We scored 596 domains across nine sectors on NODA's dual-axis DNS methodology, chosen specifically to test whether technical sophistication predicts DNS security posture: DNS/hosting infrastructure, financial services, government (non-US-mandate jurisdictions), healthcare, large ISPs, news/media, and cloud/SaaS split into hyperscale and mid-market cohorts.

Scope and a note on how this was checked

Before writing this, every sector was individually audited for the kind of domain-resolution artifact that has previously affected published NODA research — a broken or misresolved domain producing an artificially low score that gets mistaken for a genuine finding. Result: zero such artifacts in any of the nine sectors. Two silently-failed checks were identified and re-run successfully — both are live, correctly-resolving domains (lamoncloa.gob.es, nyulangone.org) that hit a transient recursive-resolver timeout during the original batch, not a bad URL. Two further domains (cimb.com, airtel.in) were excluded after repeated re-checks: both are live, but each returns enough nameservers that the check pipeline cannot complete within the server's response-time limit — a pipeline constraint, not a finding about either domain, disclosed here rather than silently dropped.

A note on scope: these are representative samples compiled from established sector-recognition sources, not exhaustive censuses. All figures reflect a live check on August 11, 2026; DNS configurations drift.

The cross-sector table

SectornDNSSECvs. 7% baselineDKIM missingSingle-AS
Government (non-US-mandate)8133.8%~4.8×74.6%¹45.0%
DNS/hosting infrastructure7229.2%~4.2×35.8%54.2%
Financial services9925.3%~3.6×58.8%55.6%
Cloud/SaaS — hyperscale4920.4%~2.9×31.8%55.1%
Large ISPs6015.0%~2.1×61.4%63.3%
Cloud/SaaS — mid-market5111.8%~1.7×3.9%90.2%
Healthcare6510.8%~1.5×62.7%81.5%
VPS/general hosting508.0%~1.1×24.0%88.0%
News/media697.2%~flat29.2%78.3%

¹ Government's DKIM figure is the outlier a standalone piece on that sector covers in depth — the short version: the same agencies that lead on DNSSEC show the weakest DKIM adoption measured anywhere in this dataset, evidence that a strong habit around one commitment doesn't automatically transfer to a differently-shaped one. Full piece →

Sorted by DNSSEC adoption against APNIC's 7% global secure-delegation baseline for 2025, every sector here clears that baseline — media sits closest to it, essentially flat.

DKIM and DNSSEC track completely different rankings. No sector that leads on one reliably leads on the other.

What doesn't correlate is as informative as what does

Read down the DNSSEC column and the DKIM column side by side. Government leads DNSSEC and trails DKIM worse than any other sector measured. Cloud/SaaS mid-market has the best DKIM hygiene of any sector in this dataset — missing on just 3.9% of domains, far ahead of sectors with much higher DNSSEC adoption — while sitting near the bottom on DNSSEC (11.8%) and carrying the second-highest single-AS concentration measured (90.2%). Financial services, generally disciplined across the board, still shows DKIM missing on nearly six in ten applicable domains (58.8%) despite DMARC being essentially universal in the same sector (missing on just 1%).

DNSSEC, DKIM, DMARC, and network redundancy are four separate operational commitments, each with its own decision cycle, its own point of ownership within an organization, and its own failure mode. A sector — or an individual domain operator — can be genuinely disciplined about one and genuinely inconsistent about another, and this dataset says that's the norm, not the exception. Treating any single metric as a proxy for "DNS security maturity" overall will consistently mislead.

Sector notes

DNS/hosting infrastructure (n=72). The sharpest test in this dataset: do the companies who sell DNSSEC automation and DNS-as-a-service sign their own zones? Mostly — 29.2% adoption, second-highest of any sector measured. But Best Practice has real spread (avg 81, range 64–100), and the bottom performer is notable: aws.amazon.com scores BP=64, the lowest Best Practice score in this sector, and the same domain reappears at the bottom of the hyperscale cloud cohort below.

Financial services (n=99). The most Health-consistent sector measured (avg 97.5, standard deviation 2.14) and the strongest DMARC posture of any sector in this dataset — missing on just 1% of domains, essentially universal. That discipline doesn't extend to DKIM, missing on 58.8% of applicable domains — worse than every sector here except government, healthcare, and ISPs. DNSSEC sits at 25.3%, solidly above baseline but well behind government and DNS-infrastructure specialists.

