/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Research: CIA, NSA, DOD among federal agencies that have yet to implement DMARC email security on all their domains, despite a DHS directive to do so by Tuesday

Zack Whittaker / TechCrunch :

TechCrunch Zack Whittaker

Context & Ripple Effects

This deadline was a year in the making: DHS ordered federal agencies to adopt DMARC and STARTTLS email security in October 2017 as part of a push to stop sender-spoofing attacks against government inboxes. Compliance has been patchy ever since — an earlier test found outgoing White House emails out of compliance with the same directive months before this deadline.

The agencies now named as laggards are the ones that should know best: the intelligence and defense community had already been flagged for skipping basic email encryption back when the Army, Navy, and DARPA were found not to implement STARTTLS in 2015. The pattern suggests the problem is not awareness but execution across sprawling domain portfolios.

First-order effects

  • CIA, NSA, and DOD face the immediate exposure the directive was meant to close: their unsecured domains can still be spoofed to send email that appears to come from the US government.
  • DHS's directive now carries a public compliance record — agencies that missed Tuesday's deadline are identifiable by name, turning a technical benchmark into an accountability list.

Second-order effects

  • Congressional overseers and auditors gain a concrete artifact to press DOD and intelligence agencies on, since the directive gives them a stated deadline these agencies demonstrably missed.
  • Vendors selling DMARC implementation and monitoring services get a fresh pool of federal buyers whose compliance gap is now publicly documented.

Third-order effects

  • If directive-plus-deadline keeps producing partial compliance across agencies, campaigns, and political organizations — presidential candidates showed the same gap later, with only seven of 21 implementing DMARC — expect pressure to shift from voluntary directives toward enforced mandates or procurement requirements tied to email authentication.
  • Email spoofing of government and political senders stays viable as long as adoption lags, keeping impersonation among the cheapest attack vectors against US institutions.

The trend: Federal email security is moving from optional best practice to mandated baseline, but enforcement is outrunning actual adoption across even the most security-focused agencies.