Blog article
Threat actors are engineering lures that blend into the exact tools and workflows employees already trust, calibrating each attempt to a target’s software stack, industry, and role. Generative AI has only sharpened that precision: attackers can generate a unique, personalized email in seconds, and a defense built to match known signatures has nothing left to match against.
That shift is why security teams aren’t asking which point solution to bolt on next. They’re asking whether their entire email architecture can hold up against today’s attacks that are personalized and novel. A legacy Secure Email Gateway (SEG) built for signature-based defense can’t answer that question.
SEG replacement decisions rarely stay limited to employees’ inboxes.
Most SEG replacement projects focus on what enters and leaves the inbox: inbound defense against phishing and BEC, and outbound monitoring for sensitive data. That focus is necessary, but it leaves an entirely different attack surface unaddressed.
Cybercriminals don’t only target employees inside a business. They impersonate the company itself, using its domain to deceive customers, suppliers, and partners. Without DMARC enforcement in place, unauthenticated emails sent from your domain reach inboxes unchallenged – and your brand carries the liability.
Most organizations address half of the problem. Find out how Abnormal and Sendmarc deliver protection across your entire email environment.
SEGs inspect email flowing through your business’s infrastructure, filtering threats arriving in employee inboxes and scanning outbound messages for policy violations. DMARC governs who’s authorized to send email from your domain.
A threat actor spoofing your domain doesn’t send through your SEG. They send independently, from their own infrastructure, using your domain to target your customers, suppliers, and partners. No SEG inspects that email, because it never touches your infrastructure in the first place.
Some SEG vendors offer DMARC capability alongside their core platform. But having the capability and reaching full enforcement – a DMARC policy of p=reject – are different outcomes. Without DMARC enforcement, unauthenticated emails sent from your domain can still reach recipients. Customers receive fraudulent invoices. Suppliers act on fake payment instructions. Investors are targeted using your brand identity.
There is a second gap that compounds this. Many enterprises don’t have full visibility into who’s sending email on their behalf. Marketing platforms, HR tools, finance systems, and departmental SaaS applications all send emails using the corporate domain, often without centralized oversight or authentication configuration.
When those senders aren’t identified and configured correctly, they introduce SPF and DKIM failures that leave the domain exposed and disrupt legitimate communications.
Enterprises often begin their DMARC journey with a p=none policy to gain visibility into who’s sending email on their behalf. That visibility is valuable, but reaching enforcement across every sender, especially ones that are hard to identify and slow to configure, is where most companies stall. Visibility isn’t protection. Knowing what the problem is and stopping it are two different things.
Abnormal and Sendmarc are built for different parts of the email security problem. Together, they deliver broader coverage than either provides alone.
Abnormal is the behavioral AI platform that protects enterprises by understanding normal behavior across every user, vendor, and interaction connected to your organization. When anything deviates from normal, whether an attack, compromise, or risk, Abnormal catches it automatically.
It detects advanced attacks, such as executive impersonation and vendor fraud attempts, that show no known malicious indicators, threats that signature-based filters miss because they’ve never been seen before.
Additionally, Abnormal transforms real email attacks into personalized phishing simulations, just-in-time AI coaching, and AI-generated phishing training that continuously adapts to human risk. It also finds misconfigurations in Microsoft 365 before attackers exploit them, scoring risks against industry benchmarks and real-world attack patterns found across its customer base.
Abnormal also stops accidental data loss by using behavioral AI to detect misaddressed emails and misattached files, quarantining them for sender review before delivery.
Sendmarc protects the people outside your business: your customers, suppliers, partners, and investors, who have no way to verify whether the email they received actually came from you.
It provides DMARC management and gives IT teams unified visibility into every sender using the corporate domain – identifying unauthorized sources, surfacing shadow IT that breaks authentication, and centralizing SPF, DKIM, and DMARC governance across departments, regions, and domains.
Beyond authentication, Sendmarc helps enterprises build a more resilient email ecosystem. MTA-STS and TLS-RPT help secure email in transit and provide visibility into transport security issues, while BIMI enables verified brand logos to appear in supporting inboxes once authentication requirements are met.
Sendmarc also provides lookalike domain monitoring, which identifies domains registered to impersonate your brand before they can be used in phishing campaigns, and a leaked credential detection solution that alerts teams when corporate credentials are exposed in known data breaches so they can respond quickly.
DMARC enforcement is no longer optional for companies sending email at scale.
Google and Yahoo introduced sender authentication requirements for bulk senders in 2024, mandating SPF, DKIM, and DMARC alignment. Microsoft followed with similar requirements for high-volume senders. Organizations that don’t meet these requirements risk having their email rejected or routed to Spam or Junk folders by receiving servers – disrupting billing, notifications, and other critical communications.
Regulatory frameworks are moving in the same direction.
PCI DSS v4.0 includes anti-phishing controls as part of its requirements. GDPR, POPIA, ISO 27001, and NIST frameworks increasingly reference domain authentication as a baseline security expectation. Cyber insurance underwriters are asking about DMARC enforcement, with many requiring evidence of authentication controls as a condition of coverage.
Boards and audit committees are asking the same questions.
The Sendmarc Platform supports compliance evidence requirements with audit-ready DMARC reporting, surfaced through a centralized dashboard. Security teams can demonstrate enforcement status, sender visibility, and policy coverage across all domains and regions – without assembling that evidence manually before each review cycle.
The DMARC compliance certificate from Sendmarc provides verifiable, third-party confirmation of enforcement status for stakeholders who need more than a screenshot.
Businesses using both Abnormal and Sendmarc gain more than full perimeter coverage: they gain visibility into vendor risk without switching between platforms.
The Sendmarc integration helps security teams identify vendors that may be vulnerable to domain impersonation because they have missing or unenforced DMARC policies, and it highlights vendors showing signs of potential account compromise, so teams can prioritize higher-risk relationships and respond sooner.
By combining Abnormal’s behavioral AI with Sendmarc’s domain authentication insights, security teams gain a more complete view of vendor email risk right inside the Sendmarc platform, which reduces manual investigation and speeds up third-party risk decisions.
That same principle holds across the entire email perimeter.
Inbox protection without domain authentication leaves the domain exposed. Domain authentication without inbox protection leaves employees exposed.
Attackers exploit inbound vectors to compromise employees, and they exploit the absence of domain authentication to impersonate organizations and defraud the people who trust them. Addressing one without the other leaves a gap that’s straightforward for attackers to find and use.
Abnormal and Sendmarc close both gaps together: inbound threat detection and domain authentication configuration, with p=reject continuous protection.
Security and IT teams get the coverage they need without increasing operational burden, and customers, suppliers, and partners get assurance that the email from your domain is the email you actually sent.
For companies replacing legacy SEGs, this is the moment to close every gap, not just the most visible one.
Learn more about the Abnormal and Sendmarc solution.