IT Blog

blog

New Zealand Government Makes DMARC Mandatory — What It Means for Your Organisation

New Zealand has officially strengthened its national cybersecurity posture with the introduction of the Secure Government Email (SGE) Common Implementation Framework, which mandates DMARC enforcement (p=reject) across all government email-enabled domains. This significant shift modernises email security practices and replaces the legacy SEEMail, scheduled for full retirement in 2026. blog.redsift.com

Why is DMARC Now Mandatory?

Email remains the number one entry point for cybercrime, including phishing and domain spoofing. CERT NZ has reported growing year‑on‑year spoofing incidents resulting in losses exceeding $1.6 billion in 2024. By enforcing DMARC at p=reject, the SGE framework prevents fraudulent emails from ever reaching inboxes—protecting citizens, agencies, and partner organisations. blog.redsift.com

What the SGE Framework Requires

Under the SGE framework, the following controls are now mandatory for all New Zealand government domains by October 2025

  • SPF: Must end with -all (hard fail), ensuring only authorised senders can use the domain. [blog.redsift.com] 
  • DKIM: All outbound email must be cryptographically signed to ensure message integrity. [blog.redsift.com] 
  • MTA‑STS: Enforced to guarantee encrypted and authenticated email transmission. [blog.redsift.com] 

These open standards replace the old gateway‑based SEEMail system and improve interoperability, visibility, and sender authentication across agencies and their partners. [blog.redsift.com]

Quick Refresher: SPF, DKIM & DMARC

SPF (Sender Policy Framework)

Defines which mail servers are authorised to send email on behalf of your domain, preventing spoofing attempts. 

DKIM (DomainKeys Identified Mail)

Adds a digital signature to every outbound message, enabling receivers to verify that emails haven’t been tampered with.

DMARC (Domain‑based Message Authentication, Reporting & Conformance) 

Builds on SPF and DKIM. DMARC lets domain owners instruct receivers to quarantine or reject spoofed emails—and provides reporting for visibility. 

Together, SPF + DKIM + DMARC ensure your domain cannot be impersonated, dramatically reducing the chance of email‑based attacks. 

Why This Matters for Your Organisation (Even if You’re Not a Government Agency)

While the mandate applies directly to government agencies, any organisation that communicates with them is affected. Misaligned SPF, DKIM, or DMARC settings may cause your emails to be quarantined or rejected by government systems. [blog.redsift.com] 

Additionally, private‑sector organisations face the same phishing threats—meaning implementing these controls is no longer optional for maintaining trust and deliverability.

Check Your Current Status

You can check your DMARC, SPF, and DKIM configuration instantly at:

Empower Your Team with Flexible IT Training

We offer a range of IT training options tailored to your needs:

  • Self-paced learning
  • Managed learning with courses assigned to suit specific roles
  • On-site personalised training or via web meeting