Same for Google Business customers.
Phishers pay to send the emails. You don't pay to receive no email. So that's the conflict of interest of these businesses.
The "CA" for email is basically SPF/DKIM/DMARC as extensions but they're kind of useless because all email providers are lying about quarantine mechanisms anyways. Nothing happens if you report an abuse of spam policies.
But I'm kind of biased because I maintain my own antispam repository [1].
Most of the professional phishing campaigns use e.g. cloned websites under a different top level domain (like company-global.com or company-eu.com), with even legit looking profiles on LinkedIn which are even LLM controlled in their responses. They use pictures and sometimes even identities of real people, and the humans usually don't know about anything that's happening online with their identity in their name.
> The "CA" for email is basically SPF/DKIM/DMARC as extensions but they're kind of useless because all email providers are lying about quarantine mechanisms anyways. Nothing happens if you report an abuse of spam policies.
So it sounds like these email providers simply won't do anything since they're not being paid or forced to do so. I don't understand why there isnt any push from financial institutions? Since access to their customer's accounts is usually the end goal for these phishing emails.
Or maybe the FTC/FCC should step in. Or some legislation is needed to enforce this.
toomuchtodo•5h ago
> Even ignoring AI, I don't know much about email but why isn't there something like a CA for email?
Is there demand for this? Would users pay for it? Or would they tolerate the existing experience with whatever does or does not end of in their Spam folder? The options here are to pick an email provider based on what they can offer from an email protection perspective, or wiring up your own defenses using something that can read your inbox and action emails within it (if your email provider's solution is lacking).
[1] https://www.cloudflare.com/learning/email-security/dmarc-dki...