Romania DMARC & MTA-STS Adoption Report 2026

Romanian organizations in 2026 navigate an increasingly aggressive threat landscape marked by Business Email Compromise (BEC), credential harvesting, and brand impersonation. While Romania maintains high-speed digital infrastructure and strong foundational SPF deployment, a nationwide assessment reveals a critical defensive vulnerability: widespread stagnation at passive monitoring and an almost total absence of transport-layer encryption. Under regulatory oversight from Romania’s National Cyber Security Directorate (DNSC), which enforces the EU NIS2 Directive via Government Emergency Ordinance no. 155/2024 (GEO 155/2024) and Law no. 124/2025, coupled with sender verification mandates from major mailbox providers, migrating to enforced domain authentication (p=reject) and MTA-STS is an urgent operational imperative to prevent delivery failures, defend supply chains, and satisfy statutory compliance.

At a Glance: Key Findings Across Romania

Our national analysis across Romanian domain assets highlights commendable baseline record publishing alongside substantial gaps in active policy enforcement and transit cryptography:

romania-spf

SPF Baseline Discipline (97.1% Correct): Romanian organizations exhibit high administrative competence in fundamental email configuration, with 97.1% publishing syntactically valid SPF records and only 2.9% containing formatting errors or misconfigurations.

Romania DMARC adoption

The DMARC Enforcement Deficit (Only 17.3% at p=reject): While 73.0% of assessed Romanian domains publish a DMARC policy, only 17.3% maintain a full protective p=reject policy to stop illegitimate email traffic. The remainder stay exposed through passive observation (p=none at 32.9%), intermediate quarantine rules (p=quarantine at 22.1%), record syntax defects (0.7%), or a total absence of DMARC (27.0%).

romania-mta-sts

MTA-STS In-Transit Vulnerability (98.2% Unsecured): Server-to-server mail encryption remains severely under-addressed across Romanian cyberspace. A staggering 98.2% of domains lack an MTA-STS policy, leaving SMTP transmissions vulnerable to Man-in-the-Middle (MiTM) TLS downgrade attacks, with only 1.8% having deployed valid transit enforcement.

romania-dnssec

DNSSEC Security Adoption Void (93.0% Disabled): Cryptographic DNS integrity remains a substantial blind spot, with only 7.0% of analyzed Romanian domains having enabled DNSSEC. The remaining 93.0% are left unprotected against DNS spoofing, cache poisoning, and route manipulation.

Sector-by-Sector Analysis

1. Financial Services (Banking): Strong Baseline Awareness with Incomplete Enforcement

Driven by National Bank of Romania (BNR) regulatory standards and early alignment with NIS2 requirements, Romanian commercial banks lead the nation in DNS integrity, yet still leave key enforcement avenues open.

Protocol Metric Current Status
SPF Accuracy 96.5% Correct (3.5% Incorrect)
DMARC Reject Policy 26.8% (p=reject)
DMARC Policies 26.7% Quarantine, 20.9% None
DMARC Gap 23.3% Missing Record, 2.3% Incorrect
MTA-STS Adoption 2.3% Valid (97.7% Unsecured)
DNSSEC Adoption 12.8% Enabled (Sector Leader, 87.2% Disabled)
finance-spf-romania

Vulnerability Exposure

Banking domains achieve a solid combined enforcement posture of 53.5% (p=reject at 26.8% and p=quarantine at 26.7%) and lead all surveyed sectors in DNSSEC deployment (12.8%). However, nearly a quarter (23.3%) lack DMARC completely, and 20.9% remain restricted to passive p=none monitoring. Furthermore, with 97.7% lacking MTA-STS, transactional data in transit remains vulnerable to wiretapping and TLS stripping.

The PowerDMARC Strategy

PowerDMARC enables financial institutions to migrate safely from passive monitoring to full p=reject enforcement without risking false positives, while hosted MTA-STS automates TLS transport protection across inter-banking exchanges.

