Back to Learning CenterEmail Authentication

Why must NZ government domains adopt new email standards?

By Samuel ChenardSeptember 29, 20253 min read

In brief

New Zealand’s Digital Government has released the Secure Government Email (SGE) Framework, a modern set of technical controls that replace the legacy…

Why must NZ government domains adopt new email standards?

New Zealand’s Digital Government has released the Secure Government Email (SGE) Framework, a modern set of technical controls that replace the legacy SEEMail gateway and bring open-standard authentication to every public-sector inbox. New Zealand email security framework The framework mandates a suite of controls that any agency handling restricted, sensitive, or confidential information must implement. Although the initial focus is on high-classification bodies, the guidance strongly encourages every government domain to comply.

Who is affected?

While the most stringent requirements target agencies that manage classified data, the ripple effect reaches all public-sector entities because secure communication must be interoperable across the entire ecosystem.

RequirementMandatory forWhy it matters to everyoneProtect confidential, sensitive, and restricted emailAgencies handling classified dataAll partners must exchange messages securely.DMARC with p=reject for every email-enabled domainClassified-data agencies and any domain they use to send mailAttackers spoof any brand; enforcement protects the whole ecosystem.Retirement of SEEMail in 2026Current SEEMail usersThe SGE framework becomes the baseline for all government domains.

The bottom line: compliance starts with high-classification agencies, but by October 2025 every public-sector domain should meet SGE standards.

Core technical controls (plain language)

1. Authenticate the sender

2. Encrypt the channel

  • Enforce TLS 1.2 or higher for all mail transport.
  • Deploy MTA-STS + TLS-RPT to require encryption in transit and receive downgrade-attack alerts.

3. Protect the content

  • Implement Data-Loss Prevention (DLP) to block outbound messages that contain data above the sender’s clearance level.

Implementation timeline

  • June 2025: SGE v1.0 published – guidance available as a PDF.
  • October 2025: All applicable agencies should have aligned external domains with SGE.
  • 2026: Legacy SEEMail gateway retires; non-compliant agencies risk isolation.

Consequences of non-compliance

The All-of-Government Service Delivery (AoGSD) team will monitor DMARC, SPF, and MTA-STS records (DKIM soon) and flag any domain that falls short. Agencies will be required to demonstrate compliance and remediate promptly.

At a glance

Quick Takeaways

  • Adopt SPF, DKIM, and DMARC p=reject to stop email spoofing.
  • Enforce TLS 1.2 or higher and enable MTA-STS for transport-level encryption.
  • Deploy DLP to safeguard sensitive data in outbound mail.
  • Start monitoring your domain’s authentication status now – Palisade offers a free checker.
  • Plan for automation; manual updates to DNS records are error-prone and can exceed lookup limits.
  • Target enforcement early; p=none provides no protection.
  • Prepare for the 2026 SEEMail retirement by modernizing your email stack today.

Questions readers ask

Frequently Asked Questions

Fix SPF limits without rebuilding your record

Start in Palisade.

Get started
Palisade domain settings with Hosted SPF enabled

Share this article

Samuel Chenard

Written by

Samuel Chenard

CEO & Co-Founder, Palisade

Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.

More from Samuel

Related articles and tools