Forward Email: Your Section 889 Compliant Email Forwarding Solution

Foreword

At Forward Email, we believe in simple, secure, and private email forwarding for everyone. Many organizations, especially those working with the US government, must comply with federal regulations for email. Our secure email forwarding service is built to meet stringent federal requirements, including Section 889 of the National Defense Authorization Act (NDAA).

Our commitment to government email compliance was recently put into practice when the US Naval Academy approached Forward Email. They required secure email forwarding services and needed documentation confirming our adherence to federal regulations, including Section 889 compliance. We provided that documentation, and the same infrastructure serves all our users seeking a reliable, privacy-focused email solution.

Understanding Section 889 Compliance

Section 889 is a US federal law that prohibits government agencies from using or contracting with entities that use certain telecommunications and video surveillance equipment or services from specific companies (like Huawei, ZTE, Hikvision, Dahua, and Hytera). This rule, often associated with the Huawei ban and ZTE ban, helps protect national security.

Note

Section 889 specifically targets equipment and services from Huawei, ZTE, Hytera, Hikvision, and Dahua, including their subsidiaries and affiliates.

For an email forwarding service for government contracts like Forward Email, this means ensuring none of our underlying infrastructure providers use this prohibited equipment, making us Section 889 compliant.

How Forward Email Achieves Section 889 Compliance

How is Forward Email Section 889 compliant? We selected our infrastructure partners carefully. Forward Email relies exclusively on two key providers for its Section 889 compliant infrastructure:

  1. Cloudflare: Our primary partner for network services and Cloudflare email security.
  2. DataPacket: Our primary provider for server infrastructure (we use Digital Ocean and/or Vultr for failover and will soon transition to solely use DataPacket; we confirmed Section 889 compliance in writing from both of these failover providers).

Important

Our exclusive reliance on Cloudflare and DataPacket, neither of which uses Section 889 prohibited equipment, is the cornerstone of our compliance.

Neither Cloudflare nor DataPacket uses equipment prohibited under Section 889. Using Cloudflare and DataPacket for Section 889 compliance is the basis of our service.

Cloudflare's Commitment

Cloudflare explicitly addresses Section 889 compliance in their Third Party Code of Conduct. They state:

"Under Section 889 of the National Defense Authorization Act (NDAA), Cloudflare does not use, or otherwise permit in its supply chain, telecommunications equipment, video surveillance products, or services produced or provided by Huawei Technologies Company, ZTE Corporation, Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities)."

(Source: Cloudflare Third Party Code of Conduct, retrieved April 29, 2025)

This statement confirms that Cloudflare's infrastructure, which Forward Email uses, meets Section 889 requirements.

DataPacket's Infrastructure

DataPacket, our server provider, uses networking equipment exclusively from Arista Networks and Cisco. Neither Arista nor Cisco are among the companies prohibited under Section 889. Both are established vendors widely used in secure enterprise and government environments, known for adhering to stringent security and compliance standards.

By using only Cloudflare and DataPacket, Forward Email ensures its entire service delivery chain is free from Section 889 prohibited equipment, providing secure email forwarding for federal agencies and other security-conscious users.

Beyond Section 889: Broader Government Compliance

Our commitment to government email security and compliance extends beyond Section 889. While Forward Email itself doesn't directly process or store sensitive government data like Controlled Unclassified Information (CUI) in the same way a large SaaS platform might, our open-source email forwarding architecture and reliance on secure, compliant providers align with the principles of other key regulations:

  • FAR (Federal Acquisition Regulation): By using compliant infrastructure and offering a straightforward commercial service, we provide FAR compliant email forwarding principles suitable for government contractors.
  • Privacy Act & FISMA: We are privacy-focused by design, offering Privacy Act email principles. We don't store your emails. Emails are forwarded directly, minimizing data handling. Our infrastructure providers (Cloudflare, DataPacket) manage their systems according to high security standards consistent with FISMA compliant email principles.
  • HIPAA: For organizations needing HIPAA compliant email forwarding, Forward Email can be part of a compliant solution. Since we don't store emails, the primary compliance responsibility lies with the end-point email systems. However, our secure transport layer supports HIPAA requirements when used correctly.

Warning

A Business Associate Agreement (BAA) might be needed with your final email provider, not Forward Email itself, as we do not store your email content (unless you use our encrypted IMAP/POP3 storage layer).

Our Path Forward: Expanding Compliance Horizons

Section 889 compliance matters most to federal contractors, but organizations and government agencies have other regulatory needs too. At Forward Email, we want to be open about where we stand on broader compliance and where we're headed.

We recognize the importance of frameworks and regulations such as:

Our Current Position and Future Goals:

Forward Email's core design (privacy-focused, open-source, and minimizing data handling, especially in our basic email forwarding service) aligns with the principles behind many of these regulations. Our existing security practices (encryption, support for modern email standards) and Section 889 compliance provide a strong starting point.

However, achieving formal certification or authorization for frameworks like FedRAMP or CMMC is a significant undertaking. It involves rigorous documentation, implementation of specific technical and procedural controls (often hundreds of them), independent assessments (like 3PAO for FedRAMP - Third-Party Assessment Organization), and continuous monitoring.

Important

Compliance requires documented processes, policies, and ongoing vigilance in addition to technology. Achieving certifications like FedRAMP or CMMC requires substantial investment and time.

Our Commitment:

As Forward Email grows and as our customers' needs evolve, we are committed to exploring and pursuing relevant compliance certifications. This includes plans for:

  1. SAM Registration: To facilitate direct engagement with US federal agencies.
  2. Formalizing Processes: Enhancing our internal documentation and procedures to align with standards like NIST SP 800-171, which forms the basis for CMMC.
  3. Evaluating FedRAMP Pathways: Assessing the requirements and feasibility of pursuing FedRAMP authorization, likely starting with a Low or Moderate baseline, potentially using the LI-SaaS model where applicable.
  4. Supporting Specific Needs: Addressing requirements like HIPAA (potentially through BAAs and specific configurations for stored data) and FERPA (through appropriate contractual terms and controls) as we engage more with healthcare and educational institutions.

This work requires careful planning and investment. While we don't have immediate timelines for all certifications, strengthening our compliance posture to meet the needs of government and regulated industries is a key part of our roadmap.

Note

Because we're open-source, our community and customers can follow this work in our code.

We will update our community as we reach compliance milestones.

Why This Matters for You

Choosing a Section 889 compliant email forwarding service like Forward Email means:

  • Peace of Mind: Especially for government agencies, contractors, and security-conscious organizations.
  • Reduced Risk: Avoids potential conflicts with federal regulations for email.
  • Trust: Shows attention to security and supply chain integrity.

Forward Email provides a simple, reliable, and compliant way to manage your custom domain email forwarding needs.

Secure, Compliant Email Forwarding Starts Here

Forward Email is dedicated to providing a secure, private, and open-source email forwarding service. Our compliance with Section 889, achieved through our partnership with Cloudflare and DataPacket (reflecting our Forward Email compliance for US Naval Academy work), backs this up. Forward Email is built for government entities, contractors, and anyone who values government email security.

Sign up free today! for secure, compliant email forwarding.

References