2. Healthcare: High DMARC Absence and Minimal Transport Protection

Romanian public and private health networks safeguard critical patient records and vital life-sciences communications, yet display an alarmingly weak defensive posture across advanced protocols.

Protocol Metric Current Status
SPF Accuracy 97.1% Correct (2.9% Incorrect)
DMARC Reject Policy 11.8% (p=reject)
DMARC Policies 19.1% Quarantine, 38.2% None
DMARC Gap 30.9% Missing Record
MTA-STS Adoption 0.0% Valid (100.0% Unsecured)
DNSSEC Adoption 5.9% Enabled (94.1% Disabled)
healthcare-dmarc-romania

Vulnerability Exposure

Healthcare recorded a high DMARC absence rate (30.9%) and a low rejection enforcement rate (11.8%). With 38.2% of medical organizations stagnant at p=none and zero adoption of MTA-STS (100.0% unsecured), approximately 69% of healthcare domains provide no active defense against impersonation, leaving health systems vulnerable to patient-targeted phishing and ransomware delivery.

The PowerDMARC Strategy

We provide healthcare organizations with automated, gradual rollout paths toward p=reject, ensuring medical lab reports, appointment systems, and patient alerts maintain deliverability while neutralizing spoofing.

3. Public Sector (Government): High Domain Coverage, Monitoring Stagnation

Romanian central and local government domains carry high administrative trust, reflected in strong baseline publishing, yet strict policy enforcement remains severely delayed.

Protocol Metric Current Status
SPF Accuracy 98.2% Correct (1.8% Incorrect)
DMARC Reject Policy 17.9% (p=reject)
DMARC Policies 21.4% Quarantine, 51.8% None
DMARC Gap 8.9% Missing Record
MTA-STS Adoption 1.8% Valid (98.2% Unsecured)
DNSSEC Adoption 3.6% Enabled (Sector Low, 96.4% Disabled)
public-sector-mta-sts-romania

Vulnerability Exposure

Government entities achieve the nation’s lowest DMARC omission rate (only 8.9% missing). However, more than half (51.8%) of civic domains are parked at p=none, where unauthorized emails are delivered without interruption. Furthermore, government domains record the lowest DNSSEC adoption in the country (3.6%), exposing official civic portals to DNS hijacking and fraudulent tax/legal scam campaigns.

The PowerDMARC Strategy

PowerDMARC’s multi-tenant management portal allows municipal and ministerial IT administrators to oversee complex public agency domains from a centralized console, expediting the transition to strict policy enforcement for DMARC for government.

4. Education: Flawless SPF Accuracy, Inadequate Transit Encryption

Romanian academic and research institutions manage large student and faculty bases across distributed networks, showing flawless basic hygiene but persistent transit vulnerabilities.

Protocol Metric Current Status
SPF Accuracy 100.0% Correct (0.0% Incorrect)
DMARC Reject Policy 17.0% (p=reject)
DMARC Policies 20.8% Quarantine, 39.6% None
DMARC Gap 22.6% Missing Record
MTA-STS Adoption 0.0% Valid (100.0% Unsecured)
DNSSEC Adoption 7.5% Enabled (92.5% Disabled)
education-dnssec-romania

Vulnerability Exposure

While education achieves 100.0% SPF accuracy, nearly 40% (39.6%) of educational domains linger in passive monitoring (p=none), and 22.6% lack DMARC completely. With complete non-adoption of MTA-STS (100.0% unsecured), universities and academic institutions remain attractive targets for credential harvesting and research data theft.

The PowerDMARC Strategy

Complex educational IT ecosystems frequently integrate multiple third-party educational and mailing tools, exceeding the 10-DNS lookup limit. PowerSPF flattening optimizes SPF records dynamically to prevent lookup failure errors and safeguard delivery.

5. Energy: National Leadership in MTA-STS, Solid Quarantine Posture

As a critical infrastructure sector categorized under Annex 1 of GEO 155/2024, Romania’s energy grid operators show proactive transit security implementation alongside dependable basic records.

