PCI DSS 5.4.1: where do Québec merchants actually stand?

By Cyberbilan July 24, 2026 6 min read

Since March 31, 2025, PCI DSS requirement 5.4.1 has been mandatory at every assessment: any business handling card data must have “processes and automated mechanisms” against phishing. The standard names SPF, DKIM and DMARC as examples. So I scanned 35 well-known Québec merchants — grocers, pharmacies, restaurants, hardware chains, online stores — to see where they really stand.

In short:
35Québec merchants analyzed
45.7%nothing blocking spoofing
34.3%a DMARC that blocks nothing (“none”)
28.6%at maximum protection (“reject”)
74.3%site with no CSP header
74average score out of 100 (B)

What PCI DSS 5.4.1 asks, in one sentence

PCI DSS is the standard imposed by the payment card industry. Version 4.0 added requirement 5.4.1: processes and automated mechanisms must detect and protect personnel against phishing. Two words matter. Automated: awareness training alone, however good, does not satisfy it. And mandatory: it was only a best practice until March 31, 2025, when version 4.0.1 became the only active one.

The standard mandates no specific technology — it names DMARC, SPF and DKIM as examples of anti-spoofing controls. Those happen to be verifiable from the outside, without asking anyone. That is what I measured.

The result

DMARC policy — 35 Québec merchants, July 2026
No DMARC at all11.4%
DMARC “none” (blocks nothing)34.3%
DMARC “quarantine”25.7%
DMARC “reject”28.6%

Add the first two bars: 45.7% of these merchants have nothing stopping a fake email from landing in their customers' inbox. Not the spam folder: the inbox.

The “none” trap: the ticked box that protects nothing

This is the number that surprised me most. One merchant in three (34.3%) has published a DMARC record — and that record says p=none, meaning “watch, but block nothing”.

Picture a bouncer at your store's door. p=none is a bouncer who writes down who walks in and lets everyone through. p=quarantine puts the unwanted ones in a waiting room. p=reject turns them away. Most compliance checklists tick “DMARC: yes” in all three cases.

That monitoring mode is a normal, recommended step — you leave it a few weeks to confirm no legitimate sending gets blocked, then you move up. The problem is staying there for years. From the outside, a domain at p=none is as spoofable as a domain with no DMARC at all.

What merchants do well (and why)

91.4% sign their email with DKIM and only 5.7% have no SPF. Excellent — but there is a simple reason: Microsoft 365 and Google Workspace turn these on almost automatically when a domain is set up. They are the settings you get without thinking.

DMARC requires a decision: publish a record, choose a policy, accept that a misconfigured sender will be blocked. That is exactly the gap between 91.4% and 54.3%. The remaining work is not technical — it is a decision.

And the websites that handle payments?

The picture is weaker: 74.3% have no CSP header (the protection against script injection into a page — the one that matters when a payment form is involved) and 42.9% have no HSTS (which forces the browser to always use the encrypted connection). More than half of the sites score below 70/100 on our hardening scale.

One point of honesty: many of these merchants outsource the payment itself to an external gateway, which sharply reduces their PCI scope. A missing CSP on the brochure site is therefore not automatically a breach of the standard. But it is a door nothing is closing.

What this means for your business

These 35 businesses are mostly well-known chains with IT resources. If nearly half have not locked down domain spoofing, a neighbourhood shop, a garage or an independent restaurant is likely in worse shape — not better.

The good news: fixing it is free. DMARC is a DNS record, not software to buy. The sequence is always the same: publish p=none, read the reports for a few weeks, move to p=quarantine, then p=reject.

  1. Know where you stand — our free report reads your public records and tells you in 15 seconds what is missing.
  2. Understand what the standard expects — our PCI DSS 5.4.1 explained page covers it without auditor jargon.
  3. Apply the fixes — step-by-step guides for Microsoft 365 and Google Workspace.
  4. Keep dated evidence — to an assessor, a control without evidence does not exist. The report downloads as a dated PDF.

Important clarification: this study does not say these merchants are “not PCI DSS compliant”. The standard mandates no specific technology, a merchant can satisfy 5.4.1 another way, and scope depends on their self-assessment questionnaire. Cyberbilan is not a Qualified Security Assessor (QSA). What these numbers measure is the state of a public control, verifiable by anyone — including a fraudster.

Can your business be spoofed?

Enter your domain: in 15 seconds we test your SPF, DKIM, DMARC and website — free, no signup, public data only.

Run the free check →

Method and limitations: 36 domains of well-known Québec merchants (grocers, pharmacies, restaurants, hardware chains, retailers, online stores) were analyzed on July 24, 2026 with Cyberbilan's public scanner, which reads public information only (DNS records and site headers). 35 reachable sites were kept. No private data, no mailbox access, no payment testing. The sample deliberately consists of established businesses (therefore better equipped than average) and is modest in size: read it as a trend, not a census. Businesses are not named; only aggregate proportions are published. Results reproducible by anyone with the same scanner.