Email Security Strategy
The Real Cost of Skipping Email Security: What the FBI's Latest Numbers Mean for MSPs
September 25, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Every spring, the FBI's Internet Crime Complaint Center publishes a year-end accounting of what cybercrime actually cost the country, and every spring the number gets harder to explain away as background noise. The 2024 report is no exception. For an MSP holding responsibility for dozens or hundreds of client domains, the report is not an abstract policy document. It is a description of the exposure sitting in every unmonitored inbox on the book of business.
The core finding is simple to state and uncomfortable to sit with: reported losses to internet crime hit a record $16.6 billion in 2024, a 33% jump over the prior year, and email-based fraud, phishing, spoofing, and business email compromise together accounted for a disproportionate share of that damage. For MSPs, the practical takeaway is that domain-level email authentication has moved from a nice-to-have line item to a baseline expectation clients and insurers now assume is already in place.
What Did the FBI Just Report?
The FBI's Internet Crime Complaint Center logged 859,532 complaints in 2024, and total reported losses exceeded $16 billion, a 33% increase in losses from 2023. That increase happened even as the raw number of complaints edged down slightly, which the FBI's own annual report frames as evidence that individual attacks are getting more expensive, not just more frequent.
Phishing and spoofing remained the single most reported crime type, and business email compromise, while far less frequent by complaint count, punched well above its weight in dollar terms. According to the National Automated Clearing House Association's review of the IC3 data, BEC was the seventh most reported crime type in 2024 with 21,442 complaints, yet it ranked second on the dollar-loss list at close to $2.8 billion, and the three-year total since 2022 runs close to $8.5 billion. That is a lot of money moving through what usually looks, on the surface, like a routine invoice email.
Why Does Business Email Compromise Keep Winning?
BEC succeeds because it exploits trust in a sender identity rather than a technical vulnerability, and most mail systems still cannot reliably tell a spoofed sender from a real one without authentication records in place. The scam does not need malware, an exploit, or a zero-day. It needs a convincing message that appears to come from a domain the recipient already trusts.
That mechanism is why the FBI's own public service announcement on the topic calls BEC a scam that has now produced over $55 billion in identified global exposed losses since it started tracking the category, with a further 9% year-over-year increase in exposed losses reported between December 2022 and December 2023. The scam works across small local businesses and large corporations alike, which is precisely the client mix most MSPs manage. A construction firm processing a vendor payment and a 40-person accounting practice moving payroll are both equally attractive targets if their domain has no authentication controls signaling to receiving mail servers what legitimate mail from that domain should look like.
Where Do MSPs Fit Into This Picture?
MSPs are the practical control point for the fix, because most small and mid-sized clients do not have in-house staff who understand DNS well enough to publish and maintain SPF, DKIM, and DMARC records correctly. That gap is now showing up in cyber insurance underwriting, where carriers increasingly ask specifically about DMARC configuration during renewal, treating missing or misconfigured records as a flag worth pricing into the premium.
This is not a hypothetical liability question either. When a client's domain gets spoofed to defraud one of their own customers, the reputational and financial fallout lands on the client, but the "why wasn't this caught" conversation lands squarely on the MSP. Standing up authentication monitoring across a client portfolio does not need to be a large undertaking. An MSP that has not yet built this into a service line can walk through the fundamentals in ActiScan's getting-started guide and have baseline visibility into every client domain within a single onboarding cycle.
What Actually Stops These Losses?
Email authentication does not stop every social-engineering attempt, but it closes the specific door that lets attackers impersonate a domain outright, and that door is the one BEC and phishing both rely on most heavily. The three protocols involved each play a distinct role, and understanding the division of labor matters for anyone advising clients on what "done" actually looks like.
| Protocol | What it does | Where it's defined |
|---|---|---|
| SPF | Lists which mail servers are authorized to send on behalf of a domain | RFC 7208 |
| DKIM | Cryptographically signs outgoing mail so receivers can detect tampering | RFC 6376 |
| DMARC | Tells receiving servers what to do when SPF or DKIM checks fail, and reports back on abuse | RFC 7489 |
The Cybersecurity and Infrastructure Security Agency's implementation guidance is explicit that enabling all three restricts an adversary's ability to gain initial access via email sent on behalf of a domain they do not own, and CISA's own Binding Operational Directive 18-01 required federal agencies to move their DMARC posture to a full reject policy, the enforcement level that actually blocks unauthenticated mail rather than merely reporting on it.
Mailbox providers have made the same point through policy rather than guidance. Since February 2024, Gmail and Yahoo have required bulk senders to authenticate with both SPF and DKIM and to publish a DMARC record, and mail that fails alignment now gets bounced outright rather than quietly delivered to spam. That policy shift means a client without a DMARC record is not just exposed to spoofing risk, they may already be losing legitimate mail delivery to their own customers.
For MSPs managing this across dozens of domains, the practical steps come down to a short list:
- Publish an SPF record and keep it current every time a client adds a new sending service.
- Enable DKIM signing on every outbound mail stream, including third-party marketing and invoicing tools.
- Move DMARC from monitor-only (
p=none) to quarantine and eventually reject, watching aggregate reports at each stage to avoid blocking legitimate mail.
None of these steps guarantee a client will never see a fraud attempt land in an inbox. Attackers can still register lookalike domains or compromise a legitimate account. What authentication does is remove the easiest and cheapest version of the attack, the one where a criminal simply types an executive's exact display name and domain into the From field and counts on nobody checking.
The Bottom Line for MSPs
The FBI's numbers describe a threat that is not shrinking and is not going to be solved by better spam filters alone. Losses tied to email fraud rose even as raw complaint volume fell slightly, which points toward attackers getting better at monetizing the accounts and domains they successfully impersonate. MSPs that build authentication monitoring into their standard service catalog are addressing the exact mechanism behind the majority of that dollar growth.
Getting visibility into where every client domain currently stands on SPF, DKIM, and DMARC enforcement does not require a large tooling investment or a long rollout. ActiScan's plans are built around exactly this kind of portfolio-wide monitoring, and the pricing page lays out tiers that scale with the number of domains under management rather than forcing a flat enterprise contract on a ten-client shop. For MSPs ready to see where their book of business currently stands, signing up takes less time than writing the incident report that follows a client's first successful BEC attempt.