The Korea Internet and Security Agency told municipal governments this week that public-facing email domains must publish DMARC policies at enforcement levels of quarantine or reject by 1 December, after a summer phishing campaign spoofed county tax-refund notices and drained small-business accounts that trusted .go.kr senders.

What broke

Attackers registered look-alike domains one character off from legitimate county portals, then sent VAT credit messages that passed weak SPF checks because many municipalities still monitor DMARC in reporting-only mode. KISA counted 14,800 fraudulent messages in August alone, with 3.2 billion won in attempted transfers stopped at cooperative banks. Unlike national ministries that moved to stricter policies after federal guidance, city and county domains lagged; internal scans showed 41 percent of municipal mail still at p=none.

Investigators said victims clicked because subject lines mirrored real property-tax calendars ahead of autumn filings. Several incidents targeted school meal suppliers paying invoices to spoofed education-office addresses—a reminder that municipal mail underpins payments far beyond citizen portals.

What KISA is ordering

Under the revised Public Sector Email Authentication Roadmap, any domain ending in .go.kr or operated by a local government must publish DMARC with p=quarantine minimum, alignment on both SPF and DKIM, and aggregate reporting to KISA’s centralized receiver. Domains that fail December checks lose access to the agency’s shared threat-intelligence webhook and may not display the “certified government mail” banner in partner banking portals.

KISA will host weekly office hours through November to help counties that outsource DNS to small ISPs. The Ministry of the Interior and Safety tied compliance to annual IT security grants: cities that miss the deadline forfeit a slice of smart-government subsidies unless they submit remediation plans signed by elected mayors.

Why municipalities lagged

Domestic DMARC adoption has trailed U.S. federal agencies for years; industry surveys cited by KISA still show Korean receivers rarely honor authentication failures. Municipal IT shops feared false positives would block welfare notices to elderly residents using legacy POP clients. KISA’s compromise allows a two-week monitoring window at p=quarantine before flipping to reject, provided aggregate reports show fewer than 0.1 percent legitimate mail misclassified.

The agency’s recent cooperation agreement with Japan’s JPNIC framed DMARC as infrastructure trust, not optional hygiene—a signal that Seoul wants parity with regional peers as cross-border invoice fraud rises.

Who carries liability

Legal advisers to two provincial councils told InfoHandle that spoofed tax mails could expose counties to civil claims if citizens prove reliance on authentic-looking .go.kr headers. KISA’s order does not create private causes of action but gives plaintiffs a clearer standard: p=none after December will be treated as negligent configuration in administrative appeals.

Managed service providers that host DNS for multiple counties must attest signing keys are rotated quarterly. KISA warned it will name noncompliant vendors in public bulletins—a reputational hit in a market where three integrators control most Chungcheong and Jeolla mail.

Implementation crunch

Engineers in Gyeonggi completed pilot flips for Suwon and Seongnam without major delivery drops; Jeolla counties with older Microsoft Exchange clusters reported DKIM key mismatches that took four days to fix. KISA shipped Ansible playbooks and Korean-language runbooks for common hosting stacks, but rural governments still lack staff who can read DNS TXT records without vendor help.

Banks said they will downgrade unauthenticated municipal mail to spam folders starting January, even if KISA grants short extensions. That pressure pushed holdouts faster than fines alone.

What officials should do now

KISA recommends publishing DMARC aggregate reports to the agency receiver before tightening policy, verifying DKIM on outbound welfare notices, and training call-center staff to refuse payment instructions that arrive only by email. Citizens should continue to verify tax balances through official apps, not links in messages—policy fixes the pipe, not user curiosity.

Politics and timeline

The National Assembly’s Science and ICT Committee scheduled a hearing on local-government cyber budgets for late September. Opposition members cited the tax-phishing wave as proof that central ministries moved faster than counties. For KISA, December is a hard line: municipal domains either enforce DMARC or lose the trust mark that banks and schools still assume when they see .go.kr in the from field.

What remains unknown

Agency officials would not say how many domains will need reject versus quarantine, and they have not finished negotiating with education offices that send bulk mail through third-party marketing tools. What is confirmed: spoofed county tax notices worked because receivers treated authentication as advisory. By winter, KISA wants the policy field to say otherwise.