Protocol Metric Current Status
SPF Accuracy 100.0% Correct (0.0% Incorrect)
DMARC Reject Policy 10.8% (p=reject)
DMARC Policies 32.5% Quarantine, 24.3% None
DMARC Gap 29.7% Missing Record, 2.7% Incorrect
MTA-STS Adoption 8.1% Valid (National Leader, 91.9% Unsecured)
DNSSEC Adoption 5.4% Enabled (94.6% Disabled)
energy-spf

Vulnerability Exposure

The energy sector leads Romania in MTA-STS transport encryption (8.1%) and demonstrates solid quarantine adoption (32.5%). However, only 10.8% enforce p=reject, and almost a third (29.7%) lack a DMARC record. This leaves operational supply chains and utility dispatch communications open to executive impersonation.

The PowerDMARC Strategy

We combine automated hosted MTA-STS with active DMARC policy controls to secure critical infrastructure operators against spear-phishing, digital espionage, and transport manipulation.

6. Media: Significant Identity Exposure and Elevated DMARC Absence

Romanian broadcast, digital news, and print media organizations hold substantial public influence, but their domain authentication defenses reveal widespread exposure.

Protocol Metric Current Status
SPF Accuracy 96.1% Correct (3.9% Incorrect)
DMARC Reject Policy 10.5% (p=reject)
DMARC Policies 21.1% Quarantine, 32.9% None
DMARC Gap 35.5% Missing Record
MTA-STS Adoption 0.0% Valid (100.0% Unsecured)
DNSSEC Adoption 5.3% Enabled (94.7% Disabled)
media-dmarc-romania

Vulnerability Exposure

Media domains demonstrate a high omission rate, with 35.5% lacking DMARC records altogether and 32.9% relying on passive p=none monitoring. Coupled with a minimal p=reject rate (10.5%) and zero MTA-STS deployment (100.0% unsecured), news publishers remain exposed to disinformation campaigns and fraudulent press releases sent under their name.

The PowerDMARC Strategy

By deploying Brand Indicators for Message Identification (BIMI) in coordination with enforced DMARC policies, media organizations can project verified visual brand trust in subscriber inboxes while eliminating spoofing vectors.

7. Telecommunications: Highest DMARC Void and Lowest Rejection Rate

Telecommunications operators operate complex, high-throughput network architectures, yet exhibit the most pronounced email authentication gaps among all analyzed sectors.

Protocol Metric Current Status
SPF Accuracy 94.9% Correct (5.1% Incorrect)
DMARC Reject Policy 7.7% (National Low)
DMARC Policies 20.5% Quarantine, 28.2% None
DMARC Gap 43.6% Missing Record (Sector High)
MTA-STS Adoption 0.0% Valid (100.0% Unsecured)
DNSSEC Adoption 5.1% Enabled (94.9% Disabled)
telecom-spf-romania

Vulnerability Exposure

Telecommunications ranks lowest in Romania for active DMARC rejection (7.7%) and highest for total DMARC omission (43.6% missing). With complete absence of MTA-STS (100.0% unsecured), carrier domains and subdomains remain susceptible to SMS/email gateway abuse, invoice fraud, and subscriber phishing.

The PowerDMARC Strategy

PowerDMARC simplifies policy escalation across complex telco routing architectures, allowing carriers to eliminate unauthorized sending sources without impacting customer delivery.

8. Transport & Logistics: National Leader in Enforcement, Notable Transit Adoption

Romanian transport and logistics operators handle extensive cross-border trade, freight documentation, and B2B shipping transactions, driving the country’s highest policy enforcement rate.

