New Zealand has officially strengthened its national cybersecurity posture with the introduction of the Secure Government Email (SGE) Common Implementation Framework, which mandates DMARC enforcement (p=reject) across all government email-enabled domains. This significant shift modernises email security practices and replaces the legacy SEEMail, scheduled for full retirement in 2026. blog.redsift.com
Why is DMARC Now Mandatory?
Email remains the number one entry point for cybercrime, including phishing and domain spoofing. CERT NZ has reported growing year‑on‑year spoofing incidents resulting in losses exceeding $1.6 billion in 2024. By enforcing DMARC at p=reject, the SGE framework prevents fraudulent emails from ever reaching inboxes—protecting citizens, agencies, and partner organisations. blog.redsift.com
What the SGE Framework Requires
Under the SGE framework, the following controls are now mandatory for all New Zealand government domains by October 2025:
- DMARC: Set to p=reject to block spoofed messages. [blog.redsift.com]
- SPF: Must end with -all (hard fail), ensuring only authorised senders can use the domain. [blog.redsift.com]
- DKIM: All outbound email must be cryptographically signed to ensure message integrity. [blog.redsift.com]
- MTA‑STS: Enforced to guarantee encrypted and authenticated email transmission. [blog.redsift.com]
- TLS‑RPT: Mandatory reporting for encryption failures. [blog.redsift.com]
These open standards replace the old gateway‑based SEEMail system and improve interoperability, visibility, and sender authentication across agencies and their partners. [blog.redsift.com]
Quick Refresher: SPF, DKIM & DMARC
SPF (Sender Policy Framework)
Defines which mail servers are authorised to send email on behalf of your domain, preventing spoofing attempts.
DKIM (DomainKeys Identified Mail)
Adds a digital signature to every outbound message, enabling receivers to verify that emails haven’t been tampered with.
DMARC (Domain‑based Message Authentication, Reporting & Conformance)
Builds on SPF and DKIM. DMARC lets domain owners instruct receivers to quarantine or reject spoofed emails—and provides reporting for visibility.
Together, SPF + DKIM + DMARC ensure your domain cannot be impersonated, dramatically reducing the chance of email‑based attacks.
Why This Matters for Your Organisation (Even if You’re Not a Government Agency)
While the mandate applies directly to government agencies, any organisation that communicates with them is affected. Misaligned SPF, DKIM, or DMARC settings may cause your emails to be quarantined or rejected by government systems. [blog.redsift.com]
Additionally, private‑sector organisations face the same phishing threats—meaning implementing these controls is no longer optional for maintaining trust and deliverability.
Check Your Current Status
You can check your DMARC, SPF, and DKIM configuration instantly at:
Empower Your Team with Flexible IT Training
We offer a range of IT training options tailored to your needs:
- Self-paced learning
- Managed learning with courses assigned to suit specific roles
- On-site personalised training or via web meeting