HomeSecurityUS Government: Sets strict measures regarding .gov domains

US Government: Sets strict measures regarding .gov domains

The government US has announced that starting March 10, 2020, official signatures for the registration process for new .gov domains. The government decided to take this measure to reduce the chances of fraud, which could lead to the misuse of these domains by unauthorized organizations or users.

The U.S. General Services Administration (GSA) oversees the DotGov Program , which manages the .GOV top-level domain (TLD) and makes these domains available to U.S. government agencies (both local and federal).

Security enhancement for .gov domains

“Starting March 10, 2020, the DotGov Program will begin requiring official signatures on all letters of authorization when applying for a new .gov domain,” the DotGov Registrar said.

“This is a necessary measure to enhance security and prevent fraud through signature forgery.”

“This step will help maintain the integrity of .gov and ensure that .gov domains continue to be used only by official U.S. government organizations.”.

To request a .gov domain name, a government organization must prepare and send an authorization letter and complete an online form.

This letter must include a signature from the authorizing authority of the requesting organization.

US Government: Sets strict measures regarding .gov domains

This is the letter that should have an official signature by March 10, 2020, to prevent future attempts to register .gov domains without permission.

US Government: Sets strict measures regarding .gov domains

According to the GSA, .gov domains are granted exclusively to US government agencies and give legitimacy to government sites and electronic tools so that customers can be confident that the content comes from a legitimate source.

However, until the new rules are in place, almost anyone can register a .gov domain by using false information in the authorization letter required by the GSA. This can lead to a variety of scams.

A researcher confirmed that this scenario is possible. He said that in November 2019, he had applied for a .gov domain using a fake Google Voice number and a fake Gmail, along with official letterhead extracted from a legitimate government organization.

The GSA said it “has already implemented additional measures fraud prevention,” without detailing exactly what those measures are.

CISA has indicated that it would like to take over management of the .gov TLD (in place of the GSA), as “the .gov top-level domain (TLD) is a critical infrastructure for thousands of federal, state, and local government agencies across the country.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS