Help Net Security published a video interview on August 3, 2026 featuring Mike Boyle, VP of Business Units at GMO GlobalSign, and Rahul Powar, CEO and founder of Red Sift, walking through the history of email security from the pre-SPF era to today. The headline point is not a new statistic so much as a structural admission from two people who build this infrastructure for a living: the tell-tale signs that used to flag a phishing email, awkward phrasing, mistranslated idioms, generic greetings, no longer reliably exist. Generative AI now produces a convincing, context-aware phishing email in the time it used to take an attacker to find a target’s job title.
That shift matters because most email security training built over the last two decades rests on teaching people to notice something off. Off is getting harder to manufacture reliably when the tool writing the message has read the recipient’s public LinkedIn history and mirrors their employer’s actual tone of voice. The interview frames this plainly: the defense has to move from spotting bad writing to verifying identity, because writing quality stopped being a signal either side can rely on.
Why the Old Tells Are Disappearing
For years, security awareness training leaned on a familiar list: check the sender address, look for typos, be suspicious of urgency. Those checks still catch unsophisticated spam, but they were never going to hold against a model that can draft a flawless, contextually specific email referencing a real vendor relationship, a real project name, or a real executive’s actual writing patterns pulled from prior public correspondence. Attackers do not need a human copywriter fluent in the target’s language and industry jargon anymore. They need a prompt.
What does not change with better writing is the underlying transport. A forged email still has to claim it came from a domain it did not actually send from, unless the sender is using a genuinely compromised account. That is the layer AI has not found a way around, and it is the layer DMARC, SPF, and DKIM were built to police.
Authentication as the Signal That Cannot Be Prompted Into Existence
DMARC tells a receiving mailbox whether a message’s claimed sending domain is backed by valid SPF or DKIM authentication, aligned to that domain. No language model output changes whether that check passes. An attacker can write an email indistinguishable from a real one, but without control of the domain’s DNS and signing keys, that email still fails DMARC when it tries to impersonate a protected domain.
BIMI extends that same authentication into something a recipient can actually notice without reading headers. A verified brand logo appears next to the message in the inbox, but only for domains already enforcing DMARC at p=quarantine or p=reject. That gate is the point. A logo is worthless as a trust signal if any sender can attach one to any message, so BIMI ties display to the DMARC enforcement level a domain has actually reached, not to a claim in the message body.
Getting a domain to that point currently runs through one of two certificate types. A Verified Mark Certificate requires a registered trademark and displays a verified checkmark alongside the logo. A Common Mark Certificate, a newer and less expensive alternative that several mailbox providers including Gmail now accept, only requires that the logo has been in public use for at least twelve months, with no trademark filing needed. Both still require the same DMARC enforcement prerequisite underneath them.
The Industry Is Consolidating Around This Pairing
The interview lands against the backdrop of a partnership Red Sift and GMO GlobalSign announced on June 15, 2026, combining Red Sift’s OnDMARC platform with GMO GlobalSign’s certificate issuance so a domain owner can move from DMARC monitoring through VMC or CMC issuance to a live BIMI logo without coordinating separately across vendors. That kind of packaging is a signal in its own right: two companies that sell authentication infrastructure and brand certificates for a living are betting that the gap between “technically authenticated” and “visibly trustworthy to a recipient” is where the next wave of email defense spending goes, precisely because AI has made the content of a message a worse indicator than ever.
What This Means for Your Domain
Stop training people to spot bad writing as the primary defense. It was already a weak control. Against AI-generated phishing it is close to useless, and continuing to lean on it gives your organization false confidence.
Move DMARC to enforcement if you have not already. A record sitting at p=none provides visibility into who is sending as your domain, but it blocks nothing and is not eligible for BIMI display regardless of how good your logo is.
Treat BIMI as the next step after enforcement, not before it. A CMC is now a realistic option for brands without a registered trademark, which removes the excuse that BIMI was only for large, litigious companies protecting a legal mark.
Expect recipients to lean harder on visual and structural signals, not textual ones. As AI erodes the writing-quality tell, a verified logo next to a message becomes one of the few cues a recipient can trust that does not require them to inspect a single header.
The Takeaway
The uncomfortable part of this interview is how ordinary it makes the AI phishing threat sound. It is not a novel exploit or a zero-day. It is a tool that writes convincing text quickly, applied to a problem, tricking a human into trusting a message, that has existed since email did. The only piece of that equation AI has not touched is domain-level authentication, and that is exactly why DMARC enforcement and the BIMI logo built on top of it are becoming the baseline rather than a nice-to-have.
Excello Mail helps you get your domain to DMARC enforcement and gives you continuous visibility into your SPF, DKIM, and BIMI configuration, so the trust signal a recipient sees in their inbox is backed by real authentication underneath it. Sign up for free to Excello Mail and see where your domain stands today.