A NSW Government website
Search for a command to run...
Email is a common target for cyber attacks, making it a critical focus for information security. NSW Government agencies must ensure all email communications are secure, accessible, and compliant with legal and privacy obligations. These protections prevent data breaches, minimise risks such as phishing and spoofing, and help maintain public trust in government systems.
Government emails must comply with the NSW Cyber Security Policy. This includes:
Send all emails—transactional, informational and marketing—through approved government systems or trusted third-party providers that meet security standards.
Avoid personal email accounts and unapproved platforms, as they can expose sensitive data and reduce accountability.
Keep personal and sensitive information to a minimum in emails. When required, use classification labels for content that is:
Handle data according to privacy, data protection and records management laws.
Work with your IT and security teams to implement email protections, including:
These safeguards help prevent spoofing, reduce phishing risks and support public trust.
Do not:
Only link to trusted sources such as official NSW Government websites.
Ensure emails are free from:
Use accessible formatting and content that works with security scanning tools. All emails—incoming and outgoing—are automatically scanned.
All staff must:
For guidance, refer to: