Skip to content
← Blog

DMARC for e-commerce: deliverability and trust on the same line

By Thomas · virtual CISO · 2026-08-10

For an online merchant, the sending domain carries two stakes that weigh directly on revenue. On one side, deliverability: every order confirmation, shipping notice or receipt that lands in spam is friction, a support ticket, sometimes a lost sale. On the other, trust: online shops are among the most spoofed brands, and a fake delivery or invoice email in a store's name erodes the customer relationship it spent years building. The good news is that DMARC serves both goals at once. This article explains why email authentication is a double-return investment for e-commerce, and how to implement it.

Spoofing a shop is a business of its own

Phishing campaigns love merchant brands, for a simple reason: everyone expects emails from shops. A fake parcel notice demanding a customs fee to release a held delivery, or an order-problem alert asking for bank details, blends into an online shopper's normal flow. The attacker does not even need to aim well: by spoofing a large brand, a fraction of recipients will actually have an order in progress, which is enough to make the trap credible.

That spoofing exploits the exact same technical mechanism as any address forgery — described in protecting against email spoofing. As long as the domain stays at p=none, nothing stops a receiving server from accepting a message that displays the shop's sender address. And every customer phished in a brand's name associates, rightly or wrongly, a bad experience with that brand.

Deliverability is a revenue question

Transactional email is the lifeblood of the e-commerce relationship: it is how the customer tracks their order, gets their invoice, resets their password. And the major mailbox providers have tightened their rules. The Gmail and Yahoo sender requirements now make DMARC a prerequisite for anyone sending in volume — which every active merchant does. Without correct authentication, legitimate messages risk the spam folder, or outright rejection.

The link is direct: better authentication means a better sender reputation, hence a better inbox placement. When transactional emails or campaigns land in junk too often despite SPF and DKIM, the diagnosis runs through the same levers, detailed in emails going to spam despite SPF and DKIM and in the Gmail deliverability guide.

DMARC serves both at once

Here lies the elegance of the control for e-commerce: the same work answers both stakes. Cleanly aligning every sending source and driving the domain to p=reject blocks spoofing and sends mailbox providers a seriousness signal that improves legitimate deliverability. There is no choice to make between protecting the brand and getting the emails through: both arrive with the same well-run DNS publication.

A merchant's sending estate is broader than it looks

The difficulty specific to e-commerce is the multiplicity of sources. A typical merchant sends from:

  • the e-commerce platform itself (confirmations, customer accounts);
  • an emailing provider for marketing campaigns;
  • a separate transactional service for receipts and notifications;
  • carriers and logistics solutions that notify on the shop's behalf;
  • review, support and loyalty-programme platforms.

Each must be identified and aligned, otherwise moving to p=reject would break legitimate email. This is why the first step is never to tighten the policy, but to observe through the aggregate reports to map the full real estate — almost always broader than the marketing team imagined.

The verified logo as a conversion asset

There is a specifically commercial benefit to going all the way. Reaching p=reject unlocks BIMI, which displays a verified logo next to the shop's messages in supporting inboxes. For a merchant brand, whose whole relationship rests on recognition and trust, that logo is a conversion asset: it makes legitimate mail instantly identifiable and makes a logo-less counterfeit look visibly suspect. The full reasoning, transferable as-is to e-commerce, is developed for financial brands in DMARC for banks — but the branding stake is, for a merchant, even more direct.

That benefit is not theoretical for a merchant: in an inbox saturated with commercial solicitations, the verified logo is a visual anchor that distinguishes the authentic message from the noise — and from the counterfeit. It acts as a legitimacy cue at the precise moment the customer decides to open, click, buy. Few levers offer such brand-recognition effect for so marginal a cost once DMARC enforcement is reached. That is why it is worth aiming for BIMI from the programme's design, even if activation comes last, after the alignment work.

A worked example: the fake delivery email

The great classic of merchant spoofing deserves breaking down, so effective is it. An attacker spoofs the domain of a brand stuck at p=none and mass-sends a fake parcel notice demanding a delivery fee to release the package, displaying the shop's authentic address. Statistically, a share of recipients really do have an order in progress — the message lands just right, vigilance drops, and the fraudulent payment goes out.

