Domain-based Message Authentication, Reporting, and Conformance (DMARC) is just one piece of the email security puzzle. Why DMARC cannot stop every healthcare impersonation attack. In Paubox’s 2026 Healthcare Email Security Report, 170 email-related healthcare breaches in 2025 were analyzed. Among the breached organizations analyzed, 74% either lacked DMARC or used it for monitoring only. Attackers can still circumvent the protections DMARC provides to impersonate healthcare providers. It is why healthcare organizations must enforce DMARC as part of HIPAA compliant email, advanced inbound filtering, security awareness training, and verification requirements.

 

DMARC in email

DMARC allows domain owners to tell receiving servers how to handle mail that fails authentication checks. It builds on two previous email authentication standards, namely Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM). SPF checks to see if a mail server is authorized to send email on behalf of a domain. DKIM adds a cryptographic signature to verify that the domain also authenticated the message itself.

DMARC adds a requirement for alignment. The domain that passes SPF or DKIM must match, or align with, the domain displayed in the From address of an email. If a hacker attempts to send an email from what appears to be billing@hospital.org, DMARC can help the receiving server determine if the sending server was authorized to send mail from hospital.org. Healthcare organizations can pair DMARC with HIPAA compliant email to authenticate their legitimate domains while protecting messages that contain PHI with encryption. The combination strengthens trust in legitimate communications, and sensitive information will be more difficult for attackers to steal while it’s in transit.

In May 2026, the Internet Engineering Task Force published RFC 9989, which replaced the original DMARC STD with an updated document. The replacement includes several adjustments to technical specifications and reporting procedures but maintains DMARC’s purpose of preventing unauthorized use of an email’s author domain.

 

How DMARC protects a healthcare domain

A healthcare organization will usually start with a p=none policy to identify all systems that should be authorized to send email on their behalf. These systems may include appointment reminder services, billing software, third-party labs, patient engagement platforms, email marketing vendors, and electronic health records. Once an organization has identified and approved its legitimate sending sources, it can correct any legitimate authentication issues and move confidently toward enforcement.

Attackers can still use lookalike domains to get around exact domain rejection policies. Setting a policy of reject affords the greatest protection against someone sending mail from hospital.org, but compliant receivers ultimately decide how to process a message that fails DMARC. RFC 9989 clarifies that DMARC is intended to be considered as one factor within a larger filtering decision, not an explicit instruction on whether to deliver a message.

 

Phishing email continues to target the healthcare industry

Attackers can create lookalike domains

Also known as cousin domains, lookalike domains closely resemble a legitimate domain without being exact matches. Attackers may register hospita1.org, hospital.biz, hospitalsecurity.org, or hospital.anything.org.

Legitimate organizations cannot control the actions of any domain registrar aside from their own. If an attacker registered one of the examples above, the hospital whose domain was mimicked would have no way to prevent their impersonator from publishing legitimate email authentication records. Additional inbox filters can consider domain reputation, domain age, and common links between domains in addition to authentication procedures. Paired with HIPAA compliant email, healthcare providers can remind patients and caregivers what their official email address is, how payment requests should be handled, and how to recognize their established phone numbers. If a patient receives a message asking for payment, they can reference previous HIPAA compliant emails to verify whether the request is legitimate.

 

Attackers can spoof display names

Display name spoofing changes the From address to display a trusted individual or department. A message may appear to come from “Dr. Sarah Adams” or “Hospital Payroll” while the actual email address behind the display name belongs to someone unrelated. DMARC only checks to see if the domain used in the From address is authentic. RFC 9989 acknowledges that attacks like lookalike domains and spoofed display names are outside the intended scope of DMARC.

When authenticating messages, healthcare organizations can configure identity-protect that cross references employee names and known department names with approved email addresses. Paubox ExecProtect+ protects organizational users from display name impersonation and quarantines messages received from unapproved addresses even if the displayed name is protected.

 

Attackers can take over legitimate accounts

Attackers with access to a legitimate mailbox can send messages through that mailbox’ s authorized email ecosystem. SPF, DKIM, and DMARC authentication may pass because the email is coming from an approved domain. The same concept applies if an attacker compromises an authorized vendor, laboratory, insurer, or business associate account. The email will come from the domain the recipient expects to see and may reference previous conversations between the business and the compromised party. Again, DMARC alone cannot tell hospitals or providers when an authorized email domain is being misused.

RFC 9989 states, “A DMARC pass by itself does not guarantee that delivery to the recipient's inbox would be safe or desirable.” In addition to authenticating messages, organizations should monitor for anomalies in sender behavior, recipient addresses, email language, links, attachments, and requested actions.