Cloud/SaaS — hyperscale (n=49). Fifth of nine sectors on DNSSEC (20.4%), behind government, DNS-infrastructure specialists, financial services, and — per the companion piece drawing on the full dataset — universities, despite having the deepest DNS engineering benches in the sample. Best Practice shows real spread in this cohort (avg 78.7, range 64–97): aws.amazon.com (BP=64), azure.microsoft.com (H=70), and cloud.google.com (H=70) all sit at or near the bottom of their own sector.

Large ISPs (n=60). DNSSEC adoption of 15% sits almost exactly at twice the global secure-delegation baseline, and pairs informatively with APNIC's 36% global validation figure: these are, in large part, the organizations operating the resolvers behind that validation number, and a meaningful majority of them are not signing their own corporate zones. DKIM missing on 61.4% of applicable domains is the third-worst figure in this dataset, behind only government and healthcare.

Cloud/SaaS — mid-market (n=51). The best mail-authentication hygiene measured anywhere in this dataset — DKIM missing on just 3.9% of domains, DMARC missing on 0% — alongside the second-highest single-AS concentration (90.2%) and DNSSEC adoption in the bottom third (11.8%). A genuinely interesting split: strong on the operational commitment closest to the product these companies sell (reliable, correctly-configured mail infrastructure for their own transactional email), weaker on the ones further from that core competency.

Healthcare (n=65). The second-weakest DKIM coverage of any sector in this dataset — 62.7% missing, behind only government's outlier finding — and the third-highest single-AS concentration measured (81.5%), behind only mid-market SaaS and VPS hosting. DNSSEC sits in the bottom third (10.8%). Health scores hold up fine (avg 95.4) — this is a hygiene story, not a reliability one. Given the sector's stated threat model (ransomware, patient-data exposure), the gap between operational risk and DNS hygiene here is wider than most.

VPS/general hosting (n=50). The lowest DNSSEC adoption of any sector in this dataset (8%), and the second-highest single-AS concentration measured (88%) — consistent with a "DNS is incidental to the product" profile, distinct from the DNS-infrastructure specialists this sector was deliberately split from.

News/media (n=69). DNSSEC adoption of 7.2% sits almost exactly at the global baseline — the only sector in this dataset that doesn't clear it by a wide margin. Single-AS concentration is high (78.3%). This sector was scored as a control group with no strong prior in either direction; the result reads as "unremarkable," which is itself the finding — no institutional habit pulling it above baseline, no acute failure pulling it below.

Government (n=81). Covered in full in a standalone piece: highest DNSSEC adoption of any sector measured (33.8%), with no comparable mandate in force across the nineteen jurisdictions sampled — and the weakest DKIM adoption in this dataset (74.6% missing), the specific finding that motivates the "institutional habit doesn't transfer" thesis running through this piece. Read the full sector breakdown →

The takeaway

Nine sectors, 596 domains, and the pattern that holds across nearly all of them is this: technical sophistication is not the strongest predictor of DNS security posture, and neither is budget, and neither is threat exposure. What predicts a strong result on any single commitment — DNSSEC, DKIM, DMARC, network redundancy — looks like whether that specific commitment has become someone's routine job inside that organization, independent of how sophisticated the rest of its infrastructure is. The sectors that lead on one axis are frequently the same sectors that lag on another, and no sector in this dataset is disciplined across the board.

That's not a discouraging finding. It's an actionable one: an organization that has already built the habit around one DNS security commitment has already done the harder part — establishing that this class of maintenance gets owned, budgeted, and revisited. Extending that same habit to a second commitment is a smaller lift than building the first one was.

What to do about it

  • Don't infer overall DNS security posture from a single check. A strong DNSSEC result says nothing reliable about DKIM coverage in the same organization, and vice versa — verify each commitment independently.
  • If one DNS security commitment is already well-established internally, audit for a second one next, rather than assuming the same discipline transferred automatically. The government and financial-services findings above are the clearest evidence in this dataset that it doesn't.
  • Single-AS concentration is the most commonly overlooked finding across this dataset — it's high (45–90%) in every sector measured. Confirm whether your own single AS, if you have one, is a resilient anycast network before treating this as unaddressed risk.

⇩ Download full report (PDF)

Curious where your own domain lands? Run it through NODA and see the same 41 checks scored live.

Scored using NODA, a dual-axis DNS Health + Best Practice methodology (41 checks, 5 weighted categories). Read the full methodology: NODA-v1.0 Specification.