Skip to Main Content
Research dossier · 2026
Research in productionTarget release October 13, 2026

U.S. election email security tracker 2026

A responsibly disclosed measurement of public email-authentication records: not a vulnerability ranking, compromise assessment or claim about election integrity.

Why this matters

Without an enforcing policy, participating receivers have less domain-owner direction for forged messages that use a state office or campaign’s exact From domain; this does not establish that such messages were sent or delivered.

This page stays out of search until source, methodology, chart, accessibility, SEO and claims-language reviews pass. It contains no placeholder findings.

Tracker preview

The map opens after the evidence closes

The published tracker will show one reviewed state election-office domain for every state and Washington, D.C. No pre-release findings appear on this page.

Public DNS records describe published configuration. They do not prove compromise, vulnerability or election interference.

  1. 01 · September 21

    Campaign cohort freezes

  2. 02 · September 22

    Initial public-DNS scan

  3. 03 · September 23

    Private office notification

  4. 04 · October 8

    Post-correction public-DNS scan

  5. 05 · October 13

    Target release after review

Why this matters

What is the risk when DMARC is missing?

Election offices and campaigns send high-trust, time-sensitive messages. A missing or monitoring-only policy leaves less protection at participating receivers when a forged message using their visible From domain fails aligned authentication.

Learn how DMARC evaluates a message →
Risk context

01 · DOMAIN IDENTITY

The visible From address can be forged

An attacker can send a message that displays the organization's exact domain in the From line. Without a valid DMARC record, participating receivers have no DMARC handling request from that domain owner when aligned SPF and DKIM fail.

02 · PRACTICAL HARM

False election messages can carry unusual urgency

A forged message appearing to come from an election office or campaign could circulate false voting instructions, seek credentials or donations, or redirect a recipient. Public DNS state alone is not evidence that this happened, that a message was delivered, or that election systems were compromised.

Three different DNS states

No valid DMARC
No domain-owner DMARC policy. Aggregate reports cannot be requested through that record.
DMARC at p=none
Monitoring only. Reports may be collected, but the owner requests no DMARC-based quarantine or rejection.
p=quarantine or reject
The owner asks receivers to act on messages that fail aligned authentication. Receiver behavior can still vary.

Risk, not incident evidence: this DNS state does not prove spoofing, fraud, compromise or weak internal controls. DMARC also does not stop lookalike domains, abuse of a compromised legitimate account or every phishing technique.

Scope

What this study measures

  • 01One verified organizational email domain for each state election authority and Washington, D.C.
  • 02A complete 51-authority census rather than a sample or a campaign-domain proxy.
  • 03Named public-DNS observations only after private notice, correction review, and a post-window rescan.
Research questions

Questions it will answer

  1. 01How many state election authorities publish and enforce DMARC?
  2. 02How many named offices request aggregate reports and publish exactly one SPF record?
  3. 03How much changes between responsible-disclosure notification and the final rescan?
Release plan

How this research becomes citable

  1. September 21, 2026

    51-authority cohort freeze

  2. September 22, 2026

    Initial scan

  3. September 23, 2026

    Private state-office notification

  4. October 7, 2026

    Corrections close

  5. October 8, 2026

    Post-correction rescan

  6. October 13, 2026

    Public release after legal/editorial review

    Release is conditional on the stated evidence and review gates.

Delivery package
What will be available
  • Searchable state-office map and final public-DNS observation table.
  • Before-and-after state-office measurements with exact denominators and evidence hashes.
  • Disclosure log, corrections ledger and neutral claims review.
  • Machine-readable CSV/JSON for all 51 reviewed authority rows.
  • A 40–60-target election-security and state-government media brief.

Media posture

Provide 3–5 specialist reporters an embargoed methodology and aggregate preview after disclosure closes.

Methodology

How we measured this

  1. 1.Freeze the complete 51-authority cohort on September 21 from Election Assistance Commission profiles and official authority websites.
  2. 2.Scan on September 22, notify named state offices on September 23, close corrections on October 7, and perform the final rescan on October 8.
  3. 3.Query _dmarc TXT, apex TXT, MX and default-selector BIMI through a recorded Google or Cloudflare public resolver with a five-second timeout and two DNS tries. Retain raw answers, response state, resolver, timestamp, parser version, and evidence hashes. NXDOMAIN and NODATA count as an observed absence; a timeout, refusal or server failure marks the entire domain unobserved and excludes it from denominators.
  4. 4.Treat exactly one syntactically valid v=DMARC1 record as publication. RFC 9989 defaults an omitted p tag to none; t=y lowers the effective requested handling by one level. Effective quarantine and reject count as enforcement, while a valid rua mailto destination counts as aggregate reporting.
  5. 5.Describe SPF narrowly: report whether exactly one v=spf1 record was observed, flag multiple records separately, and publish modeled recursive lookup exposure only for complete include/redirect evaluations. The model follows references to depth eight and never treats an unresolved nested query as a passing result.
  6. 6.Retain a disclosure log and include corrections or contextual replies received before the correction window closes.

Limitations

  • Public DNS configuration does not prove that a domain has been abused or compromised.
  • The reviewed organizational domain may not expose every separate sending subdomain or vendor-managed mail stream.
  • SPF lookup exposure is a record-structure model, not a full check_host() evaluation for a specific sender IP and message.
Source record

Trace the evidence

EAC state election profiles

Official starting point for all state election authorities.

RFC 9989: DMARC

Current IETF DMARC policy-record syntax, discovery and evaluation standard.

RFC 9990: DMARC aggregate reporting

Current IETF specification for DMARC aggregate-report requests and report format.

RFC 7208: SPF

IETF SPF record syntax, multiple-record error handling and DNS-lookup limit.

Publication policy

State election-authority domains may be named after ten business days of notice, correction review, and a post-window rescan. Legal and neutral-language approval are mandatory.

Questions about the tracker

How to read and reuse the observations

What does the U.S. election email security tracker measure?

The U.S. election email security tracker measures public DMARC, SPF, BIMI and MX records for one reviewed organizational domain from every state election authority and Washington, D.C.

Does the tracker evaluate private incidents or election integrity?

The U.S. election email security tracker does not evaluate private incidents or election integrity. A DNS record shows a domain owner's published email-authentication instructions at the observation time; it does not observe private controls, mail flow, incidents or voting systems.

Why can the final report name state election-authority domains?

The cohort is a complete census of 51 public organizational domains, and each authority receives ten business days of private notice before named publication. The tracker reports narrow DNS observations rather than a security score or incident claim.

When are the election-domain records measured?

The U.S. election email security tracker freezes its 51-authority cohort on September 21, scans on September 22, sends private state-office notices on September 23, and performs its post-correction rescan on October 8. Corrections received through October 7 are independently checked before the planned October 13 release.

Can journalists and researchers reuse the tracker data?

After the U.S. election email security tracker is published, its aggregate data, charts and citation files are available under CC BY 4.0. Attribution should link to the report so readers can inspect the cohort, denominators, scan dates and limitations.