A customer receives an email: "Your order #4821 is awaiting payment — click here to complete it." Your store's logo is on it, the sender address looks like yours. The customer clicks, enters their card details, and their money is gone.
Your website wasn't hacked. Your brand was impersonated: the attacker simply sent emails pretending to be you, because your domain had no mechanism allowing mailboxes to verify its identity.
Three DNS records protect your email domain. They don't protect your server — they protect your customers from emails sent in your name.
v=spf1 ... -all record says "only this server may send mail in my name."none (do nothing), quarantine (send to spam), reject (refuse). Without DMARC, mailboxes don't know how to handle impersonated emails — most let them through.Your store already sends emails to your customers: order confirmations, invoices, shipping updates. Your customers expect to receive emails from your brand — which is exactly what makes impersonation so effective. A customer who has already received a real email from your store is more likely to fall for a fake one.
The consequences: defrauded customers, destroyed reputation, your legitimate emails landing in spam (your real orders end up in the junk folder), and degraded deliverability that craters your open rates.
Our free audit now checks SPF, DMARC and DKIM in addition to the usual checks (versions, exposure, HTTPS, cookies). Enter your store's address below: the results appear in the report.
Passive audit, no modification of your site. Score /100 in 30 seconds.
v=spf1 include:_spf.yourhost.com -all (or the includes from your email tools: Brevo, Gmail, OVH...). Always end with -all.v=DMARC1; p=quarantine; rua=mailto:you@yourmail.com, monitor the reports for a few weeks, then move to p=reject.If your store is affected, the PrestaShield module (€29.90) includes this check in its full audit, and we can also intervene to configure everything for you.
Sources: RFC 7208 (SPF), RFC 7489 (DMARC), Brevo and Google Postmaster deliverability recommendations. Statistics from our audit scans (August 2026).