Proofpoint warns AI is widening email security gaps at India's largest companies

The company says enterprises have adopted email authentication, but incomplete enforcement continues to leave organisations exposed to AI-powered phishing and brand impersonation attacks.

Futuristic illustration of glowing email icons flying through a binary data tunnel, symbolizing fast digital communication, data transfer, and secure online messaging systems.

Proofpoint has warned that advanced AI tools are making phishing and email impersonation attacks more convincing and scalable, while many of India's largest enterprises have yet to enforce the strongest DMARC email authentication policy to stop such threats.

According to the cybersecurity company's latest analysis of the Fortune India 100 companies, two in five organisations do not enforce the strictest Domain-based Message Authentication, Reporting and Conformance (DMARC) policy, leaving customers, employees and business partners at greater risk of email fraud and domain impersonation.

The findings come as enterprises continue to face a growing number of phishing and business email compromise (BEC) attacks, with AI enabling cybercriminals to generate more convincing emails, automate phishing campaigns and impersonate trusted organisations at scale.

Proofpoint found that email authentication adoption among India's largest companies is already widespread.

Around 97 percent of the Fortune India 100 companies have implemented DMARC, an email authentication standard that helps verify whether emails originate from authorised domains and prevents attackers from spoofing legitimate organisations.

However, the company said implementation alone does not provide complete protection.

Among the organisations analysed, 59 percent have implemented the recommended "Reject" policy, which blocks unauthorised emails before they reach users' inboxes.

Another 32 percent continue to use the less restrictive "Quarantine" policy, while six percent remain at the "Monitor" stage.

According to Proofpoint, this means 41 percent of India's largest companies have not yet enforced the strongest level of protection against email spoofing.

AI increases phishing and impersonation risks

Proofpoint said the findings come at a time when AI is accelerating both the speed and sophistication of phishing attacks.

Advanced AI tools allow attackers to automate phishing campaigns, create more convincing impersonation emails and exploit trusted corporate brands more effectively than before.

Official data from India's Ministry of Home Affairs also showed cybercrime increased 24 percent during 2025, with authorities attributing the rise to increasingly sophisticated technologies being used for phishing and identity theft.

Proofpoint’s India country manager, Bikramdeep Singh, said India's largest enterprises have become attractive targets because of the trust customers place in their brands.

"India's largest enterprises are among the most trusted names in the country's digital economy, and that trust is precisely what makes them attractive targets for cybercriminals," Singh said.

He added that while many organisations have made progress in protecting their email communications, gaps in enforcement continue to create opportunities for attackers.

"In today's threat landscape, where AI is enabling threat actors to impersonate trusted brands at a scale and speed we've never seen before, closing those gaps isn't optional," Singh said.

He said enforcing the strongest DMARC policy remains one of the most effective steps organisations can take to protect customers, employees and corporate reputation.

Email remains a key attack vector

Despite growing investment in AI security, identity protection and cloud security, email continues to be one of the most common entry points for cyberattacks.

Business email compromise, phishing and domain spoofing remain widely used techniques for stealing credentials, committing financial fraud and gaining initial access to enterprise environments.

Proofpoint said organisations should continue strengthening email authentication while encouraging employees and customers to verify suspicious communications, avoid responding to unexpected credential requests and adopt phishing-resistant multi-factor authentication technologies such as passkeys.

The company said that as AI continues to reshape the cyber threat landscape, closing remaining email authentication gaps will become important in protecting enterprise communications and maintaining customer trust.