More Than Half Of The Middle East’s Most Valuable Companies Implement The Highest Level Of Email Authentication
Proofpoint, Inc., a leading cybersecurity and compliance company, today released new research revealing that more than half (57%) of the Middle East’s most valuable listed companies have implemented the highest level of email protection. While adoption of email authentication is widespread across the region’s largest organisations, 43% have yet to implement the strongest protection available. As a result, attackers may still be able to impersonate trusted brands in phishing campaigns targeting customers, partners and employees.
These findings are based on a Domain-based Message Authentication, Reporting and Conformance (DMARC) analysis of the 2026 Forbes Middle East Top 100 Most Valuable Companies, which ranks publicly listed organisations by market capitalisation across regional stock exchanges. DMARC is an email authentication standard that helps organisations prevent cybercriminals from sending fraudulent emails using their domains. Organisations receive the strongest protection when they enforce a “reject” policy, which blocks unauthorised emails before they reach recipients.
Key findings from the research include:
- Almost all (99%) of the Middle East’s most valuable companies have published a DMARC record, which means only 1% are taking no steps to protect their domain from impersonation.
- In addition, more than half (57%)have implemented the recommended “reject” policy, the highest level of DMARC protection. This means 43% are potentially leaving customers, partners and suppliers more exposed to fraudulent emails sent in the name of trusted organisations.
“Email remains the number one delivery channel for cyber threats, and the rise of AI is making impersonation attacks faster, more convincing and easier to scale,” said Emile Abou Saleh, Vice President, Emerging Markets at Proofpoint. “As organisations increasingly rely on digital communications to engage customers and partners, trust has become a critical security control. Publishing a DMARC record is an important first step, but organisations enforcing the recommended reject policy are best positioned to prevent attackers from abusing their domains to impersonate trusted brands.”
Email remains the primary attack vector for cybercriminals, and Proofpoint detects billions of malicious messages every day. As phishing, business email compromise and AI-generated impersonation attacks become increasingly convincing, enforcing strong email authentication is becoming a fundamental component of organisational trust.
Every day, Proofpoint analyses billions of emails to identify advanced threats targeting organisations worldwide. This intelligence consistently shows that attackers continue to exploit trusted brands through email impersonation, reinforcing the importance of enforcing DMARC at the recommended reject policy.








Email: info@cyber-gear.com