Proofpoint has published a new study that reveals that 30% of the main online travel sites in Spain lack strong email security measures to avoid the risk of cyber scams for users. The results are based on an analysis of the adoption of DMARC (Domain-based Message Authentication, Reporting and Conformance) among the top 20 websites in this sector in Spain.

Designed to combat domain abuse by cybercriminals, DMARC is a validation system that authenticates the identity of the sender before the email reaches the recipient. This protocol operates under three progressive levels of protection: monitoring, quarantine and rejection, the latter being the one that directly prevents fraudulent messages from reaching the inbox.

“Booking a vacation is one of the biggest purchases many people make each year, and is often accompanied by a barrage of emails about flights, hotels, itineraries and special offers,” explains Fernando Anaya, general director of Proofpoint for Spain and Portugal. “Unfortunately, this provides a very attractive opportunity for cybercriminals looking to impersonate trusted brands to trick people into handing over personal information or making payments.”

Main conclusions of cyber fraud

Regarding this exposure to cyber fraud, Proofpoint has drawn the following conclusions from the DMARC analysis on the main travel websites:

  • Spain demonstrates widespread adoption of email security, with 95% of its major travel sites publishing a basic DMARC email authentication record.
  • The Proofpoint study finds, however, that more could be done: only 70% of the travel websites analyzed employ the rejection policy, leaving about a third (30%) of their customers, staff and partners more vulnerable to fraudulent emails and messages that could impersonate their brand.

“While it’s encouraging to see that many travel companies are strengthening their email security, too many are still leaving their customers exposed to fraudulent messages. By implementing stronger protections, brands can make things much more difficult for fraudsters looking to exploit vacationers, helping to ensure that travelers can focus on planning their trips with complete confidence,” says Fernando Anaya.

As key safety guidelines, Proofpoint advises following these tips to stay safe when booking and managing travel online:

  • Make any reservation through official pages or accredited and verified agents. Before providing data, research these tourism companies, read opinions on the internet and check if there are customer complaints about their services.
  • Be wary of unexpected messages with confirmations, changes or requests that require urgent action. They often lead to fake login pages created by cybercriminals to steal credentials, so avoid clicking on links directly. It is preferable to type the official website address directly into the browser and check all the information.
  • Protect accounts with strong, unique passwords on travel booking sites and, if possible, enable multi-factor authentication to add another layer of security.