Estonia to add extra screening for emails from .ru domains reaching state agencies
From 31 August, emails sent from Russian servers or .ru addresses to Estonian state institutions will first be quarantined and screened before delivery, a move Justice and Digital Affairs Minister Liisa Pakosta says strengthens cybersecurity.

Estonia's Minister of Justice and Digital Affairs, Liisa Pakosta, has decided that from 31 August, emails sent from Russian servers or from addresses ending in .ru will no longer reach many state institutions directly. Instead, they will first be placed in quarantine and subjected to additional checks.
Many residents of Estonia, particularly the Russian-speaking population, still keep their email accounts on Russian servers, meaning they use addresses ending in .ru. Courts have already announced that they are asking parties to legal proceedings to stop using such addresses when communicating with the court.
Pakosta said the decision was taken as an additional security measure to protect Estonian state institutions from cyberattacks. She noted that cyberattacks against Estonia have become more frequent since 2022, with a very large share of them linked to Russia. She said Estonia needs to strengthen its defenses in many areas, and that thanks to targeted efforts, such attacks have so far not succeeded in Estonia, whereas, according to news reports, large-scale cyberattacks on the public sector in Latvia and Lithuania have unfortunately succeeded.
How the process changes
Previously, emails from .ru domains reached state institutions directly; now they will undergo additional screening. This means the emails will still arrive, but more slowly, since the checks take time. Pakosta explained that not all state institutions and local governments will apply the same lengthy procedure — it depends on the security rules set by each specific institution. A very large share of state institutions have already moved to a unified, secure cyber shield, and this transition will continue.
The minister confirmed that the new procedure will not add extra bureaucracy for institutions, since the redirection to quarantine happens automatically and centrally, requiring no action from the institutions themselves. The arrangement will affect all state institutions already operating within the protected state cyberspace.


