sysadmintools

studies · measured 2026-10-05

What all 51 state government portals look like from the outside

We measured the primary public website of every US state and the District of Columbia. Not with a scanner, and not with anything invasive — just public DNS records and a single TLS handshake per host, the same connection your browser makes when you visit.

The short version: state governments have largely done the hard part of email security and then stopped one step short of the easy part. And a surprising number are leaving a plaintext hop in front of their front door.

92.2%

publish a DMARC record

47 of 51

29.4%

actually enforce it

15 of 51 at p=reject

66.7%

support TLS 1.3

34 of 51

17.6%

reachable over IPv6

9 of 51

The gap that matters most

Almost every state has published a DMARC record — 47 of 51. That is genuine, and it took real work.

But publishing a DMARC record is not the same as enforcing one. A record with p=none asks mail providers to reporton spoofed mail, not to block it. Someone can still send mail that appears to come from that state's domain, and the state gets a report about it afterwards.

Only 15 of 51 portals publish p=reject, which is the setting that actually stops the forgery. Another 11 sit at p=quarantine, which routes suspicious mail to spam. That leaves 71% with no enforcement at all: 21 at p=none and 4 with no DMARC record.

The fix is one word in a DNS record. Moving from p=none to p=reject is a text edit — the work is in the weeks beforehand, reading the reports to find out which systems are sending legitimate mail on your behalf. That is why the step gets skipped, and it is a reason rather than an excuse.

What good looks like

These states are running the full stack on their public portal: DMARC enforced at p=reject with SPF ending in -all. This is the configuration worth copying.

AlabamaHawaiiMinnesotaMontanaNebraskaNew JerseyPennsylvaniaTexasWest Virginia

Email: the rest of the picture

  • 51 of 51 publish an SPF record.
  • 27 end it in -all (hard fail, the strongest setting). 24 use a weaker ending, and 0 publish no SPF record at all.
  • A soft or neutral SPF ending is often deliberate during a migration. It is also the state that persists when nobody goes back to finish the job.

The bare domain is the weak spot

Two portals have exactly the same shape of problem: the www host is configured correctly and the bare domain is not. Both are easy to miss, because both look fine in a browser.

Wyoming does not complete a TLS handshake on the bare domain at all — only on www. Someone typing the domain without www gets a plaintext redirect before reaching the secure site, and that first hop is the one an attacker on the same network can interfere with.

Virginia serves an incomplete certificate chain on the bare domain: it sends its own certificate but omits the intermediate, so the chain cannot be verified on its own. Most browsers quietly fetch the missing intermediate and hide this entirely — which is why it survives. It still breaks strict clients, older Android devices and plenty of command-line tooling. The same domain over www sends the full chain correctly, which is how we know it is a configuration gap and not a broken certificate.

Both fixes are small: make the apex answer on port 443 the way the www host already does, and make sure the intermediate certificate is served on every hostname the certificate covers.

TLS and DNS

  • 50 of 51 portals present a certificate chain that validates on its own — the exception being Virginia, described above, where the www host validates and the bare domain does not. That is a genuinely good result: expired or self-signed certificates are the most common TLS finding in surveys like this, and there are none here.
  • 34 of 51 negotiate TLS 1.3, the current standard. The other 17 stop at TLS 1.2, which is not broken, just older.
  • 13 of 51 have a DNSSEC chain that validates end to end. DNSSEC is the one item on this list with no partial credit — it either validates or it does not.
  • 9 of 51 are reachable over IPv6. The other 42 have no AAAA record. This is the widest gap in the study, and the least urgent — but it is also the one that will keep mattering more each year.

The full results

Every portal, in alphabetical order. Deliberately not ranked — the point of this table is to be complete, not to sort anyone to the top or bottom.

