Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Phishing is getting harder to spot: how organizations can help customers know what to trust

Дата публикации: 23-09-2026 21:20:00

Phishing remains a growing threat. The Anti-Phishing Working Group (APWG) identified 3.8 million unique attacks in 2025, showing just how widespread these schemes have become. Cybersecurity Awareness Month emphasizes the importance of recognizing and reporting phishing, while organizations also have an important role to play in making legitimate communications easier to authenticate and recognize.Phishing has become more convincing, making traditional warning signs harder to rely on. Training and awareness still matter, but technical safeguards and trust signals can give recipients additional ways to distinguish legitimate brand communications from impersonation attempts.Email remains a top form of outreach and a great way to connect brands and consumers. By combining authentication with visible brand signals, organizations can help protect recipients, make legitimate messages easier to recognize, and build brand trust.

Основное содержимое страницы с новостью.

Phishing remains a growing threat. The Anti-Phishing Working Group (APWG) identified 3.8 million unique attacks in 2025, showing just how widespread these schemes have become. Cybersecurity Awareness Month emphasizes the importance of recognizing and reporting phishing, while organizations also have an important role to play in making legitimate communications easier to authenticate and recognize.

Phishing has become more convincing, making traditional warning signs harder to rely on. Training and awareness still matter, but technical safeguards and trust signals can give recipients additional ways to distinguish legitimate brand communications from impersonation attempts.

Email remains a top form of outreach and a great way to connect brands and consumers. By combining authentication with visible brand signals, organizations can help protect recipients, make legitimate messages easier to recognize, and build brand trust.

Why phishing is getting harder to distinguish from legitimate email?

Phishing refers to deceptive messages designed to steal information, credentials, or prompt harmful actions. These attacks often rely on spoofing or impersonation to make messages appear to come from a trusted source. 

Phishing emails in the past were often difficult to spot, but still included a few key tells: 

  • Misspellings
  • Generic greetings
  • Awkward grammar
  • Promises that seem too good to be true
  • Warnings or urgent demands for action

Savvy users noticed these scam signals and responded accordingly, but these days, phishing emails are a lot more polished, and therefore, more convincing. Content is more persuasive, as attackers may use professional formatting, personal details, lookalike domains, spoofed display names, or multiple channels such as email and text messages to imitate legitimate brands and contacts. AI can also make fraudulent messages easier to create at scale and harder to distinguish based on writing quality alone.

Traditional phishing red flags still matter, but they are no longer enough to differentiate dangerous emails from their legitimate counterparts. 

Cybersecurity Awareness Month reinforces the ongoing need to recognize and proactively address phishing. There are measures that both senders and recipients can take. Organizations can support user awareness with technical safeguards and trust signals that help recipients recognize legitimate communications and identify suspicious messages.

How organizations can make legitimate email easier to recognize

It should not be entirely on the email recipient to distinguish phishing attacks from authentic messages. Brands and email providers can do much of the heavy lifting by implementing frameworks and protocols that help address phishing at the source. Several protocols work together to address email security risks and to enable visual trust indicators, including:

  • SPF. The Sender Policy Framework forms the critical foundation on which several email security safeguards rely. This helps receiving mail servers clarify that sending servers are authorized to send messages on a particular domain's behalf.
  • DKIM. DomainKeys Identified Mail leverages public key cryptography to add a cryptographic signature to email. Receiving systems verify that signature using the domain’s public key. Through DKIM, they can verify the signing domain and determine whether signed message content has been altered.
  • DMARC. The Domain-based Message Authentication, Reporting, and Conformance protocol builds on SPF and DKIM by evaluating authentication and alignment with the From domain. Domain owners can publish policies requesting that receivers quarantine or reject messages that fail aligned authentication.
  • BIMI. The email standard Brand Indicators for Message Identification allows qualifying brands to display verified logos next to messages within supported email inboxes. BIMI uses the previously discussed authentication standards so that only domains with proper enforcement can showcase their logos.
Mark Certificates make authenticated brand identity visible

BIMI enables brands to display logos in email inboxes, while mark certificates provide the third party validation of the organization and logo that many mailbox providers require for display. This adds an independently validated visual brand signal to authenticated email.

Two types of Mark Certificates help bring the advantages of brand visibility and visual trust to client or customer inboxes. Verified mark certificates (VMCs) allow brands to display trademarked logos and to qualify for Gmail's blue checkmark.

Common Mark Certificates (CMCs) provide an option for eligible organizations without a registered trademark. Qualifying logos must have been in public use for at least 12 months.

S/MIME certificates verify senders and protect email integrity

The Secure/Multipurpose Internet Mail Extensions standard offers a pathway to secure emails through encryption and digital signatures. Typically purchased from certificate authorities (CAs) and installed in email clients, these certificates use public-key cryptography to secure email contents — attachments included.

Through S/MIME, digital signatures help email recipients confirm sender identities so they feel confident that messages come from trusted sources. Furthermore, S/MIME proves that messages have not been changed in transit. When encryption is used, message content and attachments can be protected so that only the intended recipient can decrypt them.

These capabilities can strengthen phishing defenses by giving recipients an additional way to verify sender identity and message integrity, making it more difficult for attackers to successfully impersonate a legitimate signed sender.

Make email trust part of your phishing defense

Recognizing and reporting phishing is a key part of cybersecurity awareness, but as schemes continue to grow more sophisticated, watching for well-known red flags is not sufficient. User awareness should be reinforced by technical safeguards. Frameworks such as SPF, DKIM, and DMARC provide a foundation for email authentication, helping organizations protect their sending domains and make unauthorized messages easier for receiving systems to identify.

BIMI and mark certificates signal credibility with visual cues on top of that technical foundation. Through BIMI and VMCs (or CMCs), validated brand logos can appear in supported email inboxes.

Under this approach, both senders and recipients have important parts to play. Organizations set the stage for secure email communication by implementing SPF, DKIM, DMARC, and BIMI — and adding S/MIME when verified sender identity, digital signing, or encryption is needed.

Recipients do their part by carefully inspecting sender domains and looking for validated brand logos (and, when relevant, Gmail blue checkmarks). They should avoid clicking on any links that are unexpected or seem suspicious. The same level of caution should be applied to unanticipated attachments. Unexpected or sensitive requests that emerge should be verified through alternative channels. Any phishing schemes that come to light must be quickly reported.

Sectigo supports stronger email trust through solutions designed for different aspects of email identity and security. Mark Certificates validate brand identity and logos for supported inboxes, while S/MIME certificates support sender verification, digital signing, message integrity, and encryption.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1End of manual certificate management: Why automation is becoming a cybersecurity requirement09.0124-09-2026
2Why shorter certificate lifespans matter for cybersecurity?09.824-09-2026
3How to sign a PDF: Electronic and Digital Signature methods explained06.710-08-2026
4Sectigo Quantum Ready™: Moving from quantum awareness to quantum action011.2117-09-2026
5From courtroom credibility to public recognition: How lawyers can build a stronger professional brand09.8328-09-2026
6Flexible tenancy, same leadership: the next evolution of the Sectigo Partner Platform08.4816-09-2026
7Sectigo's F5 partnership expands to F5 Distributed Cloud Services: What this means for you06.5403-09-2026
8Revolut breach exposes authentication-authorization gap018.8617-09-2026
9Qué sabemos de este aviso para actualizar tus datos de correo Movistar: es una notificación de Telefónica para "garantizar la seguridad" de tu cuenta05.323-09-2026
10Cicada8: во II квартале 2026 г. мошенники чаще атаковали операторов связи, брокеров и социальные фонды010.9929-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.42. Источник: sectigo.com.