Do you accept card payments? Enter your domain: we check the state of the email controls the standard names as examples — explained without auditor jargon.
Free, no signup. Result in 15 seconds, with the full report (SPF, DKIM, DMARC, website).
PCI DSS is the security standard imposed by the payment card industry. Version 4.0 added requirement 5.4.1: “processes and automated mechanisms must be in place to detect and protect personnel against phishing attacks.” It started as a best practice — it has been mandatory at every assessment since March 31, 2025, the date v4.0.1 became the only active version.
Two things merchants often discover too late: the key word is automated (security-awareness training alone, however good, does not satisfy it), and the standard names DMARC, SPF and DKIM as examples of anti-spoofing controls in its guidance column. It does not mandate one single technology, but email authentication is the control everyone looks for first — because it is the one that stops a fraudster from writing to your customers or staff in your name.
PCI DSS applies as soon as you process, transmit or store card data — an in-store terminal, an online store, payments taken over the phone. Size does not change that: what changes is the self-assessment questionnaire (SAQ) your payment provider or acquiring bank asks you to complete, and the list of requirements differs from one questionnaire to another. Ask them which one applies to you. Either way, locking your domain against spoofing cannot hurt: it is free to configure and it protects you even with no audit in sight.
p=quarantine then p=reject. This is the most common gap: many businesses have DMARC at p=none, which observes without blocking anything.Curious where everyone else stands? We scanned 35 Québec merchants: 45% have nothing blocking spoofing, with the numbers and method.
The report downloads as a dated PDF: concrete evidence of the state of your controls on a specific date. Continuous monitoring (free for one domain) documents the rest automatically — daily checks, history, and an alert if your configuration degrades. The same evidence serves a vendor security questionnaire or a cyber-insurance application.
Worth knowing: Cyberbilan is not a Qualified Security Assessor (QSA) and this test does not make your business PCI DSS compliant. It checks the public state of your email and web controls — a concrete, verifiable piece of the puzzle, not the whole standard.
Since March 31, 2025. It was one of the PCI DSS v4.0 “future-dated” requirements; on that date v4.0.1 became the only active version and all of those requirements became applicable at every assessment.
Not literally. The requirement mandates automated anti-phishing mechanisms and names DMARC, SPF and DKIM as example anti-spoofing controls. In practice it is the cheapest, simplest and most verifiable answer for the “nobody can impersonate you” side.
No. The requirement explicitly talks about processes and automated mechanisms: staff awareness is necessary but does not replace technical controls.
Yes, as soon as you handle card data. Which requirements you must attest to depends on the self-assessment questionnaire your payment provider asks for — confirm with them which one applies to your business.
No. We are not a Qualified Security Assessor (QSA) and compliance covers far more than email. This test freely checks the state of your publicly verifiable controls and gives you a dated report to keep.