Protocol Metric Current Status
SPF Accuracy 93.1% Correct (6.9% Incorrect)
DMARC Reject Policy 41.4% (National Leader)
DMARC Policies 10.4% Quarantine, 24.1% None
DMARC Gap 24.1% Missing Record
MTA-STS Adoption 6.9% Valid (Strong Second Place, 93.1% Unsecured)
DNSSEC Adoption 6.9% Enabled (93.1% Disabled)
transport-romania

Vulnerability Exposure

Logistics providers outperform all other Romanian industries in active enforcement, recording a remarkable 41.4% p=reject rate, alongside strong MTA-STS adoption (6.9%). Nonetheless, 24.1% still lack DMARC completely and 6.9% exhibit SPF syntax errors, exposing supply chain partners to invoice redirection schemes.

The PowerDMARC Strategy

We provide transport and freight operators with continuous sender visibility, dynamic SPF validation, and automated TLS enforcement, protecting logistics billing and supply chain manifests.

Deep Dive: Four Systemic Vulnerabilities in Romanian Domains

1. The Observation Trap: Over-Reliance on p=none

A primary systemic vulnerability across Romania’s digital domain assets is treating passive monitoring as a finished security state. Currently, 32.9% of all Romanian domains remain stationary at p=none. While p=none generates telemetry on outbound mail sources via aggregate RUA reports, it provides zero active defense against spoofing – unauthorized phishing emails continue to land in recipient inboxes unhindered.

Expert insight:

“Deploying DMARC at p=none without an active plan to reach enforcement is like installing security cameras while leaving your entrance unlocked. Monitoring displays threats, but only strict p=reject policies stop impersonation.”

Romania DMARC adoption

Maitham Al Lawati, CEO, PowerDMARC

Expert insight:

“Enterprise cloud adoption makes SPF lookup limit breaches almost inevitable. Implementing dynamic SPF flattening is vital to programmatic record optimization, eliminating format errors, and protecting critical outbound deliverability.”

Romania DMARC adoption

Yunes Tarada, Service Delivery Manager, PowerDMARC

2. SPF Lookup Exhaustion and Delivery Hardening

As Romanian enterprises adopt multifaceted cloud software stacks (ERP systems, CRMs, marketing automation, payroll portals), domain SPF records frequently breach the strict 10-DNS lookup ceiling set by RFC specifications. Exceeding this boundary triggers PermError validation failures, causing legitimate corporate emails to be rejected or directed to spam folders.

3. MTA-STS: Opportunistic Mail Transit Vulnerabilities

With 98.2% of Romanian domains lacking MTA-STS configurations, inbound and outbound email transmissions rely almost exclusively on opportunistic STARTTLS. Network adversaries positioned along mail routing paths can easily carry out SSL-stripping and Man-in-the-Middle (MiTM) downgrade attacks to intercept cleartext communications and tamper with message contents.

Expert insight:

“Opportunistic encryption is not a secure strategy for transport security. Without enforced MTA-STS, attackers can easily downgrade connection paths to intercept corporate communications. Implementing strict transport encryption is non-negotiable for preserving message integrity and privacy.”

Romania DMARC adoption

Ayan Bhuiya, Operations & Delivery Shift Lead, PowerDMARC

Expert insight:

“If your base domain registry is compromised in a DNS cache-poisoning attack, your downstream application security measures become ineffective. DNSSEC provides the cryptographic signature needed to verify that users are reaching your actual servers rather than a malicious lookalike.”

Romania DMARC adoption

Engjell Koliqi, Marketing Manager, PowerDMARC

4. DNSSEC: Trust Gaps at the Routing Layer

With 93.0% of Romanian enterprise and institutional domains omitting DNSSEC, the vast majority remain unprotected against DNS cache poisoning, rogue zone tampering, and DNS-level redirection schemes.

Global Benchmarking: Romania in Context

While Romania demonstrates strong baseline SPF compliance on par with leading Western European economies, its overall DMARC enforcement and transport encryption rates reveal clear room for operational advancement.

