#
Four in five U.S. political campaign domains are sending email with no active defence against impersonation, and the 2026 midterms are now weeks away.
The finding comes from DigiCert, whose “The 2026 Election Trust Check” examined 3,756 campaign domains across all 50 states, using a DNS snapshot taken on 21 August 2026. It found that 82% of those domains lack the DMARC enforcement settings that tell email providers to block or quarantine messages fraudulently sent under a campaign’s official identity. The report arrives as donor and voter trust in digital communications is already strained by documented impersonation scams, straw-donor fraud, and a surge in election-adjacent domain registrations.
Here is what the data tells you about who is exposed, why attackers find campaign inboxes so valuable, and what you can do right now to make sure the next campaign email asking for your money or details is the real thing.
What DigiCert’s snapshot of 3,756 campaign domains actually found
The headline number is the one that travels: 82% of the 3,756 campaign domains DigiCert assessed as of 21 August 2026 were not enforcing DMARC, the standard that stops attackers from sending email under a campaign’s exact domain.
But the headline understates how close some of these campaigns came to being protected. Only 18% had reached an enforcement-level policy, meaning email providers were instructed to quarantine or reject messages that failed authentication.
The middle of the distribution is where the exposure becomes concrete. A full 38% of campaign domains had DMARC configured in monitoring-only mode, known as p=none. That setting watches unauthenticated email pass through and reports on it, but it instructs providers to do nothing. The infrastructure is in place; the door is still open.
That distinction matters for you as a reader trying to gauge the real risk. The 38% in monitoring-only mode are not campaigns that never heard of the standard. They are campaigns that started the work and stopped exactly at the point where nothing gets blocked.
DMARC policies come in three states, and the difference between them is entirely about what happens to a fraudulent message:
- p=none (monitoring only): Email providers receive reports on suspicious messages but are told to take no action. The message still reaches the inbox.
- p=quarantine: Messages that fail authentication are diverted to spam or held for review rather than delivered normally.
- p=reject: Messages that fail authentication are refused at the mail server before they ever reach an inbox.
Both major parties showed comparably low enforcement rates, so this is not a story about one side lagging the other. It is a structural gap across the field.
| Policy setting | What it instructs email providers to do | Share of campaign domains |
|---|---|---|
| p=none or no record | Take no action on unauthenticated mail; message is delivered | 82% (of which 38% are p=none) |
| p=quarantine / p=reject | Divert or refuse unauthenticated mail before delivery | 18% |
DigiCert was careful about the limits of its own work. The assessment was a point-in-time snapshot of publicly visible DNS records, with no access to internal campaign systems and no confirmed spoofing incidents documented. It tells you how the front door is configured, not whether anyone has walked through it.
When big ASX news breaks, our subscribers know first
Why campaign domains are a high-value target, and why the gap persists
A campaign domain is not just a web address. It appears in the sender field of every fundraising email and every voter outreach message, which is exactly what makes it valuable to impersonate. Recognition is the whole point of a campaign brand, and recognition is precisely what an attacker borrows when they spoof it.
So the 82% figure is less about negligence than about structure. Campaigns are temporary organisations, built for a single cycle and dissolved afterward, which makes long-term investment in email infrastructure a hard sell against advertising and field organising.
They also operate without the forcing function that drove adoption elsewhere. CISA recommends a DMARC “reject” policy as the end-state for election-related email, but its binding directive, BOD 18-01, applies only to federal civilian executive branch agencies. It does not reach political campaigns, which means no regulator is compelling the fix.
The structural invisibility of government email security is a feature, not a flaw: the vendors holding ISM-compliant contracts with sovereign agencies rarely generate headlines precisely because the infrastructure is working, a dynamic that shapes how institutional cybersecurity investment is evaluated across jurisdictions.
Three structural reasons explain why campaigns consistently lag on this:
- Temporary organisational lifespan: A campaign that exists for months has little incentive to build permanent email security infrastructure.
- Limited budgets and competing priorities: Money and staff attention flow to fundraising, advertising, and turnout, leaving cyber hygiene as a secondary concern.
