Retail
Overview
Email is a necessary aspect of doing business in the retail industry. Hundreds of thousands of retail firms around the world use email for internal and external interactions every day. However, because emails are so widely used, it becomes a tempting target for cybercriminals intending to steal money, data, or both. While all organizations are vulnerable to fraud and data theft, the retail industry is particularly more vulnerable. In fact, shops are the target of 24% of the attacks, costing more than $30 billion every year.
A high-profile cybercrime, particularly one involving Personally Identifiable Information (PII) and financial data, can erode trust nurtured among a retailer’s customers over time. According to a survey in the United States, 22% of customers will stop doing business with a company that has been hacked, and two-thirds will lose trust in a company after a breach. The retail business sector ranks dead last among key industries in terms of DMARC email authentication adoption and enforcement. As a result, their email system is open to impersonation assaults.
Retailers communicate with their consumers on a regular basis, particularly via emails, which increases the risk of phishing and spoofing. Sensitive customer data like email addresses, phone numbers, and credit card numbers are commonly stored in retail databases. Naturally, the retail industry is vulnerable to more attacks and security breaches than any other industry.
Phishing/social engineering is the most common method of compromise, according to Trustwave’s 2020 Global Security Report, accounting for 50% of all cyber attacks. Malicious insiders, the second most popular approach, was used in only 11% of attacks.This highlights the urgent need for merchants to strengthen their email security, as it is by far their most vulnerable area.

Retail Sector DMARC Adoption
As per a survey conducted across 1500 organizations and 3,033 domains, around 56.6% of the organizations have implemented SPF, 12.2% have implemented DMARC, 11.3% have implemented both, and the rest 19.9% of these organizations have not implemented either. The policy-wise breakdown is:
None Policy – The None (Monitor) policy is used by 12.1% of the domains.This policy detects but does not prevent authentication abuse.
Quarantine Policy – The Quarantine policy, which forwards emails that fail authentication to the defined spam folder, was applied by about 2.3%.
Reject Policy – Reject policies have been implemented by 1.3% to prohibit messages that fail authentication. This is the ideal state because it prevents attackers from impersonating a brand.The rest 84.2% of the organizations haven’t implemented any policy. Refer to the graphs showing the adoption statistics for other components.

Retail Sector DMARC Adoption (Source: 250ok report)






How Can EmailAuth Help?
Apart from giving companies and organizations guaranteed security and complete control of their email domains through DMARC’s implementation, EmaiAuth has many other advantages. You can read more about them here.
EmailAuth provides a free DMARC Record Checker to display your record, test it, and verify that it is valid. All you need to perform a DMARC check is to provide your domain name. The tool will then analyze and display your DMARC record along with other information on your domain’s activities. Similarly, you can also verify your DKIM and SPF records using EmailAuth’s free and automated tools: DKIM record checker and SPF record checker.
In case you don’t have a DMARC record published for your domain, you can use EmailAuth’s DMARC Record Generator to generate a record instantly.