Financial institutions in Singapore show high rates of initial DMARC record implementation driven by MAS regulatory oversight. However, adoption of transport-layer encryption via MTA-STS remains low. A small percentage of financial institutions still lack DMARC records entirely or linger at monitoring-only p=none policies, leaving room for targeted impersonation attacks.
Official public sector domains demonstrate strong baseline SPF alignment and DNSSEC adoption. However, policy progression to complete p=reject enforcement is gradual, with a notable portion of government and municipal subdomains remaining under passive p=none or quarantine configurations.
Healthcare organizations process high volumes of confidential medical and personal data, making them prime targets for phishing scams. While basic SPF adoption is broad, a substantial number of healthcare providers operate with passive p=none policies or lack DMARC protection completely, with minimal MTA-STS integration.
Academic institutions and research networks rely heavily on passive monitoring policies. Combined with low rates of p=reject enforcement and occasional DNS configuration issues, academic databases, intellectual property repositories, and student identities remain vulnerable to email spoofing.
Critical utility operators maintain solid baseline SPF coverage, but the transition to strict p=reject policy enforcement remains incomplete. With a proportion of utility domains remaining at passive monitoring levels and lacking MTA-STS encryption, transit interception risks persist across energy grid supply chains.
News agencies, media networks, and publishing groups show low rates of active policy enforcement. High reliance on passive p=none policies and unmonitored sending sources allows malicious actors to fabricate official press communications and news releases.
Telecom carriers and network service providers exhibit varying baseline configurations with occasional syntax errors in SPF records. Reliance on monitoring-only policies and low deployment of transit-layer protection leave customer communication channels exposed to subscription scams and identity theft.
Logistics, maritime, and supply chain operators show gradual progress in adopting active authentication policies. However, a significant fraction remains stuck at monitoring-only levels, and transport-layer encryption is rarely deployed, exposing trade documentation to transit interception.