PCI DSS DMARC Requirement: What Section 5.4.1 Requires
# Summary
PCI DSS v4.0.1 does not explicitly mandate DMARC by name, but Requirement 5.4.1 makes automated anti-phishing mechanisms mandatory and lists DMARC, SPF, and DKIM as example controls that satisfy this requirement—a rule effective for all assessments since March 31, 2025. In practice, assessors expect organizations to implement DMARC or equivalent email authentication protocols to comply, even though the standard names it only as a suggested example rather than a hard requirement.
Read Full Article →