- Absence of a regulatory mandate: Unlike federal agencies or regulated industries, campaigns face no audit-driven pressure to reach enforcement.
For you as a donor or voter, the takeaway is uncomfortable but clear: this gap is unlikely to close before November, which means the burden of verification falls on the recipient, not the sender, in this cycle.
When weak authentication becomes a financial crime
The threat model here is not hypothetical. In February 2025, a former Democratic National Committee (DNC) staffer was tricked into wiring approximately $29,000 to a cybercriminal who impersonated newly appointed DNC Chairman Ken Martin through a fraudulent email, according to reporting by International Business Times published on 28 July 2026. Email impersonation of a senior political figure produced a direct, six-figure-adjacent loss.
The fraud extends to the fundraising layer too. In June 2025, Inside Investigator reported that cybersecurity professional Dominic Rapini identified roughly $2 million in donations processed through ActBlue in the names of 18 Connecticut residents, most of them elderly or retired, in a straw-donor scheme.
And the attack surface keeps expanding. Check Point and PBS NewsHour both reported in June 2026 on a surge in election-related domain registrations, which widens the pool of look-alike sites available for phishing, fraudulent donation pages, and candidate impersonation.
Election Integrity Partnership research, produced in collaboration with the Stanford Internet Observatory, documented the systematic nature of online interference campaigns targeting U.S. elections, establishing the broader threat landscape within which email impersonation and fraudulent domain registrations operate.
What donors and voters can do before the next campaign email arrives
When authentication is absent at the sender level, the verification burden shifts to you. That is the core principle to carry into this cycle: direct navigation and independent confirmation are the strongest defences available to a recipient right now.
Here are five concrete steps to apply the next time a campaign email lands:
- Navigate directly rather than clicking. Type the campaign’s official web address into your browser or reach it through a trusted search result instead of following a link in an email or social post.
- Verify the domain name and spelling. Check that the sending domain matches the well-known official one, character for character. Attackers rely on slight variations and plausible-looking substitutes.
- Treat unsolicited donation requests with caution at the platform level. Confirm that fundraising links originate from official campaign communications, not from an unexpected email, and review receipts and statements for anomalies.
- Use urgency as a verification trigger. Any unexpected request for a large transfer or urgent donation, especially one claiming to come from a senior official, should be confirmed through a separate channel such as a known campaign office number before you act.
- Understand what authentication does not cover. DMARC stops spoofing of a campaign’s exact domain. It does not stop look-alike domains or messages sent from a compromised account.
CISA’s own guidance for organisations, published 8 June 2025, recommends implementing SPF, DKIM, and DMARC and monitoring DMARC reports to catch apparent forgeries. On the sender side, DigiCert is offering free assisted DMARC enforcement to campaigns through its Valimail subsidiary, which gives some sense of what a fix would look like if campaigns choose to act before election day.
For this cycle, skepticism and direct verification are the correct posture for any campaign email that asks for your money or personal information.
Where the fix sits, and whether campaigns will reach it before November
The accountability splits cleanly into two tracks, and knowing which is which sharpens how you should read the 82% figure.
- What donors and voters should do now: Carry the verification burden. Navigate directly, check domains, and confirm unusual requests through a separate channel, because sender-side protection will not be universal this cycle.
- What campaigns and vendors need to do before the next cycle: Reach enforcement-level DMARC. With DigiCert offering free assisted enforcement through Valimail, cost is not the barrier.
That last point reframes the whole story. The 18% of campaign domains that have already reached enforcement prove the solution works within campaign structures. The gap is a prioritisation problem, not a technical impossibility, which shifts the question from “can this be fixed” to “will it be fixed in time.”
The wider context tells you why it persists. Federal agencies are bound by BOD 18-01, and regulated industries face audit-driven pressure, while campaigns have neither. CISA still positions a “reject” policy as the baseline end-state for any domain sending mail, not a stretch goal.
If you follow financial markets or work in a regulated field, you will recognise these as the same baseline email authentication controls applied to corporate and institutional communications. This is a digital-trust infrastructure story that happens to be playing out on the ballot, with a snapshot dated 21 August 2026 and a report released 22 September 2026 establishing just how current the gap is.
This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions.