Benchmarks / UK online retailers

UK online retailers

Two mandates land on the same page. PCI DSS 4.0 requires every script on a payment page to be inventoried and watched for change, and accessibility law is being litigated hardest against online retail. Both are checkable from outside, which means a complainant can check them too.

31.9%

can be impersonated by email.

36 of 113 online retailers have no enforced DMARC policy, so a criminal can send mail that appears to come from them. Across 113 domains scanned.

Overall113 domains scanned

36.3%
graded D or worse overall
2.2
real faults per domain, on average
Grade spread

Can this sector be spoofed?

DMARC is the record that lets the world reject forged mail. Only an enforced policy (quarantine or reject) actually stops impersonation; p=none only watches.

  • Enforced (p=reject) 42.5%
  • Enforced (p=quarantine) 25.7%
  • Monitor only (p=none) 30.1%
  • No DMARC at all 1.8%

What we found, most common first

Common across the internetcontext, not a sector failing

Weakest categories

How we measure this

Independent retailers drawn from UK shopping directories. We run the same public checks we run for customers, entirely from the public internet, with nothing installed anywhere. We publish sector averages only: no organisation is named, linked or individually reported, and we do not publish findings about any specific business. This sample leans towards larger and better-resourced organisations, so the real figure across the whole sector is likely to be worse, not better.

See how you compare.

Free, no signup, about a minute.