StateDomainDMARCSPFTLSIPv6DNSSEC
Alabamaalabama.govp=reject-all1.2no—
Alaskaalaska.govp=none~all1.2no—
Arizonaaz.govp=quarantine~all1.3no—
Arkansasarkansas.govp=quarantine-all1.3no—
Californiaca.govp=none-all1.3yesvalid
Coloradocolorado.govp=none~all1.2no—
Connecticutct.govp=quarantine~all1.2no—
Delawaredelaware.govp=reject~all1.2no—
District of Columbiadc.govp=none~all1.3yesvalid
Floridamyflorida.comp=none~all1.3no—
Georgiageorgia.govp=none-all1.3no—
Hawaiihawaii.govp=reject-all1.2yes—
Idahoidaho.govp=none-all1.3novalid
Illinoisillinois.govp=quarantine~all1.3no—
Indianain.govp=none-all1.3no—
Iowaiowa.govp=quarantine~all1.3yesvalid
Kansaskansas.govnone-all1.2no—
Kentuckykentucky.govp=quarantine-all1.3no—
Louisianalouisiana.govp=reject~all1.3no—
Mainemaine.govp=reject~all1.2no—
Marylandmaryland.govp=none~all1.3yesvalid
Massachusettsmass.govp=none~all1.2novalid
Michiganmichigan.govp=rejectno all1.3no—
Minnesotamn.govp=reject-all1.3novalid
Mississippimississippi.govp=none~all1.2no—
Missourimo.govp=none?all1.3yes—
Montanamt.govp=reject-all1.2no—
Nebraskanebraska.govp=reject-all1.3no—
Nevadanv.govp=quarantine-all1.3yes—
New Hampshirenh.govp=none-all1.3no—
New Jerseynj.govp=reject-all1.3novalid
New Mexiconm.govp=none-all1.3no—
New Yorkny.govnone-all1.3no—
North Carolinanc.govp=reject~all1.3no—
North Dakotand.govp=none-all1.3no—
Ohioohio.govp=quarantine-all1.3no—
Oklahomaoklahoma.govnone-all1.3no—
Oregonoregon.govp=quarantine-all1.2no—
Pennsylvaniapa.govp=reject-all1.3no—
Rhode Islandri.govp=none~all1.2no—
South Carolinasc.govp=quarantine~all1.3yes—
South Dakotasd.govp=noneno all1.3yes—
Tennesseetn.govp=reject~all1.3novalid
Texastexas.govp=reject-all1.2novalid
Utahutah.govp=quarantine~all1.3novalid
Vermontvermont.govp=none-all1.2novalid
Virginiavirginia.govp=none~all1.2 chainnovalid
Washingtonwa.govp=none-all1.3no—
West Virginiawv.govp=reject-all1.3no—
Wisconsinwisconsin.govp=none-all1.2no—
Wyomingwyo.govnone~allwww onlyno—

If you run one of these portals

None of this requires a vendor or a budget conversation. Every finding here is a DNS record or a certificate setting, and every one of them is checkable with a free tool:

How this was measured

Public DNS records and a single TLS handshake per host. No port scanning, no vulnerability probing, no HTTP requests beyond the TLS handshake, no crawling.

The measurement window is a single point in time — 2026-10-05. DNS records can change within minutes of being measured, and any state may have already fixed what is shown here.

What this is not

This is not a security assessment, and it should not be read as one. It measures a handful of publicly visible settings, and a state with every setting perfect could still have serious problems elsewhere. Conversely, a missing record is not automatically a mistake — a domain that does not send mail has no reason to publish SPF.

  • Measures the primary public portal domain only, not every domain a state operates. Agency and subdomain posture may differ.
  • DKIM cannot be enumerated from outside: selectors are not discoverable, so a 'not found' result here means 'not found at the selectors we checked', not 'absent'. DKIM is therefore excluded from every headline figure.
  • DMARC, SPF and DNS are point-in-time. Any state may have changed its records since this scan.
  • A missing record is not necessarily misconfiguration — a domain that does not send mail legitimately may publish no SPF record.
  • This is not a security assessment. It is a measurement of a few publicly visible settings.

About the scan itself

The script that produced this is plain Python in the project repository, and it is deliberately boring: DNS lookups and one TLS handshake per host. It does not port-scan, does not probe for vulnerabilities, does not attempt authentication, and does not crawl. There is no HTTP request beyond the TLS handshake, so it cannot touch a form, a query string, or any application logic on any of these systems.

Corrections are welcome and acted on — if we have something wrong about your domain, tell us and we will fix it and say that we did.