The Global Leaderboard: 2026 Comparative Data

Country SPF Correct DMARC Reject MTA-STS Valid DNSSEC Enabled
Switzerland 96.0% 16.8% 4.4% 32.6%
Austria 97.0% 19.7% 1.9% 7.1%
France 95.6% 28.3% 2.6% 17.9%
Spain 97.0% 18.0% 0.8% 10.4%
Italy 91.0% 16.7% 1.0% 3.5%
Poland 98.9% 21.2% 0.9% 15.7%
Netherlands 70.0% 23.2% 0.9% 37.7%
Brazil 92.1% 20.7% 0.7% 21.9%
Ecuador 96.1% 24.9% 1.4% 4.8%
USA 95.7% 49.0% 1.7% 18.0%
UK 93.7% 44.1% 20.6% 3.8%

Romania in the Global Spotlight: 2026 Analysis

1
Enforcement Position

Romania’s p=reject enforcement rate (17.3%) outperforms Switzerland (16.8%) and Italy (16.7%), closely trailing Spain (18.0%) and Austria (19.7%), but sitting behind France (28.3%), the UK (44.1%), and the US (49.0%).

2
MTA-STS Compliance

At 1.8%, Romania’s MTA-STS adoption exceeds regional peers including Spain (0.8%), Poland (0.9%), Italy (1.0%), and the USA (1.7%), standing level with Austria (1.9%) while trailing Switzerland (4.4%), France (2.6%), and the UK (20.6%).

3
DNSSEC Standing

Romania’s DNSSEC adoption rate (7.0%) aligns closely with Austria (7.1%) and surpasses Italy (3.5%) and Ecuador (4.8%). However, it trails Spain (10.4%), Poland (15.7%), France (17.9%), Switzerland (32.6%), and the Netherlands (37.7%).

The PowerDMARC Viewpoint

“Romania has demonstrated commendable baseline hygiene with exceptionally high SPF accuracy across key operational sectors. The immediate imperative for Romanian IT and security executives is converting passive observation into enforced protection. With the DNSC actively implementing the regulatory controls and sanctions outlined in GEO 155/2024 and Law 124/2025, moving to strict p=reject policies and enforced MTA-STS transit encryption is crucial for national cyber resilience.”

Strategic Roadmap: Transitioning to Active Protection

To mitigate impersonation risks and comply with national NIS2 transposition standards, Romanian organizations should implement a structured three-step technical roadmap:

Advance to Full Enforcement (p=reject)

Migrate methodically from passive observation (p=none) through gradual quarantine (p=quarantine) to complete rejection (p=reject)

Deploy Hosted MTA-STS & TLS-RPT

Implement enforced transit encryption across all SMTP routing gateways to eliminate cleartext downgrade vulnerabilities, utilizing automated TLS reporting to monitor transit failures.

Automate SPF Record Optimization

Utilize dynamic SPF flattening (PowerSPF) to prevent DNS lookup threshold violations and maintain high-volume email deliverability.

Methodology, Research & Data Sources

DNS Record Analysis

Automated DNS query scans were conducted across Swiss enterprise domain directories, evaluating SPF, DMARC, MTA-STS, and DNSSEC records against strict IETF/RFC standards.

Sector Sampling

Domains were evaluated across 10 distinct Swiss economic sectors:

  • Banking (Financial Services)
  • Healthcare
  • Public Sector (Government)
  • Education
  • Energy
  • Media
  • Telecommunications
  • Transport & Logistics
  • Job Boards
  • Fitness & Wellness

Global Benchmarking

Comparative international indexes were compiled using the same DNS-analysis methodologies from PowerDMARC's global cybersecurity dataset. This allows Switzerland's metrics to be directly compared to standardized country indexes from Austria, France, Spain, Italy, Poland, the Netherlands, Brazil, Ecuador, the USA, and the UK.

Risk Classification

Evaluations incorporate published p=reject enforcement ratios, DMARC absence rates, SPF syntax error percentages, MTA-STS enforcement, and active DNSSEC validation status.

Transforming Romanian Domain Visibility into Active Defense

Romanian organizations possess a solid foundation in basic domain administration. Elevating communication channels against evolving threats requires progressing from passive monitoring to automated, active enforcement. Contact the PowerDMARC team today to assess and secure your organization’s domain ecosystem.