PCI DSS 4.0 section 5.4.1: anti-phishing controls are now mandatory
if your organization processes card payments, this applies to you
DMARC at enforcement is the most direct technical control you can implement to prevent domain spoofing
https://dmarcguard.io/learn/pci-dss/
#DMARC #EmailSecurity