DMARC, SPF, DKIM: the email security test most e-commerce stores fail

In short: your store's security doesn't stop at your website. Without properly configured SPF and DMARC, anyone can send emails in your name — fake order confirmations, fake delivery notices, phishing. Our first scans show that a significant share of stores have no DMARC at all. The check takes 30 seconds.

The scenario nobody imagines

A customer receives an email: "Your order #4821 is awaiting payment — click here to complete it." Your store's logo is on it, the sender address looks like yours. The customer clicks, enters their card details, and their money is gone.

Your website wasn't hacked. Your brand was impersonated: the attacker simply sent emails pretending to be you, because your domain had no mechanism allowing mailboxes to verify its identity.

The three mechanisms, simply explained

Three DNS records protect your email domain. They don't protect your server — they protect your customers from emails sent in your name.

Why it's critical for e-commerce

Your store already sends emails to your customers: order confirmations, invoices, shipping updates. Your customers expect to receive emails from your brand — which is exactly what makes impersonation so effective. A customer who has already received a real email from your store is more likely to fall for a fake one.

The consequences: defrauded customers, destroyed reputation, your legitimate emails landing in spam (your real orders end up in the junk folder), and degraded deliverability that craters your open rates.

Check your domain in 30 seconds

Our free audit now checks SPF, DMARC and DKIM in addition to the usual checks (versions, exposure, HTTPS, cookies). Enter your store's address below: the results appear in the report.

Check your store now

Passive audit, no modification of your site. Score /100 in 30 seconds.

How to fix it, in order

  1. SPF: add a TXT record v=spf1 include:_spf.yourhost.com -all (or the includes from your email tools: Brevo, Gmail, OVH...). Always end with -all.
  2. DKIM: enable signing in your sending tool (Brevo, Gmail, OVH) and publish the public key it gives you in your DNS.
  3. DMARC: publish v=DMARC1; p=quarantine; rua=mailto:you@yourmail.com, monitor the reports for a few weeks, then move to p=reject.

If your store is affected, the PrestaShield module (€29.90) includes this check in its full audit, and we can also intervene to configure everything for you.

Sources: RFC 7208 (SPF), RFC 7489 (DMARC), Brevo and Google Postmaster deliverability recommendations. Statistics from our audit scans (August 2026).