In Rick Aviation, Inc. v. United States, the Court of Federal Claims (COFC) tackled a novel application of the Federal Acquisition Regulation (FAR) “late is late” rule. The question the court squared up against is what happens when an otherwise timely bid or proposal is caught in a government firewall or email filter and does not reach the procuring agency’s email server?
According to COFC, unless the bid or proposal is received by the designated government office in the solicitation before an award is made, the “late is late” rule prevents the agency from accepting the bid or proposal. As the government continues to expand its implementation of cybersecurity controls and AI-supported processes, this issue may become a problem for a growing number of offerors.
COFC’s decision serves as a practical reminder that, absent certain narrow exceptions, the risk related to ultimate receipt by the procuring agency of an electronically submitted proposal remains largely on the offeror.
Below, we discuss the case and provide practical suggestions to help reduce this risk.
Rick Aviation, Inc. v. United States, No. 25-1604 (June 17, 2026)
In April 2025, the Defense Logistics Agency (DLA) issued a solicitation for the procurement of petroleum fuel products with a deadline of 1 p.m. on May 23, 2025. The solicitation advised contractors to ensure their offers were “sent with enough time to be processed through the server.” The solicitation also instructed offerors to submit their proposals via email to either the contracting officer or the designated DLA email address and warned that its email filtration system would scan for viruses and key words that could delay delivery of a bid.
On May 22, at 1:27 p.m., Rick Aviation, Inc. (RAI) emailed its proposal to the designated DLA email address and received an automated response stating that its proposal had been successfully delivered. One other competitor, Avfuel, also submitted a proposal.
DLA accepted Avfuel’s proposal and awarded it the contract on August 19, 2025. On September 23, 2025, RAI notified DLA that it intended to protest the award. After receiving RAI’s notice, the contracting officer informed RAI that the agency could not find RAI’s proposal in either potential email inbox. Unbeknownst to RAI or DLA, RAI’s email with its proposal had been quarantined by the Defense Information Systems Agency (DISA), a partner of DLA that provides information technology services, including email services, “due to error by the sender” related to the Sender Policy Framework (SPF) configuration authentication standard used by DISA. Because DISA’s email gateway blocked RAI’s email as a result of the SPF error, the proposal never reached DLA’s designated email inbox.
In September, the contracting officer concluded that because RAI’s proposal never arrived at the designated email address before award, it could not be considered under the “late is late” rule. RAI filed its complaint at COFC later that month, alleging that DLA’s rejection of its bid was arbitrary and capricious.
The Court denied RAI’s protest, explaining that under FAR 52.212-1(f)(2)(i) (Instructions to Offerors—Commercial Products and Commercial Services), an offer received at the government office designated in the solicitation after the exact time specified for receipt of offers is “late” and will not be considered unless:
(1) the proposal was received before award was made;
(2) the contracting officer determined that accepting the late offer would not unduly delay the acquisition; and
(3) one of the clause’s specific exceptions applies, including the “electronic commerce” exception (receipt at the “initial point of entry to the government infrastructure” no later than one day prior to the due date) or the “government-control” exception (acceptable evidence that the offer was received at the government installation designated for receipt and was under the government’s control before the time set for receipt of offers).
(For further discussion on the exceptions to the “late is late” rule, see our previous post.)
RAI’s proposal was not “received” at the government office designated in the solicitation before award. DISA is an intermediary agency that essentially provides email services to DLA. Although DISA and DLA are part of the same Department of War, receipt by DISA’s server did not satisfy the receipt-by-the-agency requirement. Instead, the Court determined DLA never “received” RAI’s proposal because DISA’s gateway blocked RAI’s email from arriving on DLA’s server.
Further, the Court ruled that the automated response RAI received indicating that its email had been delivered was not the same as confirmation that the email had been received. Notwithstanding RAI being lulled into a false sense of security by the delivery confirmation, the Court’s analysis ultimately turned on the fact that the CO in the office specified in the solicitation did not receive the proposal before the award was issued.
The Court recognized that its result may seem harsh and that “disputes like this one have arisen with disturbing frequency [and] painfully illustrate how FAR provisions enacted long ago conflict with modern technology.” Nevertheless, the FAR places the responsibility on offerors to ensure their proposals reach their intended destinations, and RAI could have followed up with the contracting officer to confirm receipt. Because RAI’s proposal was not “received” prior to award, a “late is late” exception could not apply.
The Court also rejected RAI’s assertion that DISA’s SPF configuration standard, which resulted in the quarantine of RAI’s proposal, constituted an unstated evaluation criterion. In short, the SPF configuration was a technical or procedural matter, not a substantive basis for evaluating proposals, and thus, it could not be considered an evaluation criterion.
Key Takeaways for Contractors
In an age of firewalls, encryption, and AI-assisted security, contractor personnel need to be certain they understand the technical details of the processes by which they communicate with the government—and how to ensure their communications successfully work their way through the electronic maze and are received by the intended recipient. Offerors bear full responsibility for ensuring their electronic submissions actually reach the designated inbox—including maintaining properly configured email authentication protocols. Indeed, the Court emphasized that the solicitation expressly warned offerors to verify receipt with the contracting officer, and RAI’s failure to do so proved fatal to its protest.
As the RAI decision makes clear, contractors should not treat their “sent items” email box or automated delivery response as conclusive proof that the agency received an offer. Instead, to mitigate the non-receipt risk, contractors should:
- Build into electronic submission plans sufficient time to verify receipt and resolve any delivery problems before the deadline.
- Request affirmative confirmation of receipt from the contracting officer or other receipt point(s) designated by the solicitation.
- When a solicitation warns that email filtering may delay delivery, follow up on receipt. Doing so can be the difference between a timely offer and an offer the agency cannot consider.
In sum, contractors are advised to submit proposals early, confirm receipt, and keep a record showing that the offer reached the right place before the deadline.