ActiScan

Industry News

What DigiCert's Acquisition of Valimail Tells Us About Where Email Security Is Headed

September 28, 2026

Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Two iron padlocks joined on one chain across a wooden door

On September 16, 2025, DigiCert announced it had acquired Valimail, one of the longest-standing names in automated DMARC enforcement and a driving force behind the BIMI standard. On its face, this looks like a routine consolidation story in a crowded security market. Look closer, and the deal maps out where the entire email authentication category is headed, and why MSPs who still treat DMARC as a checkbox item are going to feel increasingly out of step with where their clients' inboxes are actually protected.

The short answer to why this deal matters: DigiCert is a certificate authority, not an email company, and it just spent real money to own DMARC enforcement, DKIM, SPF, and BIMI infrastructure outright. That move signals email authentication is no longer a standalone product category. It is becoming a component of a broader digital trust stack that also includes PKI, DNS, and certificate lifecycle management, which is exactly the direction MSP tooling needs to follow.

Why Did a Certificate Authority Buy a DMARC Company?

DigiCert's own announcement frames the logic plainly: email remains the top attack vector, and folding DMARC, DKIM, SPF, and BIMI enforcement into the existing DigiCert ONE platform creates a single place to manage identity across websites, software, devices, DNS, and now email. DigiCert CEO Amit Sinha put it directly, saying the company's strategy has always been to expand platform capabilities with technologies that solve emerging threats, and that email authentication is the next logical step for DigiCert ONE.

That rationale only makes sense if you accept a premise that has been building for years: authentication problems that used to live in separate silos, TLS certificates for web traffic, DMARC records for email, DNS hygiene for domain integrity, are converging into the same operational conversation. A domain's trustworthiness is now judged holistically, not certificate by certificate or DNS record by DNS record.

The Numbers Behind the Deal

Valimail did not arrive as a struggling asset looking for an exit. The company reported more than 92,000 clients worldwide, up 70 percent over the prior year, and it holds the distinction of being the only DMARC provider with FedRAMP authorization, a detail that matters enormously for anyone selling into government or highly regulated verticals, as DigiCert's press release notes. Industry coverage of the deal pegged the addressable market for paid DMARC solutions at more than $4 billion, and framed the acquisition as DigiCert's entry ticket into that space, according to MediaPost's Email Insider column.

That same coverage made an observation worth sitting with: as with prior consolidations in the sector, "email marketers now have one vendor where they once had two." That is the pattern MSPs should watch closely, because it rarely stops at one deal.

Is This Part of a Bigger Consolidation Pattern?

Yes, and it is not just about email. DigiCert already unified public certificate authority services, private PKI, certificate lifecycle management, and DNS under the DigiCert ONE umbrella before this acquisition, so adding email authentication was less a pivot and more the next domino. The pairing of Valimail's DMARC enforcement with DigiCert's existing Verified Mark Certificate business is a clean illustration of why: VMCs let organizations display verified brand logos in the inbox, and that capability only works once a domain has DMARC enforcement in place, since BIMI depends on strong authentication as its foundation, as outlined in coverage of the deal from SecurityBrief Australia.

In practical terms, a feature that used to require stitching together a certificate vendor and a DMARC vendor now lives under one roof. For enterprises that can be a convenience. For MSPs managing dozens or hundreds of client domains, it changes the vendor landscape they need to evaluate, and it raises the bar for what "email security" tooling is expected to cover in a single pane of glass.

Why Enforcement, Not Adoption, Is the Real Pressure Point

The deal did not happen in a vacuum. It landed almost two years after Google and Yahoo announced that bulk senders would need DMARC in place, with enforcement phased in starting February 2024, a requirement that turned DMARC from a nice-to-have into a delivery gate for any domain sending meaningful volume, as dmarcian's breakdown of the requirements explains. That single policy shift from two of the largest inbox providers did more to drive DMARC adoption than a decade of security advisories combined.

