Only Two-Thirds of Federal Domains Meet Email Security Deadline
About two-thirds of federal agencies met the Department of Homeland Security’s October 16 deadline for implementing the DMARC anti-spoofing protocol on their email domains. The operators of about one-fifth of the domains apparently had not taken the first step. When DHS issued the order, only 8 percent of government domains already had DMARC fully implemented. DHS cyber policy leader Tom McDermott says that the agency has plans to reach 100 percent adoption “in the near future.”
DMARC must be installed on both the sending and receiving server to work, with the systems mutually confirming that the sending server is authorized to send email for the return address attached to each message. Because DMARC is implemented by most major third-party commercial email providers, general compliance is about 80 percent. However, compliance by government contractors, the largest of which typically operate their own email servers, is rare, with only 1 of 50 large contractors using it fully.

