Financial institutions in South Africa show relatively higher rates of initial DMARC implementation compared to other sectors. However, transport-layer encryption via MTA-STS remains largely unadopted across the sector. A subset of targeted financial institutions still lacks DMARC records entirely or remains stuck at passive monitoring levels, with DNSSEC adoption remaining limited.
State-owned entities and government domains generally maintain basic SPF records, but policy escalation to active enforcement is slow. A considerable proportion of public sector domains remain on passive p=none policies or lack DMARC protection altogether, while MTA-STS deployment is almost nonexistent.
Private and public health networks handle vast amounts of sensitive personal data, yet remain highly vulnerable to spoofing. Many healthcare providers continue to rely on passive monitoring policies, leaving medical administrative systems and patient data processing channels open to spoofing attacks.
Higher education institutions and academic research networks heavily rely on passive monitoring policies. Coupled with low p=reject enforcement and missing authentication records, academic networks, intellectual property repositories, and student communications face ongoing risk.
Critical utility and power generation entities maintain foundational SPF records, but transition toward active p=reject enforcement remains incomplete. With a portion of domains remaining on monitoring-only policies and lacking MTA-STS encryption, transit interception risks persist across utility supply chains.
Media and broadcasting organizations show limited adoption of modern email protection frameworks. High reliance on passive policies and missing DMARC configurations allow bad actors to impersonate news organizations and corporate press channels.
Telecommunication providers display varying baseline configurations with occasional SPF syntax errors. Reliance on passive monitoring and low deployment of transit-layer encryption leaves subscriber communication channels vulnerable to phishing and brand abuse.
Logistics and supply chain managers show moderate progress in implementing active security policies. However, a significant fraction remains at monitoring-only levels, and transport-layer encryption is rarely deployed, exposing supply chain documentation to interception.