingly by AI-powered impersonation attacks. Our findings show that too many of Southeast Asia's largest enterprises are still leaving their domains vulnerable to spoofing, despite the availability of proven protections like DMARC," said Philip Sow, Head of Systems Engineering, Southeast Asia and South Korea at Proofpoint. "Enforcing DMARC at the 'Reject' level is one of the most effective ways organisations can prevent fraudulent emails from reaching customers and employees, while strengthening trust in their digital communications."
Key findings of Proofpoint’s DMARC analysis across key Southeast Asia markets include:
-
Overall, 83% currently do not enforce the recommended strictest level of DMARC implementation (reject).
-
17% do not have any DMARC record at all and are wide open to email fraud and domain spoofing attacks.
-
Across the 500 largest companies in Southeast Asia listed on the Fortune Southeast Asia 500, the remainder sit at quarantine (38%) or monitor (28%).
-
DMARC results vary by countries across the region:
-
Singapore: Continues to lead the region on strict email authentication at 28%, but the rate is unchanged from Proofpoint's 2024 analysis. 34% remain under quarantine mode and 10% still lack any DMARC record.
-
Malaysia: Recorded highest improvement on strict enforcement, rising from 11% in 2024 to 21% today. Only 7% of top Malaysian enterprises have no DMARC record — the lowest in the region — while a further 55% sit at quarantine.
-
Indonesia: Recorded the region's second-largest gain, with reject enforcement rising from 10% to 18%. 44% utilise quarantine, while 18% have no DMARC record at all.
-
Thailand: Posted the sharpest fall in unprotected domains, from 45% with no DMARC record in 2024 to 26% today. Strict enforcement, however, rose only marginally to 12%, and 35% remain at the monitor level — gathering data without active blocking.
-
Vietnam: Improved from the region's lowest base, with strict enforcement rising from 4% to 11% and domains with no DMARC record falling from 37% to 24%. 38% remain on monitor. Vietnam and the Philippines now record the region's lowest strict enforcement rate, at 11% each.
-
Philippines: Made no progress on strict enforcement, holding at 11% for ‘Reject’ since 2024 and slipping from joint-second in the region to fifth. 36% use quarantine and 23% carry no email authentication record.
Best Practices for Enhanced Email Security for customers, staff, and other stakeholders:
-
Check the validity of all email communication and be aware of potentially fraudulent emails impersonating trusted brands, colleagues, suppliers, and stakeholders.
-
Be cautious of any communication attempts that request login credentials or threaten to suspend service or an account if a link isn't clicked.
-
Adopt phishing-resistant multifactor authentication, such as passkeys.
To learn more about DMARC, visit: https://www.proofpoint.com/au/threat-reference/dmarc.
Methodology
This analysis was conducted in July 2026 using data from the Fortune Southeast Asia 500 list.
About Proofpoint, Inc.
Proofpoint, Inc. is a global leader in human and agent cybersecurity, securing how people, data and AI agents connect across email, cloud and collaboration tools. Proofpoint is a trusted partner to over 80 of the Fortune 100, over 14,000 large enterprises, and millions of smaller organisations in stopping threats, preventing data loss, and building resilience across people and AI workflows. Proofpoint's collaboration, data and AI security platform helps organisations of all sizes protect people, defend data and adopt AI securely and confidently. Learn more at www.proofpoint.com.
Connect with Proofpoint on LinkedIn.
Proofpoint is a registered trademark or tradename of Proofpoint, Inc. in the U.S. and/or other countries. All other trademarks contained herein are the property of their respective owners.