Austrian banking and financial institutions lead the nation in policy enforcement with a strict DMARC p=reject deployment rate of 47.6%. Additionally, 21.9% operate at p=quarantine and 26.8% linger at p=none, with only 3.7% lacking a DMARC record entirely. SPF alignment is high at 96.3% (3.7% incorrect). However, 98.8% of financial domains lack functional MTA-STS records (only 1.2% valid), and DNSSEC enablement stands at 8.5% (91.5% disabled).
Public sector agencies maintain solid baseline SPF implementation at 94.4% (5.6% incorrect) and lead national DNSSEC adoption at 19.4% (80.6% disabled). However, policy escalation to full protection remains slow: only 16.7% enforce p=reject, while 31.9% use p=quarantine, 27.8% remain at p=none, and 23.6% lack a DMARC record entirely. MTA-STS deployment remains limited to 4.2% (95.8% without a record).
Healthcare providers display significant exposure to email spoofing, with only 7.4% enforcing a strict p=reject policy. Meanwhile, 38.8% lack a DMARC record altogether, 33.1% sit at passive p=none, 15.7% use p=quarantine, and 5.0% have incorrect DMARC configurations. While SPF compliance is strong at 98.8% (1.2% incorrect), MTA-STS adoption is minimal at 0.8% (99.2% without a record) and DNSSEC enablement is low at 2.5% (97.5% disabled).
Academic and research institutions show high SPF configuration accuracy at 98.6% (1.4% incorrect), but rely heavily on passive monitoring, with 41.9% remaining stagnant at p=none. Coupled with 27.0% at p=quarantine, 16.2% lacking DMARC, and only 14.9% enforcing p=reject, educational networks and research assets remain exposed. MTA-STS adoption stands at 0.0% (100.0% without a record), while DNSSEC enablement is 9.5% (90.5% disabled).
Energy grid operators and utility suppliers show solid SPF alignment at 93.5% (6.5% incorrect). However, policy escalation remains incomplete: 40.2% operate on monitoring-only p=none, 25.0% use p=quarantine, 19.6% lack DMARC (1.1% incorrect), and only 14.1% enforce p=reject. Furthermore, 98.9% lack MTA-STS transport encryption (only 1.1% valid) and DNSSEC adoption stands at 4.3% (95.7% disabled).
Media and broadcasting organizations exhibit strong SPF setup at 98.7% (1.3% incorrect), but suffer from weak DMARC policy enforcement. Passive monitoring p=none accounts for 36.2% of domains, 23.8% lack DMARC entirely, 17.5% use p=quarantine, and 1.3% have invalid setups, leaving only 21.2% at p=reject. MTA-STS adoption is 0.0% (100.0% without a record) and DNSSEC enablement stands at 3.7% (96.3% disabled).
Telecom operators maintain high SPF correctness at 97.0% (3.0% incorrect) and lead all commercial sectors in MTA-STS deployment at 5.0% valid (95.0% without a record). However, active enforcement remains divided: 25.3% enforce p=reject, 27.7% use p=quarantine, 27.7% remain at p=none, 17.8% lack DMARC, and 1.5% have errors. DNSSEC adoption is recorded at 9.4% (90.6% disabled).
Transport and logistics providers demonstrate relatively strong policy enforcement, with 36.6% achieving active p=reject status. However, 26.7% remain at monitoring-only p=none, 20.0% use p=quarantine, and 16.7% lack DMARC protection entirely. SPF alignment stands at 93.3% (6.7% incorrect), while MTA-STS deployment is 0.0% (100.0% without a record) and DNSSEC adoption is 6.7% (93.3% disabled).