Financial institutions in Turkey lead the market in initial DMARC setup under BDDK regulatory oversight. However, transport-layer encryption via MTA-STS remains largely unadopted across the sector. A subset of financial entities still operates under passive p=none policies or lacks DMARC entirely, while DNSSEC adoption remains limited.
Public sector agencies show strong baseline SPF adoption driven by national cybersecurity directives. However, policy escalation to active p=reject rules is slow, with a notable portion of government domains remaining on passive monitoring or lacking DMARC, alongside negligible MTA-STS deployment.
Public and private healthcare providers manage high volumes of confidential personal data under KVKK rules. Despite this, many healthcare organizations continue to rely on passive p=none policies or lack DMARC protection completely, exposing patient processing channels and administrative networks to domain spoofing.
Academic institutions and research networks demonstrate a high reliance on passive monitoring policies. Coupled with low p=reject adoption and missing authentication records, educational networks, student records, and intellectual property remain exposed to phishing exploitation.
Power generation and utility operators maintain solid baseline SPF records, but transition toward active p=reject enforcement remains incomplete. With a portion of domains remaining on monitoring-only policies and lacking MTA-STS encryption, transit interception risks persist across critical energy supply chains.
Broadcasting and digital media companies show low adoption of restrictive DMARC policies. Widespread reliance on passive monitoring enables malicious actors to forge trusted press voices and distribute deceptive public communications.
Telecom carriers present variable baseline setup quality, with occasional SPF configuration errors. Heavy reliance on passive monitoring and low adoption of transit-layer encryption leaves subscriber messaging channels vulnerable to subscription scams and brand abuse.
Logistics and supply chain providers demonstrate moderate progress in publishing DMARC records. However, a significant fraction remains stuck at monitoring-only levels, and transport-layer encryption is rarely deployed, leaving operational supply chain communications open to interception.