• Remote Support
  • Client Portal
  • Call us on 0333 444 3455
Business IT Services by CNLTD
  • What we do
    • Managed IT Services
    • Shield: Comprehensive Cybersecurity and Data Protection
    • Cyber Essentials
    • DMARC Implementation
    • Data Backup and Recovery Solutions
    • Business VOIP Phone System
    • Business Connectivity Solutions
  • Microsoft 365
  • What are Managed IT Services?
  • Industries
    • #1 Managed IT for Insurance Brokers
    • Expert Managed IT Support for Accountants
    • Solicitors IT Support Services
    • IT Support for Charities and Not for Profits.
    • IT Support for Early Years Education
    • Specialist IT Support for Healthcare
  • About
    • About Us
    • Service Locations
    • Meet The Team
  • Resources
    • Latest News
      • Security
      • Resources
      • Strategy
      • Cloud
      • Infrastructure
      • Company and Community
    • Commercial Networks University
    • Encyclopaedia
  • Contact us

PCI DSS v4 Now Requires DMARC – What You Need to Know

If your business handles cardholder data, you’re likely familiar with PCI DSS, the security standard that governs how payment data is processed and protected. But as of March 2025, there’s a new requirement that might catch some organisations off guard: DMARC (Domain-based Message Authentication, Reporting and Conformance) is now part of the standard.

So what does that mean, and what do you need to do about it?


First, What Is DMARC?

DMARC is an email authentication protocol that helps prevent phishing, spoofing, and other email-based attacks. It builds on SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) by giving domain owners a way to:

  • Tell receiving email servers how to handle messages that fail authentication
  • Request reports on how their domain is being used

In short: it gives you visibility and control over your domain’s email reputation.


What’s Changed with PCI DSS v4.0?

Under Requirement 8.6.1 of PCI DSS v4.0 (as of 31st March 2025), organisations must implement controls to protect against email-based threats and that includes having a DMARC policy in place for all domains used to send emails.

This means:

  • You can no longer skip DMARC if you’re subject to PCI compliance
  • You need to align SPF, DKIM, and DMARC properly
  • The policy must be configured to enforce protection (not just monitor)

What Happens If You Don’t Implement DMARC?

Non-compliance could mean:

  • Failing a PCI audit
  • Increased risk of phishing attacks using your domain
  • Potential fines or restrictions from card processors or acquiring banks

More critically, it leaves your staff and customers vulnerable to impersonation attacks that are easily preventable.


How to Get Compliant

  1. Check if your domain has a DMARC record
    Use tools like MXToolbox or nslookup to see if a DMARC record exists.
  2. Start in ‘none’ mode
    Use p=none to begin collecting reports without impacting mail flow.
  3. Review reports and align SPF/DKIM
    Ensure all authorised senders are covered.
  4. Move to ‘quarantine’ or ‘reject’
    Once you have full visibility, update the policy to enforce protection (p=quarantine or p=reject).
  5. Document everything
    Auditors will expect clear records of implementation, monitoring, and enforcement.

Need Help?

DMARC isn’t just a checkbox, it’s a vital part of securing your business email and protecting your reputation. If you’re navigating PCI compliance or unsure where your domains stand, we can help review, configure, and monitor everything for peace of mind.

Let’s make compliance easier and your email safer.

Commercial Networks pci dss v4

You may also like

Padlocks and ethernet cableHow Microsoft 365 products help with GDPR compliance DMARC illustrationWhy You Need to Pay Attention to Secure Business Email Security Right Now GDPR complianceWhat Happens After a GDPR Breach? The 5 Big Potential Consequences Commercial Networks NIS2 and UK NIS RegulationsNIS2 vs UK Cybersecurity Regulations: How UK Businesses Can Stay Compliant and Secure
Get a free 30 minute IT consultation

We'd love to find out more about your IT...

Pick up the phone and call 0333 444 3455 today so we can discuss how we can help your business move forward. Our support Hotline is available 08:30 - 17:30 Monday - Friday

You can also reach us using the form here, Commercial Networks Ltd looks forward to becoming your preferred IT partner.

Follow us on LinkedIn Follow us on Facebook Follow us on Twitter

OFFICE LOCATIONS
Stoke on Trent
Newcastle Under Lyme
Falkirk
Manchester
Oswestry

© 2026 Commercial Networks LTD
Privacy Policy
Cookie Policy
Terms and Conditions

    • What we do
      • Managed IT Services
      • Shield: Comprehensive Cybersecurity and Data Protection
      • Cyber Essentials
      • DMARC Implementation
      • Data Backup and Recovery Solutions
      • Business VOIP Phone System
      • Business Connectivity Solutions
    • Microsoft 365
    • What are Managed IT Services?
    • Industries
      • #1 Managed IT for Insurance Brokers
      • Expert Managed IT Support for Accountants
      • Solicitors IT Support Services
      • IT Support for Charities and Not for Profits.
      • IT Support for Early Years Education
      • Specialist IT Support for Healthcare
    • About
      • About Us
      • Service Locations
      • Meet The Team
    • Resources
      • Latest News
      • Commercial Networks University
      • Encyclopaedia
    • Contact us