Estonia to quarantine emails from Russian servers sent to state institutions starting September
From the end of August, emails sent to many Estonian state institutions from addresses ending in .ru will be automatically routed through additional security checks instead of being delivered immediately. The move, aimed at preventing cyberattacks, will particularly affect Estonia's Russian-speaking residents.

Starting in September, emails sent to Estonian state institutions from Russian servers — addresses ending in .ru — will no longer arrive instantly. Instead, they will be automatically redirected to quarantine for additional security screening, as part of efforts to prevent cyberattacks.
The change is expected to affect a portion of Estonia's population, particularly Russian-speaking residents who still rely on email accounts hosted on Russian servers.
Rising threat level
Justice and Digital Affairs Minister Liisa Pakosta, of the Eesti 200 party, said the measure is one more step in protecting state institutions. She noted that cyberattacks against Estonia have risen sharply since 2022, with a large share of them linked to Russia. While determined efforts have so far kept such attacks from succeeding against Estonia, Pakosta pointed out that large-scale cyberattacks against the public sector have succeeded in both Latvia and Lithuania, according to news reports. She said continuous improvement of cybersecurity across many areas is necessary, and this measure is one small part of that broader effort.
Not all institutions included
The new arrangement will not apply to every state institution, and local governments are excluded entirely. Some bodies have already gone further: Estonia's courts have announced they will ask parties involved in proceedings to stop using .ru email addresses when communicating with the courts.
Pakosta explained that the exact approach depends on each institution's own security rules, though all state institutions must comply with strict cybersecurity requirements. A large share of them have already joined a unified, strong cyber shield, and that transition is ongoing.
The minister emphasized that the new system will not create extra bureaucratic burden, since the rerouting happens automatically and centrally, requiring no additional action from government agencies. It applies to all state institutions already operating within the state's secure cyberspace.


