What is SGE? Understanding New Zealand’s government requirement
Protect your government email domain from phishing, spoofing, and data breaches with Sendmarc’s expert solutions. Achieve full compliance with New Zealand’s Secure Government Email (SGE) framework quickly and effectively.
Book a demo or start a free trial today to secure your email and safeguard sensitive communications.
Why SGE matters for email security
Email remains a primary communication channel for government agencies, often carrying sensitive information that requires the highest level of protection. Unfortunately, these domains are frequent targets for cybercriminals who attempt to impersonate trusted senders, steal data, or disrupt operations.
SGE protects government email communications through strict authentication and encryption standards.
By implementing SGE, agencies can:
- Protect sensitive information: Emails are protected via advanced authentication and encryption protocols.
- Prevent phishing and spoofing attacks: It helps ensure that emails sent from government domains are verified, making it harder for threat actors to impersonate official senders.
- Enhance compliance: SGE aligns with the New Zealand Information Security Manual (NZISM), helping organizations meet regulatory and security standards.
In short, it isn’t just a technical requirement – it’s a vital step toward securing New Zealand’s government communications.
Understanding SGE: What is Secure Government Email?
SGE is an email security framework mandated by the New Zealand government to protect email traffic. It replaces the SEEMail system (which will be retired in 2026) with a modern approach that’s better aligned with today’s cybersecurity needs.
Key objectives
SGE has been introduced to:
- Improve the security of external email: By enforcing authentication and encryption, the framework reduces the risk of email-based attacks.
- Reduce spoofing: SGE uses protocols that verify sender identity and message integrity to help prevent impersonation.
- Retire legacy systems: The SEEMail service will be replaced with open standards, improving compatibility and flexibility.
Important terms and protocols
To fully understand the framework, it’s helpful to know the key email security protocols it uses:
- Domain-based Message Authentication, Reporting, and Conformance (DMARC): Allows domain owners to specify how unauthenticated emails should be handled.
- Sender Policy Framework (SPF): Defines which email servers are authorized to send messages on behalf of a domain.
- DomainKeys Identified Mail (DKIM): Uses cryptographic signatures to allow recipients to verify that an email hasn’t been altered in transit.
- Message Transfer Agent Strict Transport Security (MTA-STS): Enforces the use of Transport Layer Security (TLS) encryption for email transport, preventing downgrade attacks.
- Transport Layer Security Reporting (TLS-RPT): Provides visibility into encryption failures and delivery issues by generating reports for domain owners.
These protocols work together to provide layered protection and significantly strengthen email security.
Book a demo or start a free trial to see how we simplify the implementation and management of these standards.
SGE compliance requirements and deadlines
Compliance is mandatory for all New Zealand government agencies.
To achieve full compliance with the framework, organizations must implement:
- An SPF record with a fail (
-all) policy - DKIM signing on all outbound communications
- A DMARC policy of p=reject with strict DKIM alignment, where possible
- DMARC compliance evaluations on incoming messages
- TLS1.2 at minimum
- A defined MTA-STS record set to
enforce - TLS-RPT on all sending domains
Compliance deadline
All government agencies must be fully compliant by October 2025.
Failing to meet this deadline might result in:
- Increased risk of email-based attacks
- Loss of public trust
- Potential reputational damage
Resources and tools to help you implement SGE
While implementation might seem complex, the right tools and guidance can make the process effortless.
Sendmarc provides a comprehensive range of solutions to support your organization’s path to full enforcement:
- Automated DMARC, SPF, and DKIM management: Simplify the creation and maintenance of DNS records.
- MTA-STS and TLS-RPT configuration: Ensure secure email transport and gain visibility through detailed reporting.
- Real-time monitoring and alerts: Stay ahead of authentication failures and potential cyberthreats.
- Expert support: Access guidance from specialists in email security and DMARC compliance.
- User-friendly dashboards: Visualize email traffic, compliance status, and security metrics at a glance.
Get started with Sendmarc’s easy DMARC setup today.