> Lt. Cmdr Tim Gorman [...] said that emails sent directly from the .mil domain to Malian addresses “are blocked before they leave the .mil domain and the sender is notified that they must validate the email addresses of the intended recipients”.
I think the issue is people sending emails from personal accounts that the DOD cannot control. The article also mentions travel agents as another source of the email.
Sales and travel agents, an IT depts worse nightmare. People too busy to double check anything are the fault of emails delivering to the wrong recipient.
Colour me surprised.
then make it part of any contract that if you do business for .mil, and you use microsoft/zoho/gsuite etc, that they automatically run a set of ".mil compliance settings" overlaid onto your tenant.
Given what can be figured out by collecting thousands of hotel itineraries or whatever is actually being leaked here, it may just be the DoD needs to crack down and expand the definition of what is considered sensitive.
The military should move to domain that is safer from typosquatting, by controlling a bunch of related TLDs.
Or continue not caring about spying on random unclassified information.
It seems like a better approach would be to harden all email software in usage to ban almost-but-not-quite .mil at the end of email addresses, looking for the above permutations client-side before anything is transmitted.
Because I can see some serious shortcomings in your proposal right off the bat...
I don't know how easy it would be to insert lies in the root DNS servers, without it being spotted, and without it triggering a potential war if it impacts ccTLDs.