BY-GX3 — Email Protective Marking

Printable artifact pack · 6 micro-scenarios · 15-minute course · Foundation
Australian Government Email Protective Marking Standard (syntax v2025.1) · 9 controls cited

This pack turns the six modules of BY-GX3 into hands-on micro-scenarios. Each sheet is one activity: the student handles practice emails, chooses values, rewrites syntax, resolves clashes and composes a real send — then checks their work against the answer key at the back (trainer only).

Contents

SheetActivityFormatTime
1Reference cards — six values, caveats, syntax (cut out and keep)Cards
2M1 · The unmarked thread — find what is wrong in five emailsInbox sweep5 min
3M2 · Mark to the highest thing inside — three variants, one value eachValue drill5 min
4M3 · The syntax clinic — rewrite eight malformed linesRewrite drill6 min
5M4 · The header that wins — resolve the clashTriage6 min
6M5 · Tool limits — who stays accountableTriage5 min
7M6 · Send it properly — compose the full email + self-checkCompose8 min
8Answer key — trainer onlyKey

How to run

Classroom: print one pack per student (answer key pages withheld). Students work sheet by sheet; trainer reveals answers after each sheet. Total hands-on time ≈ 35 minutes + debrief.
Virtual: share the sheets as a PDF; students annotate or type answers; reveal the key sheet by sheet. Important: all entities, people and addresses are fictional. Never reuse real entity templates.

Sheet 1 · Reference cards (cut out, keep on the desk)

The six SEC values — least to most sensitive

UNOFFICIAL OFFICIAL OFFICIAL:Sensitive PROTECTED SECRET TOP-SECRET

There is no seventh word and no local variant. Mark to the highest sensitivity present in the whole message — body, attachments, anything else. The sender applies the marking; the sender stays accountable.

The two marking forms (exact fixed syntax)

1 · Subject Field Marking — appended at the end of the subject line, after the human-readable text:

2 · Internet Message Header Extension — in the message header:

Where both forms appear, the header wins. Watch the trip-ups: no spaces inside the brackets, one space after the comma, correct case on SEC= and the values.

The four caveat types — and the marker that is not one

Caveat typeWhat it marks
C — CodewordA specific compartmented activity
FG — Foreign GovernmentInformation originating with another government
SH — Special HandlingHandling beyond the classification alone
RI — Releasability IndicatorWho it may be released to — codes such as AGAO, AUSTEO, REL + country codes

A caveat never travels alone — it is always marked alongside a classification. ACCESS= is not a caveat: it carries an Information Management Marker such as ACCESS=Legal-Privilege, and requires SEC=OFFICIAL:Sensitive or higher (the floor). The NATIONAL-CABINET caveat is retired — never apply it; refer historic material.

The five-point self-check (use before every send)

1 · Did I read every part — body, attachments, quoted content?
2 · Is the Subject Field Marking present, exact syntax, correct value?
3 · Is the X-Protective-Marking header present and matching?
4 · Is any caveat paired with a classification?
5 · Did the tool suggest, and did I — not it — decide?

Sheet 2 · M1 — The unmarked thread (5 min · individual)

Task: five emails from the practice mailbox. Which are not properly marked? In one line each, what makes each one wrong? (Reference: Sheet 1.)
From:
r.okafor@example.gov.au  ·  To: grants.team@example.gov.au
Re: Program coordination catch-up
Thanks all — Thursday at 10 works for me. (Internal mail doesn't need a marking, right?) See you then. — R.
From:
m.patel@example.gov.au  ·  To: grants.team@example.gov.au
⦿ High importance (red flag) Vendor invoice — action needed
Attached is the vendor invoice for the regional grants workshop series. Please arrange payment. — M.
From:
s.nguyen@example.gov.au  ·  To: a.chen@example.gov.au
FYI — the summary you asked for
As discussed on the phone — here is the two-page summary of the grantee meetings. (We talked about how sensitive this one is, so you know.) — S.
From:
j.whitfield@example.gov.au  ·  To: grants.team@example.gov.au
X-Protective-Marking: SEC=OFFICIAL
Northern Regions Grants — quarterly status [SEC=OFFICIAL]
Attached is the quarterly status note for the Northern Regions Grants Program. — J.
From:
a.chen@example.gov.au  ·  To: grants.team@example.gov.au
Grantee briefing pack
Please find attached the briefing pack for next week's grantee forum.

