Under oversight from Finanstilsynet and European DORA frameworks, the Danish financial sector demonstrates the country's strongest email authentication baseline. Correct SPF implementation stands at 98.8% (1.2% incorrect). An impressive 80.5% of banking domains enforce strict p=reject policies, with 11.0% in quarantine, 6.1% at p=none, 1.2% incorrect, and only 1.2% lacking a record. DNSSEC activation reaches 61.0% (39.0% disabled). However, MTA-STS adoption remains limited at 6.1%, leaving 93.9% of financial communication channels without verified transport encryption.
Driven by central digital government standards and CFCS security baselines, Danish public institutions achieve exceptional authentication performance. Baseline SPF correctness reaches 98.6% (1.4% incorrect). Full p=reject enforcement is active across 93.2% of government domains, with 2.7% in quarantine, 1.4% at p=none, and 2.7% without a record. DNSSEC deployment is the highest among all sectors at 93.2% (6.8% disabled). Nevertheless, MTA-STS deployment sits at just 4.1%, leaving 95.9% of municipal and departmental mail streams open to transport eavesdropping.
Handling sensitive patient records and medical communications, Danish healthcare infrastructure faces ongoing phishing exposure. While SPF adoption is strong at 94.1% correct (5.9% incorrect), DMARC policy enforcement lags significantly: only 41.6% enforce p=reject, while 20.8% use quarantine, 24.7% remain at passive p=none, and 12.9% have no record. DNSSEC is enabled on 60.4% of domains (39.6% disabled). Valid MTA-STS coverage is just 3.0%, leaving 97.0% of patient-related email exchanges exposed to transit tampering.
Academic institutions and research universities achieve 100.0% correct baseline SPF records. However, enforcement remains divided: 51.7% enforce p=reject, 13.8% use quarantine, 17.2% remain in passive p=none observation, 3.5% have misconfigured records, and 13.8% lack a record completely. DNSSEC is active on 58.6% of domains (41.4% disabled). Notably, valid MTA-STS implementation stands at 0.0% (100.0% unconfigured), leaving institutional research networks and campus communications without transport-layer protection.
As vital components of national critical infrastructure falling under NIS2 oversight, utility operators demonstrate 96.5% correct SPF implementation (3.5% incorrect). DMARC enforcement shows moderate progress, with 54.6% enforcing p=reject, 10.5% in quarantine, 20.9% at p=none, and 14.0% lacking records. DNSSEC adoption stands at 65.1% (34.9% disabled). However, MTA-STS is active on only 2.3% of utility domains (97.7% unconfigured), creating potential supply-chain blind spots.
Danish news publishers, broadcasters, and media groups show the lowest enforcement rate across the evaluated sectors. While 93.1% maintain correct SPF configurations (6.9% incorrect), only 37.5% enforce p=reject. Meanwhile, 33.3% linger at passive p=none, 15.3% use quarantine, and 13.9% have no record. DNSSEC adoption is 61.1% (38.9% disabled), while valid MTA-STS encryption is deployed on only 1.4% of domains (98.6% unconfigured), leaving corporate press channels vulnerable to brand impersonation.
Danish network operators and communication service providers achieve 98.2% correct SPF coverage (1.8% incorrect). However, active anti-spoofing enforcement is low: only 46.4% enforce p=reject, with 10.7% in quarantine, 25.0% idling at p=none, and 17.9% having no DMARC record. DNSSEC is implemented across 58.9% of domains (41.1% disabled). MTA-STS adoption is 0.0% across the board (100.0% unconfigured), exposing customer-facing communication channels to credential harvesting and subscriber deception.
Supporting Denmark's global shipping and distribution hubs, transport operators achieve 100.0% correct SPF records. Despite this foundation, policy enforcement is limited: only 42.3% enforce p=reject, while 23.1% use quarantine, 23.1% remain at p=none, and 11.5% have no record. DNSSEC adoption stands at 61.5% (38.5% disabled). MTA-STS implementation reaches 7.7% (92.3% unconfigured), meaning trade and freight documentation remains largely exposed to transport downgrade attacks.