82% of 2026 Campaign Domains Lack Email Fraud Protection

Four in five U.S. political campaign email domains are running without active DMARC enforcement as the 2026 midterms approach, leaving donors and voters exposed to impersonation scams that have already produced documented financial losses exceeding $2 million.
By Branka Narancic -
Wall of U.S. campaign yard signs with bold "82%" stat marking political campaign email security gap before 2026 midterms
  • DigiCert's 21 August 2026 DNS snapshot of 3,756 campaign domains found 82% lack DMARC enforcement, meaning email providers are not instructed to block or quarantine fraudulent messages sent under those campaign identities.
  • A full 38% of campaign domains have DMARC configured in monitoring-only mode (p=none), meaning the infrastructure exists but is deliberately set to allow unauthenticated mail through without interception.
  • Both major parties showed comparably low enforcement rates, confirming this is a structural gap across the entire campaign ecosystem rather than a partisan failing.
  • Documented losses tied to political email impersonation include a $29,000 wire fraud against a DNC staffer in February 2025 and approximately $2 million in straw-donor donations processed through ActBlue in the names of Connecticut residents.
  • DigiCert is offering free assisted DMARC enforcement to campaigns through its Valimail subsidiary, making cost an insufficient explanation for the gap and framing it as a prioritisation failure with a known, available fix.
Summarise with AI:

#

Four in five U.S. political campaign domains are sending email with no active defence against impersonation, and the 2026 midterms are now weeks away.

The finding comes from DigiCert, whose “The 2026 Election Trust Check” examined 3,756 campaign domains across all 50 states, using a DNS snapshot taken on 21 August 2026. It found that 82% of those domains lack the DMARC enforcement settings that tell email providers to block or quarantine messages fraudulently sent under a campaign’s official identity. The report arrives as donor and voter trust in digital communications is already strained by documented impersonation scams, straw-donor fraud, and a surge in election-adjacent domain registrations.

Here is what the data tells you about who is exposed, why attackers find campaign inboxes so valuable, and what you can do right now to make sure the next campaign email asking for your money or details is the real thing.

What DigiCert’s snapshot of 3,756 campaign domains actually found

The headline number is the one that travels: 82% of the 3,756 campaign domains DigiCert assessed as of 21 August 2026 were not enforcing DMARC, the standard that stops attackers from sending email under a campaign’s exact domain.

But the headline understates how close some of these campaigns came to being protected. Only 18% had reached an enforcement-level policy, meaning email providers were instructed to quarantine or reject messages that failed authentication.

The middle of the distribution is where the exposure becomes concrete. A full 38% of campaign domains had DMARC configured in monitoring-only mode, known as p=none. That setting watches unauthenticated email pass through and reports on it, but it instructs providers to do nothing. The infrastructure is in place; the door is still open.

That distinction matters for you as a reader trying to gauge the real risk. The 38% in monitoring-only mode are not campaigns that never heard of the standard. They are campaigns that started the work and stopped exactly at the point where nothing gets blocked.

DMARC policies come in three states, and the difference between them is entirely about what happens to a fraudulent message:

  • p=none (monitoring only): Email providers receive reports on suspicious messages but are told to take no action. The message still reaches the inbox.
  • p=quarantine: Messages that fail authentication are diverted to spam or held for review rather than delivered normally.
  • p=reject: Messages that fail authentication are refused at the mail server before they ever reach an inbox.

Both major parties showed comparably low enforcement rates, so this is not a story about one side lagging the other. It is a structural gap across the field.

Policy setting What it instructs email providers to do Share of campaign domains
p=none or no record Take no action on unauthenticated mail; message is delivered 82% (of which 38% are p=none)
p=quarantine / p=reject Divert or refuse unauthenticated mail before delivery 18%

DigiCert was careful about the limits of its own work. The assessment was a point-in-time snapshot of publicly visible DNS records, with no access to internal campaign systems and no confirmed spoofing incidents documented. It tells you how the front door is configured, not whether anyone has walked through it.

