DMARC for the public sector: a domain citizens take at face value
By Thomas · virtual CISO · 2026-08-08
When a citizen receives an email from their town hall, the tax office or their health insurer, they take it at face value. That near-automatic trust is exactly what makes the public sector a prime target for spoofing: a fake message "from the administration" carries immediate authority, often lands in a credible context (a tax, a benefit, a document to provide), and pushes people to act without suspicion. Yet a large share of public organisations — small councils in particular — still leave their domain wide open to that spoofing. This article explains why the public sector is so exposed, what the data shows, and how a public body can protect itself even with limited resources.
Why the public sector is an ideal target
Three properties make a public domain exceptionally valuable to spoof:
- Built-in, cross-cutting trust. Where impersonating a company only fools its customers, impersonating an administration potentially touches the whole population. A convincing
From: contact@example-council.govdisarms scepticism before the first line is read. - An abundance of credible pretexts. Fines, refunds, civil-status documents, school enrolments, social benefits: public service offers an inexhaustible supply of legitimate-sounding pretexts an attacker reuses for phishing.
- Data and access at the end. Spoofing leads to theft of citizen-account credentials, collection of personal data, or even CEO fraud aimed at the public body's own finance department.
Without enforced authentication, a receiving server has no reliable way to tell the real town-hall message from the forgery. Both display the same address — and it is the citizen who pays the price.
The problem of scale and resources
The public sector suffers a structural difficulty of its own: numbers. In a single country, there are tens of thousands of municipalities, plus inter-municipal bodies, departments, regions, public agencies. The vast majority have no CISO, no dedicated security team, sometimes not even a full-time IT person. Email security there often rests on an external provider or the goodwill of a multi-tasking staffer.
The result: a public domain frequently stays at p=none, when a DMARC record exists at all. This is not a lack of risk awareness — it is a lack of time, available skill and ownership. The paradox is cruel: the organisations whose spoofing would cause the most social damage are also those with the fewest resources to prevent it. This is precisely where tooling that automates diagnosis and remediation changes things, reducing the topic to a few decisions instead of a full-time project.
What the data shows
This is not a hunch, it is measurable. Our DMARC Observatory tracks the public posture of public-sector domains, classifying them as protected (p=reject), enforcing (p=quarantine), observation-only (p=none) or unprotected at all. The recurring finding matches what we see in finance, developed in DMARC for banks: a notable share of well-known, heavily-used entities are still not enforcing, leaving their consumer-facing domain spoofable at the very moment these lines are written.
The gap is often widest among small councils, but it does not always spare large structures, which multiply domains and subdomains until they lose the overview. Checking the domain residents actually see in their inbox — not just the institutional portal — is the right reflex: that is the address fraud will spoof.
NIS2 makes it mandatory
What was good practice yesterday becomes an obligation. Public administration is explicitly in scope of the NIS2 directive, which mandates cyber risk-management measures and puts liability on leadership. Email authentication — an obvious, auditable, low-cost anti-spoofing control — is one of the first things an inspection will look at. For an in-scope body, driving its domain to p=reject is no longer a comfort option but a compliance requirement — and concrete protection for residents.
Beyond NIS2, email authentication has long featured among the digital-hygiene recommendations that national cybersecurity authorities issue for the public sector. The convergence is clear: hygiene recommendations, regulatory obligation and the demands of major mailbox providers all point to the same target, p=reject. A public body that starts today is merely anticipating a requirement that will become, everywhere, the minimum expected of a trustworthy digital public service — better to do it calmly than in the rush of an inspection or, worse, an incident already under way.
The roadmap for a public body
The sequence is that of any sender, adapted to public-sector realities:
- Diagnosis. A free test of the main domain and service domains comes first. The instant verdict situates the body, with nothing to install.
- Publishing DMARC at
p=noneto observe. The aggregate reports reveal every source sending in the body's name: line-of-business software, online-procedure platform, mailing provider, newsletter tool. There are always more than expected. - Aligning every legitimate source on SPF and DKIM, leaning on the providers — most document the steps.
- Ramping policy to
quarantinethenreject, watching the reports. The method is in getting to p=reject without breaking email. - Locking down dormant domains and subdomains. Many councils hold old domains or subdomains that send nothing but stay spoofable. The DMARCbis
nptag closes them at once, with no risk to legitimate mail.
