Posts tagged: compliance
PCI DSS DMARC Requirement: What 5.4.1 Actually Says
PCI DSS v4.0.1 Section 5.4.1 mandates anti-phishing controls — and names DMARC, SPF, and DKIM as examples, not requirements. See what your auditors expect.
DORA Compliance for Email: Map DMARC to Art. 9-11
DORA compliance for email, mapped to Articles 9, 10 and 11. How DMARC, SPF, MTA-STS and TLS-RPT meet the regulation's data-in-transit duties.
Does HIPAA Require DMARC? §164.312 Email Auth Mapping [2026]
Does HIPAA require DMARC? Not by name. How §164.312 technical safeguards map to DMARC, SPF, DKIM, MTA-STS, TLS-RPT — plus the Dec 2024 NPRM.
NIS2 Email Security: Article 21 → DMARC, MTA-STS, DANE
NIS2 compliance: map Article 21(2) to email auth — DMARC, SPF, MTA-STS, DANE, TLS-RPT. The control map, copy-paste DNS checks, and a 2026 readiness plan.
DMARC for MSPs: The Independent Operator's Guide (2026)
Vendor-neutral DMARC guide for MSPs: real wholesale pricing, multi-tenant ops, PSA integrations, 2026 compliance pressure, and ROI math — without the partner-program pitch.
Microsoft DMARC: Office 365 Setup Guide 2026
Microsoft enforces DMARC for Outlook senders since May 5, 2025. Set up DMARC for Office 365 and Microsoft 365 step-by-step with DNS examples. Configure now.
Google, Yahoo & Microsoft DMARC Requirements
Google, Yahoo, and Microsoft now require DMARC for bulk senders — including Gmail's 2025 SMTP rejection escalation. See the full compliance checklist.