Why campaign domains are a high-value target, and why the gap persists

A campaign domain is not just a web address. It appears in the sender field of every fundraising email and every voter outreach message, which is exactly what makes it valuable to impersonate. Recognition is the whole point of a campaign brand, and recognition is precisely what an attacker borrows when they spoof it.

So the 82% figure is less about negligence than about structure. Campaigns are temporary organisations, built for a single cycle and dissolved afterward, which makes long-term investment in email infrastructure a hard sell against advertising and field organising.

They also operate without the forcing function that drove adoption elsewhere. CISA recommends a DMARC “reject” policy as the end-state for election-related email, but its binding directive, BOD 18-01, applies only to federal civilian executive branch agencies. It does not reach political campaigns, which means no regulator is compelling the fix.

The structural invisibility of government email security is a feature, not a flaw: the vendors holding ISM-compliant contracts with sovereign agencies rarely generate headlines precisely because the infrastructure is working, a dynamic that shapes how institutional cybersecurity investment is evaluated across jurisdictions.

Three structural reasons explain why campaigns consistently lag on this:

  1. Temporary organisational lifespan: A campaign that exists for months has little incentive to build permanent email security infrastructure.
  2. Limited budgets and competing priorities: Money and staff attention flow to fundraising, advertising, and turnout, leaving cyber hygiene as a secondary concern.
  3. Absence of a regulatory mandate: Unlike federal agencies or regulated industries, campaigns face no audit-driven pressure to reach enforcement.

For you as a donor or voter, the takeaway is uncomfortable but clear: this gap is unlikely to close before November, which means the burden of verification falls on the recipient, not the sender, in this cycle.

When weak authentication becomes a financial crime

The threat model here is not hypothetical. In February 2025, a former Democratic National Committee (DNC) staffer was tricked into wiring approximately $29,000 to a cybercriminal who impersonated newly appointed DNC Chairman Ken Martin through a fraudulent email, according to reporting by International Business Times published on 28 July 2026. Email impersonation of a senior political figure produced a direct, six-figure-adjacent loss.

The fraud extends to the fundraising layer too. In June 2025, Inside Investigator reported that cybersecurity professional Dominic Rapini identified roughly $2 million in donations processed through ActBlue in the names of 18 Connecticut residents, most of them elderly or retired, in a straw-donor scheme.

And the attack surface keeps expanding. Check Point and PBS NewsHour both reported in June 2026 on a surge in election-related domain registrations, which widens the pool of look-alike sites available for phishing, fraudulent donation pages, and candidate impersonation.

Election Integrity Partnership research, produced in collaboration with the Stanford Internet Observatory, documented the systematic nature of online interference campaigns targeting U.S. elections, establishing the broader threat landscape within which email impersonation and fraudulent domain registrations operate.

What donors and voters can do before the next campaign email arrives

When authentication is absent at the sender level, the verification burden shifts to you. That is the core principle to carry into this cycle: direct navigation and independent confirmation are the strongest defences available to a recipient right now.

Here are five concrete steps to apply the next time a campaign email lands:

  1. Navigate directly rather than clicking. Type the campaign’s official web address into your browser or reach it through a trusted search result instead of following a link in an email or social post.
  2. Verify the domain name and spelling. Check that the sending domain matches the well-known official one, character for character. Attackers rely on slight variations and plausible-looking substitutes.
  3. Treat unsolicited donation requests with caution at the platform level. Confirm that fundraising links originate from official campaign communications, not from an unexpected email, and review receipts and statements for anomalies.
  4. Use urgency as a verification trigger. Any unexpected request for a large transfer or urgent donation, especially one claiming to come from a senior official, should be confirmed through a separate channel such as a known campaign office number before you act.
  5. Understand what authentication does not cover. DMARC stops spoofing of a campaign’s exact domain. It does not stop look-alike domains or messages sent from a compromised account.

