PCI DSS DMARC Requirement: What Section 5.4.1 Actually Requires
PCI DSS DMARC Requirement: What Section 5.4.1 Requires
PCI DSS v4.0.1 mandates automated anti-phishing mechanisms under Requirement 5.4.1 but does not explicitly require DMARC. While DMARC, SPF, and DKIM are cited as recommended examples in the guidance, the standard allows for alternative controls. Auditors expect to see these protocols in practice, yet the binding text focuses on the outcome of protection rather than a specific technology. Understanding this distinction is crucial for passing assessments without falling for vendor overstatements.
So does PCI DSS require DMARC? Not by name. In practice, it is the control your assessor expects you to point to.