FedScoop: More than a third of federal agencies still have not adopted Department of Homeland Security-mandated security measures that stop attackers from spoofing email, according to an analysis of public records. And worse, many have misconfigured it.
As of Feb. 22, just 180 .gov domains — or 58 percent of the 311 .gov domains reviewed by Easy Solutions — had a policy for Domain-based Message Authentication, Reporting and Conformance, which DHS required as of Jan. 15.
Of those, nearly 30 are still vulnerable to subdomain spoofing because they haven’t set a proper subdomain policy.
The most significant government policy, business, and technology news and analysis delivered to your inbox.
Subscribe Nowi360Gov is an intelligent network of websites and e-newsletters that provides government business, policy and technology leaders with a single destination for the most important news and analysis regarding their agency strategies and initiatives.
Telephone: 202.760.2280
Toll Free: 855.i360.Gov
Fax: 202.697.5045
The most significant government policy, business, and technology news and analysis delivered to your inbox.
Subscribe Now