CISA’s own guidance for organisations, published 8 June 2025, recommends implementing SPF, DKIM, and DMARC and monitoring DMARC reports to catch apparent forgeries. On the sender side, DigiCert is offering free assisted DMARC enforcement to campaigns through its Valimail subsidiary, which gives some sense of what a fix would look like if campaigns choose to act before election day.

For this cycle, skepticism and direct verification are the correct posture for any campaign email that asks for your money or personal information.

Where the fix sits, and whether campaigns will reach it before November

The accountability splits cleanly into two tracks, and knowing which is which sharpens how you should read the 82% figure.

  • What donors and voters should do now: Carry the verification burden. Navigate directly, check domains, and confirm unusual requests through a separate channel, because sender-side protection will not be universal this cycle.
  • What campaigns and vendors need to do before the next cycle: Reach enforcement-level DMARC. With DigiCert offering free assisted enforcement through Valimail, cost is not the barrier.

That last point reframes the whole story. The 18% of campaign domains that have already reached enforcement prove the solution works within campaign structures. The gap is a prioritisation problem, not a technical impossibility, which shifts the question from “can this be fixed” to “will it be fixed in time.”

The wider context tells you why it persists. Federal agencies are bound by BOD 18-01, and regulated industries face audit-driven pressure, while campaigns have neither. CISA still positions a “reject” policy as the baseline end-state for any domain sending mail, not a stretch goal.

If you follow financial markets or work in a regulated field, you will recognise these as the same baseline email authentication controls applied to corporate and institutional communications. This is a digital-trust infrastructure story that happens to be playing out on the ballot, with a snapshot dated 21 August 2026 and a report released 22 September 2026 establishing just how current the gap is.

This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions.

Frequently Asked Questions

What is DMARC and why does it matter for political campaign email security?

DMARC is an email authentication standard that instructs mail providers to quarantine or reject messages fraudulently sent under a domain's identity. Without enforcement-level DMARC, anyone can spoof a campaign's official email address and send convincing fundraising or voter outreach messages that reach inboxes unchallenged.

How many U.S. campaign domains lack email authentication in 2026?

DigiCert's snapshot of 3,756 campaign domains taken on 21 August 2026 found that 82% were not enforcing DMARC, meaning the vast majority of campaign emails sent this cycle carry no active protection against impersonation.

What real-world fraud has resulted from weak political campaign email security?

In February 2025, a DNC staffer was tricked into wiring approximately $29,000 to a cybercriminal impersonating DNC Chairman Ken Martin via a spoofed email, and a separate scheme processed roughly $2 million in fraudulent ActBlue donations in the names of 18 Connecticut residents.

How can donors verify a political campaign email is legitimate before donating?

Navigate directly to the campaign's official website by typing the address into your browser rather than clicking email links, confirm the sending domain matches the known official one character for character, and verify any large or urgent transfer requests through a separate channel such as a known campaign phone number.

Why are political campaigns allowed to operate without mandatory email security standards?

CISA's binding directive BOD 18-01, which compels federal civilian executive branch agencies to reach DMARC enforcement, does not apply to political campaigns, and no equivalent regulatory mandate exists for them, leaving adoption entirely voluntary.

Branka Narancic
By Branka Narancic
Client Success Manager
Branka Narancic is Client Success Manager at StockWireX and Discovery Alert, and an active contributor to the News sections on both platforms, bringing more than a decade of experience across financial journalism, capital markets communications, and investor engagement. A founding contributor and former Editor of Companies and Markets at The Market Herald, she combines deep ASX market knowledge with a commercially focused approach to client success.
Learn More

Breaking ASX Alerts Direct to Your Inbox

Join +20,000 subscribers receiving alerts.

Join thousands of investors who rely on StockWire X for timely, accurate market intelligence.

About the Publisher