wiredepth
Run a check

Which retail brands can be spoofed in email?

Retail brands are the second-most-impersonated category after finance, driven by 'your order was placed', 'your delivery failed', and 'your refund is processing' scams. Grocery chains and big-box stores have generally caught up; mid-tier brands and international retailers lag.

Spoofable

4 (20%)

No DMARC, or DMARC at p=none. Anyone can send from these domains.

Partial protection

1 (5%)

DMARC at p=quarantine, or p=reject with pct<100. Spoofed mail may slip through.

Not practically spoofable

15 (75%)

DMARC p=reject pct=100 + SPF -all or DKIM. Spoofed mail rejected at SMTP.

BrandDomainVerdict
Aldialdi.comSpoofableSee the math →
Carrefourcarrefour.comSpoofableSee the math →
Lidllidl.comSpoofableSee the math →
Trader Joe'straderjoes.comSpoofableSee the math →
Wayfairwayfair.comMaybeSee the math →
Best Buybestbuy.comProtectedSee the math →
Costcocostco.comProtectedSee the math →
Etsyetsy.comProtectedSee the math →
Home Depothomedepot.comProtectedSee the math →
IKEAikea.comProtectedSee the math →
Lowe'slowes.comProtectedSee the math →
Macy'smacys.comProtectedSee the math →
Nordstromnordstrom.comProtectedSee the math →
Sainsbury'ssainsburys.co.ukProtectedSee the math →
Sephorasephora.comProtectedSee the math →
Shopifyshopify.comProtectedSee the math →
Targettarget.comProtectedSee the math →
Tescotesco.comProtectedSee the math →
Walmartwalmart.comProtectedSee the math →
eBayebay.comProtectedSee the math →

Other categories

What does "spoofable" actually mean?

A domain is spoofable when a third party can send mail FROM addresses at that domain (e.g. [email protected]) and have it land in inboxes. The mechanism that prevents this is DMARC enforcement combined with SPF and DKIM. Without all three, receivers have no policy to apply against unauthorised senders.

Want the same check on your own domain? Run the free Spoofability check.

This category last scored: .