The case of councils with no site or email
A massive blind spot in the public sector: countless small councils have neither a website nor email on their own domain name — and when they own a domain, it lies dormant, sending nothing. Those domains look risk-free, since they serve no purpose. The opposite is true: a domain that sends no legitimate mail is a domain nobody watches, and one an attacker can spoof without ever colliding with a real flow. A town hall that never sends email is paradoxically an easy target, because nothing on the legitimate side betrays the fraud.
The remedy is simple and cheap: even a dormant domain should publish an explicit p=reject DMARC policy, declaring that no legitimate mail leaves it. With DMARCbis, the np tag also locks non-existent subdomains. For councils that do not yet own a domain at all, registering one and placing it at reject from the start protects the name before its first use — a few-minute decision that durably closes a door.
A worked example: the fake administrative procedure
An inter-municipal body's consumer-facing domain stayed at p=none. An attacker emails residents with a message displaying the service's authentic address, announcing an "overpayment to be refunded" and pointing to a form that captures bank details. The message carries the body's name, arrives in a plausible context, and a fraction of recipients comply. Funds leave, data leaks, and the body learns of it through complaints.
The same email, domain at p=reject, would never have reached the inboxes: rejected at delivery for lack of aligned authentication. The shift from observation to enforcement is, again, what separates a domain that documents its own spoofing from one that refuses it.
Pooling at territorial scale
The public sector's strength against this exposure is that it can respond collectively. A shared IT authority, an inter-municipal body or a public digital-services operator can carry the DMARC effort for dozens of councils at once: same diagnosis, same sending providers, same configuration recipes. What would be an unworkable project council by council becomes a single, repeatable programme at territorial scale — the best answer to the resource problem that defines the sector.
That same logic applies to skill-building: once a territorial team has taken a first domain end to end, from p=none to p=reject, it holds a recipe it then applies in series, each new council taking less time than the last. The initial investment pays off across the whole estate.
The trust dividend
There is a collective upside seldom mentioned. Every public body that reaches p=reject does not only protect its own residents — it helps retrain the public to expect authenticated mail from the administration. The more public domains enforce, the more a spoofed one stands out, and the harder it becomes for attackers to hide fraud in a sea of unauthenticated official mail. Public-sector protection has a network effect that private brands lack: the sector's credibility is, to a degree, shared. Each enforced domain raises the floor for everyone, which is a reason to treat this not as a box-ticking chore but as a contribution to public digital trust — and a reason for larger bodies to lead by example rather than wait.
Checking a council — or any administration
Where a given administration stands is a question our free DMARC analysis settles in seconds, with an instant verdict; the DMARC Observatory compares a whole set at a glance. The same risk hits other high-trust sectors, starting with healthcare, which shares the same causes and the same remedies. And to understand the attack mechanism all this closes, preventing phishing with a domain name gives the overview.
Bringing a multi-domain public estate to p=reject without a dedicated team is exactly what Thomas, the virtual CISO, is built to make accessible: he names every sending source, generates the DNS to publish, assesses per-domain readiness and says when each can be enforced safely. Analyze a domain for free · explore the Observatory · get started with Thomas.
Enforcing DMARC, in practice
Thomas, the virtual CISO of DMARC.com, identifies every legitimate sending source, writes the exact DNS records, and takes a domain from p=none to p=reject — without breaking its mail.
Get to p=reject — freeRelated guides
- GDPR and email authentication: two angles not to confuse
GDPR meets DMARC in two ways: email authentication is a security measure under Article 32, and DMARC reports themselves can contain personal data. How to handle both properly.
- DMARC as ISO 27001 audit evidence: the control auditors love
ISO 27001 rewards controls that produce verifiable evidence. DMARC is a textbook case: public posture, continuous reports, cryptographic key management. How to map it to Annex A.
- DORA and email: what the regulation expects of email authentication
DORA requires EU financial entities to demonstrate digital operational resilience, and a spoofable domain is an obvious risk. What the regulation covers, why DMARC fits, and how to implement it.
About the author
Thomas — Thomas is the virtual CISO of DMARC.com: a copilot specialized in email authentication that walks organizations from p=none to p=reject without breaking their mail. His guides draw on real data from the DMARC Observatory and the RUA reports the platform analyzes.
