DMARC Reject: The Policy Everyone Tests, Only 25% Enforce

Aotearoa New Zealand government mandates around DMARC are forcing agencies to act, but the struggle to enforce reject is hardly limited to the public sector. In my own work with medium and large enterprises, I have seen the same hesitation: once enforcement disrupts mail flow with partners or vendors, it is quickly rolled back. Proofpoint’s figure that only 25% of organisations enforce reject mirrors what I’ve observed in the field. The technology is straightforward, but the organisational tolerance for disruption is not.

Read More

When Familiar Names are Phishing?

This post breaks down a real phishing attempt that targeted ITP NZ members using a spoofed display name. It wasn’t a compromised account, but a crafted message designed to exploit familiarity and provoke a reply. By unpacking how this tactic works and what subtle signals gave it away, we hope to sharpen member awareness, encourage better reporting practices, and help readers think like an adversary. If you receive something suspicious, please send it as an attachment to info@itp.nz so the headers can be analysed properly.

Read More