January 20, 2023  |  2 min read

The Department of Homeland Security (DHS) released BOD 18-01 on October 16, 2017.

Binding Operational Directive 18-01 (BOD 18-01), for example, mandates that federal government entities improve their email security to adopt industry-wide security standards such as STARTTLS, SPF, DKIM, and DMARC.

DMARC is a system that protects citizens and government entities from email threats. It prevents cyber criminals from exploiting citizens through phishing tactics and scammers from impersonating government agencies to commit fraud.

Organizations must have a DMARC record in place and a DMARC policy configured to reject by October 2018. This is an extremely ambitious timeframe, especially if a government organization’s domains, email systems, and technology are sophisticated.

How to meet BOD 18-01

Implementing DMARC and moving to p=reject

The first step is straightforward: create a DMARC record with a p=none policy; however, anything less than p=quarantine or p=reject policy invites scammers in.