Providers can require additional verification for any requests involving PHI, payment information, login credentials, or modifications to patient or vendor records. When in doubt, verify through a known phone number or set workflow that can’t be manipulated by redirecting customers through the email message itself.

 

Attackers can send malicious messages from authorized domains

DMARC does not define what constitutes a suspicious or malicious message. SPF, DKIM, and DMARC cannot analyze the message content to determine if it contains malware, scams, phishing links, a fraudulent invoice, or a request to divulge sensitive information. An attacker can compromise a domain or set up a domain mimic and send a malicious message from an authorized domain under their control. That message can pass DMARC checks and still cause patients to visit a forged Microsoft 365 login page or trick employees into disabling security tools.

HIPAA compliant email can protect legitimate PHI while it travels across networks. Healthcare organizations can reduce the risk of successful phishing and impersonation by implementing advanced inbound security measures like link checking, attachment sandboxing, malware detection, and automated security training.

 

Attackers can also try impersonating providers over SMS, voice, and collaboration tools

SMS and voice phishing are known as smishing and vishing, respectively. Collaboration applications like Microsoft Teams can also be abused by attackers. According to current phishing guidance published by CISA, message recipients should not call or click if they think a message might be genuine but contains odd elements. Contacts should establish verified communication channels with patients, relatives, and staff through normal business channels like HIPAA compliant email.

 

Why healthcare needs layered email security

Healthcare environments are busy. Providers are accustomed to receiving messages from patients about prescription refills, test results, appointment updates, bill payments, and more at a rapid rate.

According to a study on hospital phishing published by the Journal of Medical Internet Research, workload was cited as a factor that could increase the chance of hospital employees clicking phishing links. The study’s authors used surveys and simulations to conclude that once workers make the decision to comply with a request, “Intention and compliance might not be as strongly linked as previously assumed.”

Employees should not be the last line of defense between a hacker and protected health information (PHI). Technology can help screen messages for authentication failures, abnormal sender activity, suspicious links, known malware attachments, risky language, and deviations from typical sender behavior.

In February 2026, HHS’ Office for Civil Rights announced a HIPAA settlement involving a successful phishing attack. The attack allowed a hacker to obtain remote access to a workforce member’ s email account and ePHI for 1,980 patients. During its investigation, OCR also found evidence that the healthcare organization “had not conducted an accurate and thorough risk analysis.”

While we do not know if DMARC was implemented or if any DMARC failures contributed to this breach, the OCR case shows that even validated account access can lead to ePHI exposure. Risk analyses should cover email as both a source of threat and a mechanism for preventing data loss. Later in 2026, OCR reached four more settlements involving breaches impacting over 427,000 individuals. All impacted healthcare organizations. OCR recommended that they update their risk analyses, complete risk management processes, implement device authentication and auditing, encrypt ePHI when appropriate, improve security measures post-incident, and provide annual HIPAA training.

 

Healthcare email threats keep evolving. Make sure your security controls do too.

Healthcare organizations should implement DMARC if they have not already. Set a policy of none and work with internal teams to establish which servers and partners should legitimately send mail from the organization’s domain. Review DMARC reports for unknown sending sources and alignment issues.

Use DMARC and other HIPAA compliance tools in conjunction with display name protection, behavioral analysis, link and attachment protection, multifactor authentication, and security awareness training. Verify high-risk requests through an established communication channel that attackers can’t influence.

Organizations can protect their risk analyses by explaining why domain authentication alone cannot prevent data breaches. Healthcare organizations are required by the HIPAA Security Rule to identify potential risks and apply reasonable and appropriate safeguards. The Security Rule does not set out which email security technologies should be used. Medical practices and hospitals can use HIPAA compliant email to protect PHI in transit. Healthcare encrypts outbound messages containing PHI without adding complexity for patients and staff. Advanced inbound filtering can help catch the impersonation attacks DMARC was never designed to stop.

 

FAQs

Can DMARC stop an attacker from using a lookalike hospital domain?

No, a hospital’s DMARC policy cannot control a separate domain registered by an attacker, even when that domain closely resembles the hospital’s name.

 

Why can an email from a compromised vendor pass DMARC?

The message may pass because the attacker is using the vendor’s genuine account and authorized sending infrastructure, which requires behavioral and contextual analysis beyond domain authentication.

 

Does HIPAA specifically require DMARC?

No, the current HIPAA Security Rule does not require DMARC by name. It requires regulated entities to assess their risks and implement reasonable and appropriate safeguards based on their environment.