A. Chen
Program Officer, Grants
Department of Sample Affairs
SEC=OFFICIAL

Your findings:

1 · Email — problem:

2 · Email — problem:

3 · Email — problem:

4 · Email — problem:

5 · Email — status:

Sheet 3 · M2 — Mark to the highest thing inside (5 min · individual)

Task: the same message, three versions. Read every part of each version and choose the one SEC value. Then say which part of the message drove your choice.
From:
j.whitfield@example.gov.au  ·  To: grants.team@example.gov.au
Program status update
Hi team — the program calendar for the coming month is unchanged: grantee forum on the 18th, reporting due the 25th. No issues to report. — J.
No attachments.

Version A value:   driven by:

From:
j.whitfield@example.gov.au  ·  To: grants.team@example.gov.au
Program status update
Hi team — attached is the Q3 program data extract. Please review before the 18th. — J.
Attachments: Q3-program-data.xlsx (marked OFFICIAL:Sensitive)

Version B value:   driven by:

From:
j.whitfield@example.gov.au  ·  To: grants.team@example.gov.au
Program status update
Hi team — attached is the partner agreement draft. Please confirm the figures before we return it. — J.
Attachments: partner-agreement-draft.docx (marked PROTECTED)

Version C value:   driven by:

Reverse drill: an email carries the value [SEC=PROTECTED]. What must be inside it?

Who owns the choice?

Sheet 4 · M3 — The syntax clinic (6 min · individual)

Task: eight lines from real sends. Rewrite each in the exact fixed syntax — both forms (Subject Field Marking and X-Protective-Marking header). One of them is already correct: find it, don't rewrite it.
#As it was sentYour rewrite
1Subject: [sec=official] Quarterly meeting notes
2Subject: Q3 remediation status
(body begins: "This email is OFFICIAL.")
3Subject: [OFFICIAL:Sensitive] Program update
4X-Protective-Marking: PROTECTED
5Subject: Grantee forum notes [SEC=OFFICIAL:Sensitive]
6Subject: [SEC=OFFICIAL : Sensitive] Reporting dates
7Subject: [SEC=PROTECTED,ACCESS=Legal-Privilege] Advice
8Subject: [ACCESS=Legal-Privilege] Settlement figures

Then sort them — caveat type (C, FG, SH, RI) or Information Management Marker?

ElementCaveat type or marker? (one line)
AUSTEO
ACCESS=Legal-Privilege
Material originating with another government
REL followed by country codes
NATIONAL-CABINET

Which line was the correct one?   Why is a machine-readable form important, not just a human-readable one?

Sheet 5 · M4 — The header that wins (6 min · paired)

Task: the two views of one incoming email disagree. Resolve the standing of the message, check the records requirement, and decide what you may send onward. Pair up: one of you argues "trust the subject line", the other responds with the standard. Swap.
From:
p.mwangi@example.gov.au (Department of Transport Futures — fictional)
Joint program — remediation status [SEC=OFFICIAL]
As agreed, here is the remediation status for the joint grants program. The legal advice is attached for your reference. Please let us know if you need anything further. — P.
Attachments: legal-advice-draft.docx (header page marked PROTECTED)
Full headers view: X-Protective-Marking: SEC=PROTECTED, ACCESS=Legal-Privilege

Also on the desk: the records system shows the Information Management Marker was not recorded for this message. Your executive wants a two-paragraph summary of the advice by close of business.

1 · Standing of the email:

2 · Why (which form wins, and what the rule is):

3 · The Information Management Marker floor:

4 · What you record before replying:

5 · The summary you send — marking and recipients:

What does a clash between the two forms tell you about the message's journey?

Sheet 6 · M5 — Tool limits, human decisions (5 min · individual)

Task: three observations from the help desk. Classify each as tool doing its job, user error, or tool failure — and for each, write who remains accountable for the final marking decision.

Observation 1

The mail client suggested a marking of [SEC=OFFICIAL:Sensitive] for a draft. Before sending, the user overrode it to [SEC=OFFICIAL]. The draft quotes a marked OFFICIAL:Sensitive source document.

Classification:
Who stays accountable:

Observation 2

An officer replied to a PROTECTED email. The reply draft would not allow the marking to be set below [SEC=PROTECTED] because the quoted original was PROTECTED. The officer wants a workaround.

Classification:
Who stays accountable:

Observation 3

The mail server bounced an outbound message whose X-Protective-Marking header did not match the entity's policy for the recipient domain. The sender calls it "an outage".

Classification:
Who stays accountable:

Why is it desirable that the tool cannot mark for you?

Sheet 7 · M6 — Send it properly (8 min · individual)

Brief: you are in the program team at the Department of Sample Affairs. Send a two-paragraph status update on the Northern Regions Grants Program that quotes one figure from the attached PROTECTED partner report. Recipients: two internal colleagues, your manager, and one external counterpart at the partner agency. Compose the complete email below, then run the five-point self-check.

