Election season brings a flood of digital communication. Candidates ask voters to donate, volunteer, attend events, sign petitions and share information.
But before trusting a political email, consumers should understand that there are really two different questions to answer:
Did this email come from the domain it says it came from?
And:
Does that domain belong to the candidate I think it does?
Those may sound like the same question. They are not.
This is not just a theoretical concern.
As part of our 2026 election research, we examined 3,756 U.S. political candidate campaign domains across all 50 states to understand how well campaigns are protecting the email they send to voters, donors and supporters.
We found a significant gap: roughly 8 out of 10 campaign domains we analyzed were not enforcing DMARC, an email security standard designed to make it harder for criminals to directly spoof a legitimate domain. The standard is called DMARC or Domain-based Message Authentication, Reporting and Conformance.
For consumers, the concept does not need to be complicated.
Think of DMARC as a way for an organization to tell email providers: these are the systems authorized to send email using our domain, and messages that fail those checks should not be delivered.
If a hypothetical candidate owns janedoe2026.com and properly enforces DMARC, someone else should have a much harder time sending an email that falsely claims to come from janedoe2026.com.
The challenge is that consumers normally cannot see DMARC working behind the scenes.
One visible trust signal can be a validated logo that appears beside authenticated messages in email providers’ inboxes like Gmail. Organizations that meet strong email authentication requirements can use BIMI and a Mark Certificate to display a validated logo in supporting inboxes.
For consumers, seeing a familiar, validated logo can provide another useful trust signal.
But a logo, just like DMARC, does not answer everything.
Imagine Jane Doe's real campaign operates janedoe2026.com.
Someone else could register a convincing alternative such as janedoeforgovernor.com, create a professional-looking website and properly authenticate email from that new domain.
DMARC could work perfectly.
An email from janedoeforgovernor.com really did come from janedoeforgovernor.com.
The problem is that the domain might not actually belong to Jane Doe's campaign.
That is the difference between authentication and identity.
Authentication asks:
Did this message really come from this domain?
Identity asks:
Who is actually behind this domain?
Consumers need both answers.
For political communications involving donations, personal information or other important actions, voters should independently verify the candidate's official website through trusted sources such as state election authorities or federal election records rather than relying solely on a link received through email.
Consider a remarkable real-world example from Alaska's 2026 U.S. Senate election.
Two legitimate candidates are currently running for the same Senate seat with essentially the same name: Dan S. Sullivan and Daniel J. Sullivan Jr.
Both are real people. Both are legitimate candidates. Both have their own campaign websites.
There’s no need for a fake website for a voter searching for "Dan Sullivan for Senate" to face an identity problem.
Email authentication could help establish which domain sent a particular message.
It still cannot tell the voter which Dan Sullivan they intended to find.
That is the larger lesson for consumers this election season.
Authentication helps establish where a message came from. Identity helps establish who is actually behind it.
Campaigns have a responsibility to protect their legitimate domains with standards such as DMARC and to monitor for impersonation and lookalike domains.
Consumers also have a role. Before donating, sharing personal information or acting on an unexpected political email, verify that the domain really belongs to the candidate you intended to reach.
Neither authentication nor identity solves the entire problem alone.
Together, they form two essential halves of digital trust.