r/PrivacyToolbox • u/EnthusiasmRoutine • 19h ago
News Half of New Zealand government domains are sitting on DMARC p=none and calling it security compliance
Proofpoint just published data showing half of New Zealand government agencies still haven't enforced p=reject on their DMARC policy, even after getting a full year deadline extension. They stay stuck on p=none or quarantine.
Publishing a DMARC reject record in DNS takes three minutes. IT departments stall on p=reject for years because nobody wants to audit shadow IT. The second you flip to p=reject, every rogue SaaS tool or ancient internal mailer sending email with the agency domain stops working if it lacks valid DKIM keys.
Instead of finding those unaligned senders, admins leave p=none active forever. That turns DMARC into a passive logging tool. It lets attackers spoof official government domain headers with zero pushback, while the IT team claims they checked the email security box.
If an agency cannot track which systems send mail on its behalf, they have bigger problems. Setting p=reject is basic hygiene. How many organizations in your sector actually enforce reject instead of hiding behind monitor mode?
Sources: proofpoint and SecurityBrief New Zealand, links in comments