Half of New Zealand Government Organisations Fail to Meet Email Security Standards Ahead of SGE Deadline
- Half of New Zealand Government organisations have yet to meet the highest DMARC security standard ahead of the October 2026 SGE deadline.
- DMARC adoption at the reject level has doubled from 26% in 2025 to 50%, but significant gaps remain across the public sector.
SYDNEY, Australia – 7 September 2026 – Proofpoint, Inc., a global leader in human and agent cybersecurity, has found that half of New Zealand Government organisations have yet to implement the strictest level of email cybersecurity measures required under the government’s Secure Government Email (SGE) framework, leaving them exposed to risks of email fraud that could impact the New Zealand public, government workers, and stakeholders.
The findings come less than two months before the SGE requirement takes effect in October 2026. The framework requires government domains to implement Domain-based Message Authentication, Reporting and Conformance (DMARC) at the ‘Reject’ level, which is the strongest level of DMARC protection. DMARC has three policy levels – Monitor, Quarantine, and Reject. While Monitor provides visibility into email activity and Quarantine directs suspicious messages to spam, Reject provides the strongest protection by preventing unauthorised emails from being delivered.
The National Cyber Security Centre (NCSC) reported NZ$8.3 million in direct financial losses in the first half of 2026[1], with phishing and credential harvesting the second most reported incident type. DMARC authentication effectively detects and prevents email spoofing techniques used in phishing, business email compromise (BEC), and other email-based attacks.
Proofpoint's analysis found that 97% of New Zealand Government organisations have adopted DMARC, but only 50% have implemented the required Reject policy. The analysis covered more than 200 primary organisations listed on the New Zealand Government Organisations Register, including Defence, Home Affairs, Foreign Affairs and Trade, Education, Social Services, Energy, and Treasury and Finance. These organisations hold significant amounts of information relating to New Zealanders and support critical government services and national security.
“DMARC is a critical layer of protection against email impersonation and phishing, one of the most prevalent threats facing New Zealand organisations in this AI era,” said Steve Moros, Senior Director, Advanced Technology Group, Asia Pacific and Japan at Proofpoint. “We welcome the New Zealand Government’s continued efforts to strengthen DMARC adoption across the public sector. With the SGE deployment deadline approaching, organisations need to act now to ensure trusted government domains cannot be easily abused. Strong email authentication is an important step in protecting public information, government services, and the trust New Zealanders place in them.”
The full findings of Proofpoint's DMARC analysis of New Zealand's Government agencies show:
- 50% of New Zealand Government entities have implemented the highest DMARC protection level: Reject.
- 12% have a Quarantine policy, meaning suspicious emails are sent to a spam folder.
- 35% have a Monitor policy, which only tracks DMARC activity without blocking or quarantining emails.
- 3% have no DMARC record at all.
The New Zealand government has extended the deadline for the Secure Government Email (SGE) standard from October 2025 to October 2026. Proofpoint published its first DMARC analysis of New Zealand’s government domains in 2025 and found that only 26% of them had implemented a Reject policy. A year later, that figure has doubled to 50%, representing significant progress, but with half of government domains still not meeting the standard, gaps remain ahead of the October 2026 deadline.
Best Practices for Enhanced Email Security:
- Check the validity of all email communication and be cautious of potentially fraudulent emails impersonating colleagues, suppliers, and stakeholders.
- Be cautious of any communication attempts that request log-in credentials or threaten to suspend service or an account if a link isn’t clicked.
- Adopt phishing-resistant multifactor authentication, such as passkeys.
Methodology
This analysis was conducted in August 2026 using data from 200 organisations on the New Zealand Government Organisations Register.
About Proofpoint, Inc.
Proofpoint, Inc. is a global leader in human and agent cybersecurity, securing how people, data, and AI agents connect across email, cloud, and collaboration tools. Proofpoint is a trusted partner to over 80 of the Fortune 100, over 14,000 large enterprises, and millions of smaller organisations in stopping threats, preventing data loss, and building resilience across people and AI workflows. Proofpoint’s collaboration, data, and AI security platform helps organisations of all sizes protect their people and adopt AI securely and confidently. Learn more at www.proofpoint.com.
Proofpoint is a registered trademark or tradename of Proofpoint, Inc. in the U.S. and/or other countries. All other trademarks contained herein are the property of their respective owners.