Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
PCI DSS DMARC Requirement: What Section 5.4.1 Requires (dmarcguard.io)
12 points by meysamazad 17 hours ago | hide | past | favorite | 6 comments
 help



this article takes more time to read than dmarc takes to implement

Took me too long to realize this has nothing to do with the Peripheral Component Interconnect or Direct Memory Access

> The best practice is a policy banning PAN over email, instant messaging, SMS, and chat entirely.

Sounds silly to me. A PAN should never even touch an employee's computer.


There are cases for card not present transactions, fraud and complex refunds but generally yes.

Kind of a weird post, since it acknowledges in the first 1/3rd that you don't need DMARC for PCI compliance.

two words: compensating control.

(But also setup dmarc)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: