Election Administrators’ Email Security: A State of Varying Risk
With Election Day less than 100 days away, the security posture of the officials tasked with running U.S. elections remains uneven, according to a new report from Area 1 Security. The study, “Phishing Election Administrators,” analyzed the email phishing vulnerabilities of more than 10,000 state and local election administrators, finding that the majority lack even basic protections against an attack vector responsible for the vast majority of cybersecurity damages worldwide.
The report’s core findings break down the readiness of election administrators into tiers:
- 53.24% rely on only rudimentary or non-standard technologies for protection.
- 28.14% have implemented basic controls to prevent phishing.
- 18.61% have deployed advanced anti-phishing measures.
- 5.42% use personal email accounts (such as Yahoo!, Hotmail, or AOL) for official duties.
- A number of administrators operate their own custom email infrastructure, including versions of the Exim transfer agent that are known targets for cyber actors linked to prior election interference.
The findings highlight a significant disconnect between the importance of the role and the resources dedicated to protecting it. Phishing campaigns frequently begin with a seemingly innocuous email that recipients cannot distinguish from legitimate correspondence. Consequently, the sophistication of the email protection layer often dictates the overall security posture of the organization.
“Our elections are vital. They need to be resilient against whatever crisis the moment throws at us — and that requires resources and planning,” said Oren J. Falkowitz, co-founder of Area 1 Security. “However, most state and local election administrators are not very close to ensuring a safe election. This challenge is going to be exacerbated the longer it takes for them to get the resources and expertise needed to make changes.”
Acting on the Findings
Area 1’s report includes a set of direct recommendations for election administrators looking to improve their security posture. The guidance focuses on closing the most identifiable and critical gaps.
Discontinue Use of Exim Email Servers
Administrators running custom email infrastructure are urged to stop using Exim entirely. Even with updates, the software carries residual risk given prior adversarial focus on it. Government advisories have already flagged several known critical vulnerabilities — including CVE-2019-10149, CVE-2019-15846, and CVE-2019-16928 — that require immediate attention. Those who must continue operating Exim should ensure they are running at least version 4.93, as prior versions expose the system to disclosed exploits. Updates can be applied via the Linux distribution’s package manager or by downloading the latest version from https://exim.org/mirrors.html.
Shift to Cloud Email Infrastructure
Maintaining custom infrastructure demands perfect daily administration. To reduce this burden, Area 1 recommends transitioning to established cloud email providers such as Google’s GSuite or Microsoft’s Office 365, ideally combined with a dedicated cloud email security solution.
Eliminate Personal Email from Official Duties
The report is unequivocal on this point: personal email should not be used for the conduct or administration of elections under any circumstances.
Area 1 Security states its findings were made in line with Responsible Disclosure guidelines, noting that the company has engaged with relevant stakeholders with an interest in understanding phishing campaigns targeting the election ecosystem.



