Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Darktrace reported that 62% of the phishing emails it detected in a defined first-half 2024 observation window bypassed DMARC verification checks. That is a finding about Darktrace’s own customer-fleet telemetry—not a rate for all phishing email worldwide. It also does not mean DMARC is useless: DMARC checks domain authentication and alignment, not whether an authenticated sender’s message is trustworthy.

What the 62% figure measures

In its First 6: Half-Year Threat Report 2024, Darktrace said its Darktrace/EMAIL product detected 17.8 million phishing emails between December 21, 2023 and July 5, 2024. The company reported that 62% of those emails “successfully bypassed” DMARC verification checks. The denominator is the phishing emails in that vendor dataset, not all email or all phishing attempts on the internet. Darktrace’s report does not establish a random global sample, confidence interval, or universal prevalence rate.

The same report said 56% of those messages passed through all existing security layers. That figure describes the report’s observed environment and defenses; it is not a claim that every organization’s security stack has the same failure rate.

How can a phishing email pass DMARC?

DMARC is a domain-level email authentication, reporting, and conformance protocol. It checks whether SPF or DKIM authentication aligns with the domain shown in the message’s visible From address, then applies the domain owner’s published policy. The protocol’s pass/fail and reporting model is specified in RFC 7489.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A DMARC pass is evidence about domain authentication and alignment; it is not a judgment that the message is safe. A phishing email can pass when the attacker sends from a domain they control and have configured correctly, when a legitimate sender account is compromised, or when an attacker abuses an authorized third-party sending service. Darktrace also described attackers using legitimate services such as Dropbox and Slack to blend malicious activity into normal traffic. Darktrace’s account identifies this as one evasion tactic, not the explanation for every DMARC-passing message.

What DMARC does—and does not—protect against

  • It can help address: unauthorized use of a protected domain in the visible From address, when SPF or DKIM authentication fails or does not align and the domain’s policy is enforced.
  • It does not establish: that the authenticated sender is benevolent, that a message’s links or attachments are safe, or that an account has not been taken over.
  • It is one layer: domain authentication should be combined with controls that assess sender reputation, message content, URLs and attachments, unusual behavior, and account security.

That distinction explains why the 56% result matters alongside the 62% statistic: authentication is useful for one class of identity abuse, but it cannot replace threat detection across delivery, interaction, and account compromise.

Rank #2
Securing Email with Email Security Appliance 300-720 SESA Study Guide Flashcards
  • Pass the Securing Email with Email Security Appliance 300-720 SESA with updated flashcards packed with detailed content aligned to the latest exam blueprint. Cover all core topics without the overload found in lengthy study guides. Get 300+ Securing Email with Email Security Appliance 300-720 SESA flashcards on 8-1/2″ x 11″ perforated card stock.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is 62% still the current rate?

No single percentage should be treated as timeless. Darktrace’s later full-year 2024 report gave a 70% DMARC-pass figure for a different dataset and observation window. The change does not show that the underlying rate rose everywhere; it shows that reported rates depend on the period, sample, and detection methodology. See Darktrace’s full-year 2024 report.

So the accurate reading of the headline is: in Darktrace’s December 21, 2023–July 5, 2024 customer-fleet data, 62% of detected phishing emails bypassed DMARC checks. It is not a global estimate of how often phishing passes DMARC.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sophos XGS 88W (Gen2) Wireless Security Appliance with 1 Year Xstream Protection (XY88ZZ12ZZPCUS) | 4 x 2.5 GE Ports | Built-in Wi-Fi 6, SD-WAN, Secure VPN, Central Cloud Management
  • XGS 88W with 1 Year Xstream Protection - Next-generation firewall appliance with Xstream Protection subscription providing zero-day defense, cloud sandboxing, email filtering, intrusion prevention, and advanced reporting, managed through Sophos Central for unified policies and reporting.
  • Built in Wi Fi 6 with 4 x 2.5 GE copper ports, delivering up to 9.9 Gbps firewall performance for secure wired and wireless networks.
  • Zero day protection with cloud sandboxing, email filtering, and advanced reporting for full enterprise coverage.
  • TLS inspection and next generation intrusion prevention block hidden threats in encrypted traffic and stop sophisticated attacks.
  • Includes Xstream Protection – Advanced security bundle with zero-day protection, cloud sandboxing, email filtering, and automated threat response, providing full coverage against the most sophisticated cyberattacks.
Rank #4
Sophos XGS 108 (Gen2) Network Security Appliance with 1 Year Xstream Protection (XX108Z12ZZPCUS) | 6 x 2.5 GE Ports + 1 SFP | Next-Gen Protection, SD-WAN, Secure VPN, Centralized Management
  • XGS 108 with 1 Year Xstream Protection - Next-generation firewall appliance with Xstream Protection subscription providing zero-day defense, cloud sandboxing, email filtering, intrusion prevention, and advanced reporting, managed through Sophos Central for unified policies and reporting.
  • 6 x 2.5 GE copper ports and 1 SFP fiber port, supporting up to 12.5 Gbps firewall performance for growing business networks.
  • Zero day protection with cloud sandboxing, email filtering, and advanced reporting for full enterprise coverage.
  • TLS inspection and next generation intrusion prevention block hidden threats in encrypted traffic and stop sophisticated attacks.
  • Includes Xstream Protection – Advanced security bundle with zero-day protection, cloud sandboxing, email filtering, and automated threat response, providing full coverage against the most sophisticated cyberattacks.
Rank #3
Securing Email with Email Security Appliance Study Guide Flashcards
  • Pass the Securing Email with Email Security Appliance with updated flashcards packed with detailed content aligned to the latest exam blueprint. Cover all core topics without the overload found in lengthy study guides. Get 300+ Securing Email with Email Security Appliance flashcards on 8-1/2″ x 11″ perforated card stock.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.