ChannelLife New Zealand - Industry insider news for technology resellers
New Zealand
Half of New Zealand agencies miss email security bar

Half of New Zealand agencies miss email security bar

Mon, 7th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Half of New Zealand government organisations have not met the email security standard required under the Secure Government Email framework, according to Proofpoint. The finding covers more than 200 primary state entities.

The cyber security company found 50% of organisations had implemented DMARC at the required Reject level. The rest remained below the mandated standard ahead of the October 2026 deadline.

DMARC, short for Domain-based Message Authentication, Reporting and Conformance, helps prevent attackers from sending emails that appear to come from trusted government domains. Under the framework, Reject is the strictest setting because it blocks unauthorised messages before they reach recipients.

Organisations using lower settings leave more room for misuse of official domains. Of those examined, 35% were using a Monitor policy, which tracks email activity without blocking suspicious messages, while 12% were using Quarantine, which typically sends suspect emails to spam folders. A further 3% had no DMARC record.

The research shows progress over the past year, but also a sizeable unresolved gap. The share of government organisations using the Reject setting rose from 26% in 2025 to 50% this year.

The analysis was based on data gathered in August 2026 from 200 organisations listed on the New Zealand Government Organisations Register. The group included agencies in defence, internal affairs, foreign affairs and trade, education, social services, energy, and treasury and finance.

Email risks

The issue matters because government email domains can lend credibility to fraudulent messages. Attackers often exploit trusted identities in phishing and credential theft attempts, seeking to trick staff, citizens, suppliers, or partner organisations into disclosing information or transferring funds.

Official figures underline the scale of the wider threat. The National Cyber Security Centre reported NZ$8.3 million in direct financial losses in the first half of 2026, with phishing and credential harvesting among the most commonly reported incident types.

This has pushed email authentication higher up the list of priorities for public sector cyber teams. A domain protected at Reject level is less likely to be abused in spoofed email campaigns, although organisations still need other controls, including user awareness and stronger login security, to reduce exposure to account compromise.

New Zealand's Secure Government Email programme was introduced to improve the trustworthiness of official digital communications. The government extended the compliance deadline from October 2025 to October 2026, giving agencies another year to move their domains to the strongest DMARC setting.

The latest figures suggest many agencies have used that extra time, but unevenly. Almost all of the organisations studied had some form of DMARC in place, with overall adoption reaching 97%, yet many had not completed the final step to the policy level required by the framework.

Public sector gap

The split between adoption and full enforcement illustrates a common challenge in email security policy. Monitor mode gives organisations visibility into who is sending email on behalf of their domain, while Quarantine allows some filtering of suspect traffic, but neither setting provides the outright blocking that Reject offers.

Moving to Reject can require agencies to identify legitimate third-party services that send email using their domains, such as marketing tools, notification systems, or outsourced platforms. If those systems are not configured correctly, valid messages can be affected, which often slows enforcement projects in large organisations.

For public sector bodies, that work can be more complex because of legacy systems, distributed procurement, and the number of departments, contractors, and external service providers involved in citizen-facing communications. As a result, technical adoption can be high even when policy compliance remains incomplete.

Steve Moros, Senior Director, Advanced Technology Group, Asia Pacific and Japan, at Proofpoint, said the remaining gap left room for abuse of trusted domains. "DMARC is a critical layer of protection against email impersonation and phishing, one of the most prevalent threats facing New Zealand organisations in this AI era," Moros said.

He said the government's approach had helped raise implementation levels across departments and agencies. "We welcome the New Zealand Government's continued efforts to strengthen DMARC adoption across the public sector. With the SGE deployment deadline approaching, organisations need to act now to ensure trusted government domains cannot be easily abused. Strong email authentication is an important step in protecting public information, government services, and the trust New Zealanders place in them," Moros said.

The figures leave a mixed picture for New Zealand's public sector: broad uptake of DMARC across official domains, but only half of organisations at the level required to stop unauthorised messages from being delivered.