The adoption numbers back this up, but they also expose the real gap. According to EasyDMARC's 2025 adoption report, global DMARC adoption among top domains climbed from 27.2 percent to 47.7 percent between 2023 and 2025, with enforcement policies specifically growing by 50 percent over that window, based on analysis of Fortune 500 and Inc. 5000 domain data. That same report found countries with mandatory DMARC policies saw phishing delivery success drop sharply, while unenforced markets saw it climb. The lesson for MSPs is blunt: publishing a DMARC record at p=none satisfies almost nothing. The value shows up only once a domain moves to quarantine or reject, and getting there safely is the part most client environments still get wrong.

The standard itself is also in motion underneath all of this. DMARC's original specification, RFC 7489, was published back in 2015 as an informational document, and the IETF has since replaced it with a formal standards-track set of documents, RFC 9989, RFC 9990, and RFC 9991, according to dmarc.org's current specification page. A protocol that consolidates its own governance while the vendor market around it consolidates too is not a coincidence. Both are signs of a technology maturing out of its early, fragmented phase.

TrendWhat ChangedWhy It Matters for MSPs
Vendor consolidationDMARC, BIMI, and PKI vendors merging into single platformsFewer point tools, but bigger platforms to evaluate and integrate
Inbox provider enforcementGmail and Yahoo require DMARC for bulk senders since Feb 2024Non-compliant client domains risk deliverability failures, not just spoofing
Protocol governanceRFC 7489 replaced by standards-track RFC 9989-9991DMARC is now a formal internet standard, not just an informational spec

What Should MSPs Actually Do With This Information?

The direct takeaway is not that every MSP needs to rush toward a single mega-platform vendor. It is that domain trust signals, certificates, DNS records, and email authentication are being treated as one connected surface by the largest players in the industry, and client-facing tooling should reflect that same connected view rather than a patchwork of disconnected checks.

For MSPs running scans across dozens of client domains, that means prioritizing visibility that ties SPF, DKIM, DMARC, and DNS configuration together instead of auditing each in isolation. It also means treating DMARC's move from p=none to enforcement as a project with real steps, not a one-time DNS entry. A structured rollout, one that starts with monitoring, moves through alignment fixes, and only then tightens to quarantine or reject, is the difference between a domain that is actually protected and one that merely looks compliant on paper.

Practically, that looks like:

  • Auditing every client domain's current DMARC policy state, not just whether a record exists, since a p=none record with no monitoring plan behind it provides almost no real protection.
  • Cross-checking SPF and DKIM alignment before pushing any client toward enforcement, since misconfigured alignment is the most common reason legitimate mail breaks during a policy tightening.

Tools built for this exact workflow make the difference between a manual, error-prone rollout and a repeatable one. ActiScan's own getting-started guide walks through exactly that sequence for teams bringing multiple client domains up to enforcement without breaking legitimate mail flow along the way. For MSPs sizing up whether a dedicated scanning platform fits their client roster, the pricing page lays out how that scales across a growing domain count, and firms ready to move can head straight to sign up and start auditing their book of clients today.

The Bigger Picture

DigiCert did not buy Valimail because DMARC enforcement is a niche technical concern. It bought Valimail because domain-level trust, spanning certificates, DNS, and now email, has become the connective tissue of how the internet decides what to believe. Sinha's own comments framed this as part of a longer arc, tying the acquisition to broader anxieties about AI-driven threats and the eventual pressure quantum computing will put on current encryption standards, arguing that every digital interaction increasingly requires proof of legitimacy built into the infrastructure itself.

For MSPs, the practical implication is narrower but no less real: the vendors your clients' inboxes depend on are consolidating their trust infrastructure, and the inbox providers receiving that mail are enforcing authentication requirements more strictly every year. Treating DMARC as a solved problem after one DNS entry is no longer a defensible position. Treating it as the entry point into a wider domain trust posture is where the market is clearly headed.

← Back to all posts