Benchmarks / UK online retailers
UK online retailers
Two mandates land on the same page. PCI DSS 4.0 requires every script on a payment page to be inventoried and watched for change, and accessibility law is being litigated hardest against online retail. Both are checkable from outside, which means a complainant can check them too.
can be impersonated by email.
36 of 113 online retailers have no enforced DMARC policy, so a criminal can send mail that appears to come from them. Across 113 domains scanned.
Overall113 domains scanned
Can this sector be spoofed?
DMARC is the record that lets the world reject forged mail. Only an enforced policy (quarantine or reject) actually stops impersonation; p=none only watches.
- Enforced (p=reject) 42.5%
- Enforced (p=quarantine) 25.7%
- Monitor only (p=none) 30.1%
- No DMARC at all 1.8%
What we found, most common first
- 35.4%do not enforce HTTPS (no HSTS)40 of 113
A visitor’s first request can be downgraded to plain HTTP and intercepted.
- 31.9%can be impersonated by email36 of 113
No enforced DMARC policy, so a criminal can send mail that appears to come from them. This is the root of invoice and payment-redirection fraud.
- 30.1%have no domain transfer lock34 of 113
Without it, anyone into the registrar account can move the domain away.
- 12.4%expose a sensitive file or tool14 of 113
A .env file, .git directory, database tool or status page is reachable from the internet.
- 2.7%have a certificate expiring within 30 days3 of 113
An expired certificate shows every visitor a full-page browser warning.
Common across the internetcontext, not a sector failing
- 96.5%have DNSSEC switched off109 of 113
DNS answers are unsigned. DNSSEC remains rare across the whole web, so this is context rather than a sector-specific failing.
- 85.8%have no CAA record97 of 113
Any certificate authority may issue a certificate for the domain. CAA adoption is low across the internet generally, not just here.
- 45.1%run third-party scripts on the page51 of 113
Common everywhere. It only becomes a PCI DSS 4.0 obligation on pages that take card details, where each script must be inventoried and watched.
Weakest categories
- 31.9%Email authenticationgraded D or worse
- 2.7%Payment securitygraded D or worse
- 0.9%Domain and registrationgraded D or worse
- 0.9%Content and SEOgraded D or worse
- 0.9%Performancegraded D or worse
How we measure this
Independent retailers drawn from UK shopping directories. We run the same public checks we run for customers, entirely from the public internet, with nothing installed anywhere. We publish sector averages only: no organisation is named, linked or individually reported, and we do not publish findings about any specific business. This sample leans towards larger and better-resourced organisations, so the real figure across the whole sector is likely to be worse, not better.
See how you compare.
Free, no signup, about a minute.