Romanian financial institutions exhibit strong SPF configuration at 96.5% (3.5% incorrect) and maintain the nation's highest DNSSEC adoption at 12.8% (87.2% disabled). In terms of policy enforcement, 26.8% have achieved p=reject, 26.7% utilize p=quarantine, and 20.9% remain at p=none. However, 23.3% still maintain no DMARC record (2.3% misconfigured), and 97.7% lack functional MTA-STS transport encryption (only 2.3% valid).
Public administration and government portals show strong SPF compliance at 98.2% (1.8% incorrect) and a low absence rate of DMARC at only 8.9%. Nonetheless, actual policy escalation is severely stalled: 51.8% of state domains linger under passive p=none monitoring, 21.4% rely on p=quarantine, and only 17.9% enforce p=reject. DNSSEC adoption is limited to 3.6% (96.4% disabled), while MTA-STS deployment sits at just 1.8% (98.2% lacking records).
Romanian healthcare organizations demonstrate severe vulnerability to domain impersonation, with only 11.8% having advanced to p=reject. Nearly a third of medical domains (30.9%) lack a DMARC record completely, while 38.2% sit at passive p=none and 19.1% use p=quarantine. Despite high SPF compliance at 97.1% (2.9% incorrect), the sector records 0.0% MTA-STS adoption (100.0% without a record) and DNSSEC enablement remains low at 5.9% (94.1% disabled).
Universities and academic institutions achieve a perfect 100.0% SPF implementation rate. However, email defense remains predominantly inactive, with 39.6% remaining at passive p=none, 22.6% possessing no DMARC record, and 20.8% at p=quarantine, leaving only 17.0% at p=reject. MTA-STS adoption is completely absent at 0.0% (100.0% without a record), while DNSSEC stands at 7.5% (92.5% disabled).
Energy utilities and grid operators demonstrate 100.0% SPF correctness and lead all Romanian sectors in MTA-STS transport encryption adoption at 8.1% valid (91.9% lacking records). Nevertheless, policy enforcement is weak: 32.5% operate under p=quarantine, 29.7% lack DMARC (2.7% incorrect), and 24.3% remain on passive p=none, leaving only 10.8% enforcing p=reject. DNSSEC adoption stands at 5.4% (94.6% disabled).
Media houses and broadcasting organizations exhibit solid SPF deployment at 96.1% (3.9% incorrect), but face severe exposure to identity abuse. Over a third (35.5%) have no DMARC record whatsoever, 32.9% operate on p=none, and 21.1% utilize p=quarantine, leaving merely 10.5% enforcing p=reject. Furthermore, 100.0% lack MTA-STS transport encryption (0.0% valid) and DNSSEC adoption is recorded at only 5.3% (94.7% disabled).
Telecom carriers present the lowest enforcement rates in the nation, with only 7.7% enforcing p=reject and 43.6% lacking a DMARC record entirely. While SPF configuration is high at 94.9% (5.1% incorrect), 28.2% of operators linger at p=none and 20.5% use p=quarantine. MTA-STS deployment is nonexistent at 0.0% (100.0% without a record), and DNSSEC enablement sits at just 5.1% (94.9% disabled).
Transport and logistics providers lead the country in strict policy enforcement, with 41.4% enforcing p=reject. However, 24.1% lack DMARC records altogether, 24.1% remain on passive p=none, and 10.4% use p=quarantine. SPF alignment is 93.1% (6.9% incorrect), while both MTA-STS adoption and DNSSEC enablement stand at 6.9% (93.1% lacking records / disabled).