Damn, lemmy.zip, eh? If that instance is public, I don't see that being a good thing.
Tons of businesses, people, etc, are all banning .zip and .mov TLDs for security purposes. I've personally banned all those domains from my network as well.
Bold move.
Perhaps the military should have a system in place to not allow emails to be sent outside of very specific TLDs if it's that sensitive? And perhaps have an automated contact book, instead of relying on someone typing out the to: address manually to be able to make that mistake in the first place?
Seems like some very basic security measures for something so serious.