Most U.S. Campaign Domains Lacked Email Protections
An analysis of thousands of political domains shows that over 80% fail to implement standard anti-spoofing protocols.
Updated on Sept. 22, 2026 in Cybersecurity

Live Poll
Do you trust political campaigns to adequately protect your personal data and digital communication?
An analysis by DigiCert has revealed that 82% of 3,756 political campaign domains across the United States lack essential email authentication protections. This research highlights a systemic vulnerability in the digital infrastructure used for voter outreach, fundraising, and recruitment.
Why it matters
The widespread failure to secure these channels increases the risk of successful phishing attacks and domain spoofing that could undermine voter trust. Security professionals are concerned that these gaps in campaign communications could be exploited as election cycles intensify.
The study evaluated the usage of DMARC—Domain-based Message Authentication, Reporting and Conformance—which allows domain owners to specify how receivers should handle unauthorized email. The analysis found that current enforcement rates are critically low across both major U.S. political parties.
The players
DigiCert
A Lehi, Utah-based provider of digital trust and certificate management services for enterprise network security.
The details
The research identified vulnerabilities by reviewing publicly available email-authentication records across domains in all 50 states. DMARC serves as an email-authentication protocol that uses SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) to block or quarantine fraudulent emails before they reach a user's inbox. When DMARC is not enforced, attackers can more easily impersonate campaign officials to harvest sensitive donor data or send misleading information to voters.
Timeline
September 22, 2026: DigiCert released the Election Trust Check analysis.
The Tech Race
This research follows a growing pattern of cybersecurity audits targeting high-stakes infrastructure ahead of critical election windows. The data serves as a diagnostic benchmark for the political sector, which currently lags behind the private industry standards for verifiable email authentication.
Voters and donors remain vulnerable to sophisticated spoofing attacks until campaigns implement these standard authentication controls. Users should verify the legitimacy of high-priority fundraising or recruitment links by checking sender addresses against official verified campaign portals.
The takeaway
Campaign security remains a critical, unresolved risk factor as the digital reliance of political organizations outpaces their adoption of basic authentication standards. Stakeholders should track future policy mandates that might require political entities to meet minimum cybersecurity baseline requirements for public-facing infrastructure.
Further reading
For more context on how organizations protect their communications infrastructure, visit Cybersecurity.
Source note: This article includes information reported by Owensboro Messenger-Inquirer.
Live Poll
Do you trust political campaigns to adequately protect your personal data and digital communication?