For the shop, the damage is twofold: wronged customers who associate the scam with its brand, and a flood of support complaints it must field, explaining, embarrassed, that it is not at fault. The same message, domain at p=reject, never reaches the inboxes: it is rejected at delivery. The difference between suffering this campaign and ignoring it hangs on a single policy shift — from observation to enforcement.

Marketing and transactional: two flows not to mix

A best practice specific to e-commerce is worth knowing early: the marketing and transactional flows belong on distinct subdomains — say a subdomain dedicated to campaigns, another to receipts and notifications. The benefit is twofold. First, sender reputation: an incident on marketing campaigns (complaints, unsubscribes) does not taint the critical deliverability of transactional emails on which order tracking depends. Second, clarity of alignment: each subdomain has its clearly identified sources, which simplifies the march to p=reject and the subdomain-policy setting.

It is an architectural investment that pays over time, by isolating the flow that weighs most on revenue — the transactional — from the vagaries of mass marketing.

Marketplaces and third-party senders

Many merchants also sell via marketplaces or rely on partners that send in their name. Those third-party senders are a tricky alignment source: their SPF and DKIM configuration is rarely under the merchant's control, and yet their messages claim to come from the brand. The rule is to inventory them explicitly during the observation phase, check what they allow in terms of alignment, and handle case by case those that cannot align cleanly — even moving them to send from their own domain rather than the shop's. Leaving an unaligned third party in the wild is the most frequent cause of a move to reject that "breaks email".

Measuring what it earns

Unlike many security controls whose benefit is invisible, email authentication produces measurable signals for a merchant. On deliverability, the inbox-placement rate of transactional emails is trackable after alignment, as is the drop in "I never got my confirmation" complaints. On brand, the aggregate reports show in black and white the volume of spoofed messages that were trying to pass in the shop's name — an often eloquent figure that materialises the risk just closed. These indicators turn a technical project into a result presentable to management, and justify the alignment effort well beyond the compliance argument alone. For a merchant, this is the rare security investment that shows up in the numbers a founder actually watches — inbox placement, support volume, and blocked impersonation — rather than in an abstract risk register nobody reads.

Peak season raises the stakes

There is a timing dimension merchants should not miss. Spoofing campaigns spike around the periods when shoppers expect the most email — sales, holidays, major shopping days — precisely when a fake delivery-problem notice or a payment-failure alert blends in best. Those are also the weeks when legitimate transactional volume peaks, so a deliverability dip costs the most. Reaching p=reject well before a peak, not during it, means entering the busiest window with both protections firing: fraud in the shop's name blocked, and its own confirmations landing in the inbox. The worst time to start the alignment work is the week orders surge — so authentication belongs to pre-season infrastructure, not to a fire drill run when complaints are already coming in.

The roadmap

  1. Diagnosing the domain with a free DMARC analyzer to establish the starting point.
  2. Publishing DMARC at p=none and collecting reports to identify every sending source.
  3. Aligning every source on SPF and DKIM — platform, ESP, transactional, carriers, reviews.
  4. Ramping policy to quarantine then reject, watching the reports at each step (the method).
  5. Planning BIMI as the final reward, once enforcement is reached.

Checking a shop's domain

The first step costs nothing. The domain customers receive their confirmations from, run through our free DMARC analyzer, returns an instant verdict, and the sector's posture is there to compare in the DMARC Observatory. Other high-volume, high-trust sectors share the same risk profile, such as healthcare.

Mapping a sprawling merchant sending estate and bringing it to p=reject without breaking a single order email is exactly what Thomas, the virtual CISO, automates: he names every sending source, generates the DNS to publish, assesses readiness and says when enforcement is safe. Analyze a domain for free · explore the Observatory · get started with Thomas.

Enforcing DMARC, in practice

Thomas, the virtual CISO of DMARC.com, identifies every legitimate sending source, writes the exact DNS records, and takes a domain from p=none to p=reject — without breaking its mail.

Get to p=reject — free

Related guides

About the author

ThomasThomas is the virtual CISO of DMARC.com: a copilot specialized in email authentication that walks organizations from p=none to p=reject without breaking their mail. His guides draw on real data from the DMARC Observatory and the RUA reports the platform analyzes.