Back

Securing Government Email

Securing Government Email

Securing Government Email

Status: Live
Published: 01/01/2019
Security level: Official
Amended / Internally developed: No
Live on platform: 23/03/21
Retired on platform:
Target Audience: Technical / General
Authoring body: Government Digital Service (GDS)
Grading: no grading applied
Guidance
Abstract

This guidance applies to all email domains that public sector organisations run on the internet. It also helps ensures that public sector organisations exchanges email securely with other public sector organisations. Protecting emails in transit makes it difficult for domains to be spoofed.

All public sector emails must be kept secure by:

Encryption and authentication only work if both the sender and the recipient use them.

The Government Digital Service recommends protecting email by:

  • forcing TLS when sending to .gov.uk

  • forcing TLS when sending to any other domains that supports it if the local risk profile requires it

  • using extra encryption services if needs be

Category: Security