Charity industry
Overview
The charity industry is one of the least protected industries when it comes to cyberattacks. Charity organisations handle large sums of donations and the respective data of their various donors. This makes them the prime prey for attackers.
Cyberattackers take advantage of insecure charity websites and organisations and steal millions in money and data. Amid the pandemic, it became a trend for cyberattackers to hack into the systems of charity organisations since people were going above and beyond to donate during the tough times.
One of the prime examples of a cyberattack on a charity organization is the recent case of spoofing. In 2020, cybercriminals spoofed the World Health Organization’s (WHO) domain, sending thousands of fake emails asking recipients worldwide for donations for coronavirus relief.
A study sample of 78,000 charity websites in the UK found that less than 1% of them were protected against spoofing and phishing. Moreover, a global study of NPOs and NGOs found similar results. In Canada, 95% of NPOs have no DMARC policy in place, followed by Australia (92%), and the U.S. (91%).
Hackers and cyberattackers are aware of the vulnerabilities of this industry; hence, it is of utmost importance that we work towards making the charity industry DMARC compliant.

Charity Industry Data Breaches Stats
- Data provided by the DCMS cybersecurity survey shows that 26% of charities have identified or prevented cyberattacks, including phishing and spoofing.
- 50% of the charities have at least three exposure points.

Charity Industry DMARC Adoption
A report by 250ok revealed that non-profit organizations saw the lowest percent of DMARC adoption, with 94.2% in the US having no DMARC compliance in place, closely followed by the UK nonprofits and charities, where 92.7% had no DMARC protection.
Another report by OnDMARC showed that fewer than 1% of UK charities had implemented some sort of email cybersecurity. Moreover, only 16% of the those that have implemented it, set it up to reject unauthorized emails.
How Can DMARC Help?
DMARC (Domain-Based Message Authentication, Reporting, and Conformance) is an email authentication standard or protocol that determines whether an email is authentic or not. It relies on SPF and DKIM, two other protocols, to decide the authentication status of an email.
For detailed information, read more on What is DMARC?
DMARC is essential to the charity industry since the industry receives huge sums of money in the form of donations and is always on the radar of cyber attackers. DMARC ensures that the industry isn’t monetarily harmed by spoofing attacks and phishing scams by providing visibility of an email’s original source. The donors, therefore, cannot be tricked into donating money to the attackers instead of the charity organization.
You can set up DMARC on your domain using EmailAuth’s DMARC Record Generator. The EmailAuth dashboard completely automates the DMARC setup process, making it easier to choose who is allowed to send emails on your domain’s behalf and keep track of your enforcement policies. To monitor and verify your DMARC records, use EmailAuth’s free DMARC record checker.
Apart from providing companies and organizations with email security and complete control of their email domains via DMARC, EmaiAuth has other tools and various advantages. Head to Benefits of DMARC to read more about them.