Romania DMARC & MTA-STS Adoption Report 2026
Romanian organizations in 2026 navigate an increasingly aggressive threat landscape marked by Business Email Compromise (BEC), credential harvesting, and brand impersonation. While Romania maintains high-speed digital infrastructure and strong foundational SPF deployment, a nationwide assessment reveals a critical defensive vulnerability: widespread stagnation at passive monitoring and an almost total absence of transport-layer encryption. Under regulatory oversight from Romania’s National Cyber Security Directorate (DNSC), which enforces the EU NIS2 Directive via Government Emergency Ordinance no. 155/2024 (GEO 155/2024) and Law no. 124/2025, coupled with sender verification mandates from major mailbox providers, migrating to enforced domain authentication (p=reject) and MTA-STS is an urgent operational imperative to prevent delivery failures, defend supply chains, and satisfy statutory compliance.