We scored 80 government domains — tax authorities, foreign ministries, central banks, and national portals across the UK, Japan, Germany, France, Canada, Australia, the EU institutions, and thirteen further jurisdictions — using NODA's dual-axis methodology: a Health score measuring whether DNS actually works, and a Best Practice score measuring whether it's configured the way current standards recommend, across 41 checks in five categories.

The sampling frame here is deliberate. US federal domains operate under OMB Memorandum M-08-23, a 2008 mandate requiring DNSSEC on all .gov zones — a policy variable that would confound any attempt to separate institutional capability from institutional instruction. This sample excludes .gov entirely and draws from jurisdictions with no comparable signing requirement, so the adoption rate reported here reflects what these agencies chose to do, not what they were told to do.

A note on scope: this list was compiled from major-agency and central-portal domains across nineteen jurisdictions, not a canonical index of all government DNS — treat it as a representative sample rather than an exhaustive census. All 80 domains were checked live on August 11, 2026; DNS configurations drift, so exact figures will shift over time.

The numbers

MetricValue
Domains scored80
Average Health score95.6 / 100
Health standard deviation4.45
Health range75 – 100
Average Best Practice score84.5 / 100
Best Practice range60 – 100

Health holds up well across this sample, consistent with the pattern in every sector this research has covered so far — public-sector DNS infrastructure is not, on this evidence, more fragile than its private-sector counterparts. The meaningful variation, as usual, sits on the Best Practice axis, and one component of that axis is worth isolating from the rest.

The highest DNSSEC adoption we've measured came from the one sector under no obligation to adopt it.
Government Best Practice score distribution histogram

DNSSEC: the highest adoption we've measured, and no mandate behind it

33.8% of the domains in this sample have DNSSEC enabled. Set against the 7% global secure-delegation baseline reported by APNIC for 2025, that is roughly 4.8 times the global rate — and it is the highest adoption figure NODA has recorded across any of the twelve sectors scored to date, ahead of DNS/hosting infrastructure specialists (29.2%), financial services (25.3%), and the hyperscale cloud providers who build DNSSEC automation tooling for other people's domains (20.4%).

None of the nineteen jurisdictions sampled here operate under a signing mandate comparable to OMB M-08-23. Estonia (eesti.ee, ria.ee), the Netherlands (rijksoverheid.nl, belastingdienst.nl), and Sweden (skatteverket.se) — all scoring a perfect 100 on Best Practice in this sample — suggest one candidate explanation: agencies with established digital-government programs appear to fold DNSSEC into the same operational discipline as any other infrastructure requirement, independent of whether a central mandate exists.

Why it matters

DNSSEC cryptographically signs DNS responses so a resolver can verify they haven't been altered in transit. For a government domain — where a forged response could redirect a citizen toward a convincing fake of a tax-filing or benefits portal — the absence of DNSSEC is not a hypothetical risk category.

Where the same institutional habit doesn't extend: DKIM

The DNSSEC finding above is the headline, and it deserves to stand on its own. But it would be a disservice to the sample to stop there, because the same domains that lead on DNSSEC show a markedly different pattern on mail authentication.

74.6% of applicable domains in this sample are missing a DKIM signature. That is the weakest DKIM figure NODA has measured across any sector to date — notably worse than the museums sector's 35.5%, the previous low. DMARC and SPF, by contrast, look closer to what the DNSSEC figure would predict: DMARC is missing outright on only 11.3% of domains, and SPF's lookup-limit check flags 22.5% — both broadly in line with, or better than, other sectors scored so far.

The gap between DNSSEC and DKIM in the same sample is informative in its own right. DNSSEC is a zone-level, largely one-time cryptographic decision, typically owned by whichever team manages the authoritative nameservers. DKIM is a per-sending-source operational commitment — every mail stream, including third-party services sending on an agency's behalf, needs its own key provisioned and rotated. A single strong institutional habit around signing zones does not automatically extend to the more fragmented, multi-vendor discipline that mail authentication requires. That distinction is worth keeping in mind when reading any adoption figure as a single measure of "security maturity" — the underlying operational shape of the two commitments is genuinely different.

Why it matters

DKIM lets a receiving mail server cryptographically verify that a message claiming to be from a domain was actually authorized by that domain's mail infrastructure. Without it, DMARC's enforcement value is reduced even where a DMARC record exists — a policy of p=reject is only as strong as the authentication signals feeding into it. For government correspondence in particular, an unauthenticated mail stream is a workable input for phishing campaigns impersonating official communications.

Government fail rate by DNS scoring category

Network redundancy: a mixed picture

45% of domains in this sample (36 of 80) place all nameservers within a single Autonomous System, per NODA's ASN Diversity check — lower concentration risk than the 75.7% seen in the museums sector, but still a substantial minority with no independent-network redundancy on their authoritative DNS. As with the museums finding, this is less concerning where the single AS in question is a large anycast network with inherent resilience, and more concerning where it is a single non-anycast provider with no fallback path; this dataset does not distinguish between the two without a further pass.

Government DMARC policy distribution donut chart

Best and worst performers

Top 5 (Best Practice score):

DomainBest PracticeHealth
rijksoverheid.nl10098
belastingdienst.nl10098
skatteverket.se100100
eesti.ee100100
ria.ee100100

Bottom 5:

DomainBest PracticeHealth
dvla.gov.uk6099
u.ae6492
defra.gov.uk6799
hmrc.gov.uk6799
efd.admin.ch6875

All ten are genuine, resolving domains with specific, checkable Best Practice gaps — missing DNSSEC, missing DKIM, or nameserver-configuration findings — not artifacts of a bad domain list.

The takeaway

This sector offers a cleaner test of a specific question than most: does DNSSEC adoption depend on being told to do it? On this evidence, not necessarily — these nineteen jurisdictions have the highest secure-delegation rate NODA has measured anywhere, with no comparable mandate in force. What the same dataset also shows is that institutional discipline is not a single, transferable trait. The same agencies that lead on zone signing show the weakest DKIM adoption measured to date. Whatever produces consistency in one operational commitment does not automatically produce it in a different one with a different shape — worth bearing in mind for any organization tempted to treat "we do DNSSEC" as a proxy for "our DNS security posture is handled."

What to do about it

For agencies and operators in this sector specifically:

  • If DNSSEC is already deployed, audit DKIM coverage next — the finding above suggests this is the more likely gap in an otherwise disciplined setup, particularly across third-party mail senders acting on the domain's behalf.
  • Treat DKIM as a per-sender inventory problem, not a one-time configuration task — every mail stream, including newsletter platforms, case-management systems, and constituent-communication tools, needs its own key.
  • Where nameservers sit in a single AS, confirm whether that AS is a resilient anycast provider before treating it as a finding requiring action — the risk profile differs meaningfully between the two cases.

⇩ Download full report (PDF)

Curious where your own domain lands? Run it through NODA and see the same 41 checks scored live.

Scored using NODA, a dual-axis DNS Health + Best Practice methodology (41 checks, 5 weighted categories). Read the full methodology: NODA-v1.0 Specification.