Skip to content
SECURITYSQUAD
Back to the blog

SECURITYSQUAD Joins the BSI Hall of Fame for Email Security

2026-09-18 · by SECURITYSQUAD

SECURITYSQUAD Joins the BSI Hall of Fame for Email Security

1am, at the station, packing a bag for a train to Berlin – not an emergency, just an appointment worth losing sleep over. Today in Berlin marked the closing event of the second round of the "Hall of Fame for Email Security", the wrap-up of the Email Security Year run by Germany's Federal Office for Information Security (BSI), eco – the Association of the Internet Industry, and Bitkom. SECURITYSQUAD is among the 116 organisations that made it into Hall of Fame 2.0. BSI President Claudia Plattner handed us the certificate in person.

A year aimed at the least visible weak spot

Email is more than 40 years old and was never built with security as a given. More than 90 percent of cyberattacks start with a phishing email, and more than 30 percent of organisations still have no DMARC record, leaving them exposed to sender-address spoofing. German businesses' estimated losses from cyberattacks exceeded €200 billion in 2025 alone. That is exactly where the BSI, eco and Bitkom stepped in during 2025, calling on webmail providers, hosting companies and large employers to implement two technical guidelines: TR-03108 on secure email transport and TR-03182 on email authentication. An estimated 360 billion emails are sent worldwide every day, and very few of them meet these standards.

From announcement to proven implementation

The first Hall of Fame launched in August 2025: more than 120 companies and institutions received a certificate, split into Gold (DNSSEC implemented or firmly planned) and Silver (MTA-STS implemented or planned). The second round raised the bar. Only organisations that had actually activated DNSSEC under TR-03108 by 30 June 2026 – verifiably, not merely announced – were admitted. 116 organisations cleared that hurdle.

Why we took part

If you advise clients on ISO 27001, IT-Grundschutz and technical hardening, you should hold your own infrastructure to the same standard. That is why we fully implemented SPF, DKIM, DMARC and DNSSEC on our own domains and applied for the second round. This award is not for a concept, a nice slide deck or a checkbox – it stands for infrastructure that is actually running and holding up day to day. That is exactly what we expect of ourselves when we work for clients.

What DNSSEC and DMARC actually do

A letter used to have a wax seal that would show if it had been tampered with. Cryptography now does that job for email. Technically, every DNS zone gets a key pair it uses to sign its records: alongside the actual DNS entry sits an RRSIG record holding the signature, and DS and DNSKEY records build an unbroken chain of trust from the root zone through the top-level domain down to your own domain. A resolver can trace any answer back to that root and detect tampering along the way – say, DNS cache poisoning or a man-in-the-middle attack on name resolution. For email security, that chain is also the foundation for DANE: only with a signed zone can a TLSA record reliably pin down which TLS certificate a mail server is actually allowed to present, so a silent downgrade to an unencrypted or forged connection between two mail servers becomes visible instead of staying hidden.

DMARC builds on SPF and DKIM and decides what happens to emails that falsely claim to come from your domain: reject them instead of delivering them. Without a DMARC record, almost anyone can send an email that looks like it came from your company. That is exactly the lever behind CEO fraud and invoice scams.

Where you stand today

The more-than-30-percent missing DMARC records the BSI found are not an abstract problem happening somewhere else – there is a good chance your own domain is affected too. A look at your DNS records shows within minutes whether SPF, DKIM, DMARC and DNSSEC are in place, and whether the DMARC policy is actually set to reject rather than just monitor – a record left in monitor-only mode protects no one. If you cannot or would rather not check this yourself, we help with the technical implementation, just as we did for ourselves.

Read more: IT-Grundschutz to the BSI standard · Cloud security for Microsoft 365 · Phishing and the human factor