Government
Overview
Citizens should be able to trust official communications as governments increasingly communicate via email. Many government agencies, however, have been hesitant to implement anti-spoofing mechanisms like Domain-based Message Authentication, Reporting, and Conformance (DMARC), putting citizens and their own cybersecurity at risk.
Citizens often regard government agencies as extremely legitimate and trustworthy resources, and cybercriminals take advantage of any opportunity to exploit this confidence. Impersonation of official institutions via email for malicious objectives is on the rise. Criminals may spoof government organizations to:
- Obtain personal data from citizens and government personnel
- Commit fraud
- Deploy malware and ransomware
- Influence elections
- Tarnish the reputation of the government in authority
Adopting DMARC protects citizens and government employees from malicious actors impersonating government institutions in phishing email campaigns and spoof attacks. DMARC can assist in maintaining trust between the government and the citizens by avoiding cyberattacks.
To read more about Domain-based Message Authentication, Reporting, and Conformance, head over to What is DMARC?

Government Sector DMARC Adoption
Considering the benefits associated with DMARC, several countries have recommended its implementation for government organizations, including the following:
- The US Department of Homeland Security focused on email security and issues Binding Operational Directive 18-01 in 2017 that all federal government domains implement a ‘p=reject’ DMARC policy within a year.
- The Government Digital Service in the United Kingdom amended security standards in 2016 that mandated the publishing of DMARC’s reject policy by all government domains. It also published guidelines on how to implement secure email practices that included the implementation of DMARC.
- By the end of 2019, the Standardization Forum ordered that all Dutch government entities use DMARC and set it to ‘p=reject’.
- Australian government guidelines proposed that all companies use a DMARC policy that specifies that emails from the organization’s domain and subdomains are rejected if they fail SenderID/SPF and/or DKIM checking.
- To prevent phishing, NIST advises utilizing DMARC authentication mechanisms.

Most significant cyberattacks involving government agencies
May 2021
- On May 7, Colonial Pipeline, an American oil pipeline system that originates in Houston, Texas, and carries gasoline and jet fuel mainly to the Southeastern United States, suffered a cyberattack that crippled gas delivery systems in Southeastern states.
- Ireland’s Health Service Executive declared that a huge ransomware attack forced its national health service operator to shut down all its IT systems.
- Hackers gained access to Fujitsu’s SaaS infrastructure servers and stole material from many official Japanese government institutions.
- Cybersecurity researchers identified a North Korean hacker organization as the perpetrator of a cyber espionage campaign that used phishing to target high-profile South Korean government officials.
- The FBI and the Australian Cyber Security Centre warned of an ongoing Avaddon ransomware attack that affects a variety of industries in a number of nations.
- A huge DDoS attack knocked off the Belgium government’s internet service provider, affecting more than 200 organizations including numerous government, public, scientific and educational agencies, including Belgium’s Parliament and some law-enforcement agencies.


April 2021
- Chinese hackers identified as the Naikon gang have been conducting espionage activities against the organizations and obtaining data from the victims.
- US intelligence services assisted Ukraine in thwarting an increasing number of Russian cyberattacks in recent months as Moscow’s mass along their shared border.
- Two state-sponsored hacker groups, one of which works for the Chinese government, exploited weaknesses in a VPN service to target businesses across the United States and Europe, with a particular focus on defense contractors in the United States.
- In 2017-18, Russian military intelligence hacked the agency that governs Sweden’s national sports federations.
- During the second half of 2020, Chinese hackers conducted a cyber espionage effort in Vietnam with an intent to procure political intelligence from government entities.
March 2021
- On March 16, Ukraine’s State Security Service (SBU) announced that it had thwarted a large-scale cyberattack by Russian hackers aimed at stealing sensitive government information.
- As part of a cyber espionage campaign, suspected Iranian hackers targeted government institutions, academics, and the tourism industry in Azerbaijan, Bahrain, Israel, Saudi Arabia, and the United Arab Emirates.
- As per the New York Times, data was stolen from approximately 30,000 organizations around the world using Chinese government hackers who targeted Microsoft’s workplace email software.


February 2021
- In an attempt to spread damaging papers to other government institutions, Russian hackers broke into a federal file-sharing system in a bid to install harmful documents that would infect computers that downloaded them.
- Hackers having links to the Vietnamese government used malware to penetrate individuals’ devices, spy on their activities, and exfiltrate data during a nearly three-year cyber espionage campaign against human rights campaigners in the country.
January 2021
- A group of unknown hackers gained access to a file-sharing system used by Japan’s Cabinet Office and took advantage of a zero-day vulnerability to steal personal information from 231 people.
- Google spotted an attack claiming that North Korean government hackers utilized many fake Twitter accounts to trick cybersecurity researchers into visiting infected websites or opening infected attachments in emails requesting collaboration on a research project.
- Suspected Indian hackers have been targeting businesses and governments across South and East Asia since 2012, with a focus on military and government organizations in various countries.
- Ransomware assaults connected to the Chinese government targeted five major casino and gambling countries, demanding more than $100 million in ransom.

How Can EmailAuth Help?
EmailAuth, through DMARC’s implementation, gives companies and organizations guaranteed security and complete control of their email domains. However, it has other advantages too. Read more about them in detail here.
EmailAuth also provides a free DMARC Record Checker to display your record, test it, and verify its validity. For a DMARC record check, all you need to do is provide your domain name. The tool will then analyze and display your record along with other important information.
Similarly, you can verify your DKIM and SPF records using EmailAuth’s free and automated tools:
In case you don’t have a DMARC record published for your domain, you can use EmailAuth’s DMARC Record Generator to generate a record instantly.