PCI DSS DMARC Requirement: What Section 5.4.1 Requires

https://dmarcguard.io/blog/pci-dss/

Comments

john_strinlaiJul 24, 2026, 3:29 PM
this article takes more time to read than dmarc takes to implement
CodesInChaosJul 24, 2026, 4:27 PM
> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.

Sounds silly to me. A PAN should never even touch an employee's computer.

dogma1138Jul 24, 2026, 4:34 PM
There are cases for card not present transactions, fraud and complex refunds but generally yes.
yonatan8070Jul 24, 2026, 8:44 PM
Took me too long to realize this has nothing to do with the Peripheral Component Interconnect or Direct Memory Access
tptacekJul 24, 2026, 4:51 PM
Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.
fragmedeJul 24, 2026, 8:14 PM
two words: compensating control.

(But also setup dmarc)