To:  Cc:

Subject:

X-Protective-Marking:

Attachment note:

Paragraph 1:

Paragraph 2 (with the quoted figure):

Five-point self-check — tick before "send"

CheckTick
1 · Read every part — body, attachment, quoted content — and marked to the highest sensitivity present?
2 · Subject Field Marking present, exact syntax, correct value?
3 · X-Protective-Marking header present and matching the subject?
4 · Any caveat paired with a classification?
5 · The tool suggested — I decided?

What did composing the whole message surface that reading about it did not?

Sheet 8 · Answer key

M1 · The unmarked thread

Email 1 (Okafor): wrong — no marking. "Internal mail doesn't need one" is false: the standard covers email in and between entities (Email Req 0067).
Email 2 (Patel): wrong — a colour/flag is not a marking; it must be readable text (Email Req 0061).
Email 3 (Nguyen): wrong — a phone call is not a marking; sensitivity must be written as text on the message.
Email 4 (Whitfield): correct — subject marking + matching header, exact syntax.
Email 5 (Chen): wrong — the marking sits in the signature block, not in the subject/header where a person and a machine both read it.
Message to land: if a marking is not written as text in the right place, it is not doing its job.

M2 · Mark to the highest thing inside

A → OFFICIAL (routine calendar note, no attachments). B → OFFICIAL:Sensitive (attachment carries it — mark to the highest part). C → PROTECTED (attachment marked PROTECTED lifts the whole email).
Reverse drill: something inside the message is PROTECTED or higher (an attachment, quoted content) — the recipient should be able to infer it. Who owns the choice: the sender, applying the marking (Email Req 0061; ISM-0270).

M3 · The syntax clinic

1 → Quarterly meeting notes [SEC=OFFICIAL] (case — and the marking appended after the subject text).
2 → Q3 remediation status [SEC=OFFICIAL] (marking belongs in the subject, appended — not in the body).
3 → Program update [SEC=OFFICIAL:Sensitive] (the SEC= is part of the form).
4 → X-Protective-Marking: SEC=PROTECTED (header needs SEC=).
5 → correct as sent — the hidden good one: text first, marking appended at the end.
6 → Reporting dates [SEC=OFFICIAL:Sensitive] (no space before the colon).
7 → Advice [SEC=PROTECTED, ACCESS=Legal-Privilege] (one space after the comma).
8 → must pair the marker with a classification at or above the floor: Settlement figures [SEC=PROTECTED, ACCESS=Legal-Privilege] — an Information Management Marker never travels alone, and requires OFFICIAL:Sensitive or higher (EM-IMM.floor).
Every corrected subject puts the human-readable text first with the marking appended at the end — a marking-first subject is malformed.
Sort drill: AUSTEO → RI caveat · ACCESS=Legal-Privilege → Information Management Marker, not a caveat · another government's material → FG caveat · REL + country codes → RI caveat · NATIONAL-CABINET → retired caveat — never apply it; refer historic material.
Machine-readable form matters because systems route, filter and record on the header — not on human reading.

M4 · The header that wins

Where both forms appear, the header wins (EM-7.precedence): treat the message at SEC=PROTECTED, ACCESS=Legal-Privilege — not at the subject's OFFICIAL. The Information Management Marker floor (EM-IMM.floor) is satisfied — PROTECTED sits above the OFFICIAL:Sensitive minimum the marker requires — and it rules the subject's value out on its own: a message carrying Legal-Privilege cannot sit below OFFICIAL:Sensitive. The records gap is a separate finding: the classification carries onto the record as its property (Email Req 0068), so record the message with its full marking and raise the break in the chain. The executive's summary quoting the advice carries PROTECTED forward (and the Legal-Privilege marker if the summary conveys privileged content); recipients must be cleared for it. A clash between the forms is itself a flag — the message's journey did something unexpected; note it, don't paper over it.

M5 · Tool limits

1 — user error: the tool suggested; the user overrode to a lower value on quoted sensitive content. The sender remains accountable (ISM-0271). 2 — tool doing its job: no quiet downgrades of replies below the quoted original (ISM-1089); there is no workaround to want. 3 — tool doing its job: the server is the last calm check (ISM-0565); a bounced send is the control working, not an outage.
Desirable that the tool can't mark for you: the marking decision stays human and honest.

M6 · Send it properly — model send

Subject: Northern Regions Grants — status update [SEC=PROTECTED]  ·  Header: X-Protective-Marking: SEC=PROTECTED.
Attachment note names the partner report and its marking; the figure quoted from it holds the email at PROTECTED regardless of how routine the prose reads. External counterpart is included only if the partner agency is cleared for PROTECTED in this program's arrangements — otherwise hold and brief separately. Five-point self-check ticked before send. One honest send is the whole outcome the course promises.