SAN FRANCISCO, Feb. 20, 2018 -- Providing increased protection for people who use email and websites to communicate with the U.S. government, most federal civilian agencies have begun to adopt additional anti-abuse technologies outlined in a recent U.S. Department of Homeland Security directive. The DHS will be recognized for this progress when its chief cybersecurity official presents the keynote address at the M3AAWG 42nd General Meeting in San Francisco tomorrow.
“Over two-thirds of agencies have taken critical steps in enhancing email security and protecting users against email spoofing, up from less than 20 percent on the day the directive was issued,” said Jeanette Manfra, assistant secretary for the Office of Cybersecurity and Communications, DHS. “It is crucial for U.S. citizens to trust that an email from a government agency is legitimate.”
M3AAWG Chairman of the Board Severin Walker said, “We estimate that only about 35 percent of Fortune 500 companies are using DMARC today so this high adoption rate is a significant accomplishment, along with implementing the other security measures in the directive. Several of the major data breaches we've seen recently have started from phishing emails, which can be hard to identify, but these steps can help prevent these fake messages from getting to users and are important in protecting American citizens.”
DHS issued the directive in October 2017 calling for civilian agencies within the federal government to adopt proven industry standards over the course of a year that can help safeguard the confidentiality of internet-delivered data, minimize spam and protect against phishing. Binding Operational Directive 18-01 requires agencies to:
- Enable STARTTLS for better email security. This “opportunistic TLS” protocol supports encrypted email as it moves across the internet and helps protect against man-in-the-middle attacks where criminals eavesdrop on email communications without the users’ knowledge. (See TLS for Mail: M3AAWG Initial Recommendations for background information.)
- Improve email authentication by using SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail) and DMARC (Domain-based Message Authentication, Reporting and Conformance), making spam and phishing emails easier to identify and block.
- Improve web security with HTTP Strict Transport Security (HSTS) so that users’ browsers select the more secure HTTPS address option when navigating to a government agency’s website.
All of the cited technologies were developed or actively championed by M3AAWG over the last several years and are often referenced in the best practices documents it publishes to help the industry fight online abuse and crime. This includes Operation Safety-Net, Best Practices to Address Online, Mobile and Telephony Threats, which M3AAWG co-published with UCENet (Unsolicited Communications Enforcement Network, formerly the London Action Plan), describing exploitations aimed at businesses and governments with expert advice on how to protect against them, according to Walker.
A M3AAWG certificate of merit will be presented to the DHS on February 21 during the keynote for the work by the National Protection and Programs Directorate’s CS&C Office in implementing these standards across its civilian agencies. The M3AAWG 42nd General Meeting is expected to attract over 500 security experts, public policy advisors, law enforcement personnel and researchers during the February 19-22 event. It will offer over 50 sessions with authorities sharing information on email and text messaging, mobile and telephony threats, malware, Internet of Things security, hosting and cloud services, and DNS abuse.
About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)
The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.m3aawg.org) members represent more than one billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is driven by market needs and supported by major network operators and messaging providers.
Media Contact: Linda Marcus, APR, +1-949-887-8887 (U.S. Pacific), [email protected], Astra Communications
M3AAWG Board of Directors: AT&T; Cloudmark, Inc.; Comcast; dotmailer; Endurance International Group; Facebook; Google; LinkedIn; Microsoft Corp.; Oath (Yahoo and AOL); Orange; Proofpoint; Rackspace; Return Path; SendGrid, Inc.; Vade Secure and Verisign.
M3AAWG Full Members: 1&1 Internet AG; Agora, Inc.; Akamai Technologies; Cisco Systems, Inc.; CloudFlare; Cyren; ExactTarget, Inc.; IBM; iContact/Vocus; Inteliquent; Internet Initiative Japan; Liberty Global; Listrak; Litmus; McAfee Inc.; Mimecast; Oracle Marketing Cloud; OVH; PayPal; Rackspace; Spamhaus; SparkPost; Splio; Symantec; USAA; and Valimail.
A complete member list is available at http://www.m3aawg.org/about/roster.


SoftBank Q1 Profit Beats Forecast as Intel Rally and OpenAI Investments Boost Returns
Nintendo Shares Jump as Switch 2 Sales Boost Earnings
Sinopec Boosts Russian ESPO Oil Purchases as Middle East Supply Tightens
Daimler Truck Q2 Profit Falls 18%, 2026 Outlook Raised
Delta Flight Makes Emergency Landing in Atlanta After Cockpit Fumes Reported
Treasury Wine Estates Shares Jump as U.S. Overhaul Lifts FY2026 Outlook
Nvidia to Invest Up to $3 Billion in Blackstone-Backed Lancium
Alphabet Stock Slides as Google AI Pioneer Jeff Dean Exits to Launch Discovery Loop
Meta Ordered to Pay $567M Over Child Safety Violations in New Mexico
Alibaba Plans Revenue-Sharing Model for Qwen3.8-Max AI Commercial Users
UOB Q2 Net Profit Rises 10% as Wealth Management Growth Boosts Earnings
Natura Q2 Profit Plunges 92% as Financial Expenses Weigh on Earnings
Moderna Wins FDA Approval for mFLUSIVA mRNA Flu Vaccine for Adults 50+
Qantas Shares Climb as Long-Haul Pilot Deal Eases Strike Concerns
Sony, TSMC Eye $6.3 Billion Japan Chip Venture for Next-Gen Image Sensors
SK Hynix, Samsung Lead Asian Chip Stock Selloff After Sandisk, Western Digital Outlook
Apple Tests China’s CXMT Memory Chips for iPhones and MacBooks Amid AI Supply Crunch 



