/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Test finds outgoing White House emails are not in compliance with a DHS directive to implement the DMARC security protocol that verifies the sender

The security advocacy group Global Cyber Alliance tested the 26 email domains managed by the Executive Office of the President (EOP) … Tweets: @kylegriffin1 Tweets: Kyle Griffin / @kylegriffin1 : A security advocacy group tested the 26 email domains managed by the Executive Office of the President and found that 18 are not in compliance with a DHS directive to implement a security protocol that verifies the emails as genuinely from the White House. https://www.axios.com/...

Axios Joe Uchill

Context & Ripple Effects

Six months after DHS ordered federal agencies to adopt DMARC and STARTTLS, Global Cyber Alliance tested all 26 email domains run by the Executive Office of the President and found 18 still fail to verify their senders — meaning mail that looks like it comes from the White House can be spoofed. The finding lands on the office whose correspondence is the highest-value spoofing target in government, and it previews a wider gap: later research would show even CIA, NSA and DOD had not implemented DMARC across all their domains by the directive's deadline.

First-order effects

  • The Executive Office of the President now has to bring 18 of its 26 domains into DMARC compliance or explain the shortfall to DHS, which set the mandate.

Second-order effects

  • Independent testers like Global Cyber Alliance gain a repeatable audit playbook — scanning agency domains against published directives — that turns slow federal adoption into public, nameable failures.

Third-order effects

  • If the pattern holds, DMARC becomes a case study in unfunded mandates: DHS issues the standard, agencies miss deadlines, and enforcement only arrives years later, as with the White House's 2023 order telling agencies to shore up practices many had again failed to fully adopt.

The trend: Federal email-security adoption is drifting from directive to directive — mandated in 2017, still incomplete at the Pentagon and intelligence agencies in 2018, and re-ordered by the White House in 2023 — because compliance is measured but not enforced.