Security Architecture Overview: amazon.com
Amazon.com is one of the most spoofed brands in transactional email scams. Amazon deploys strict DMARC p=reject and native Amazon Trust Services (ATS) PKI infrastructure to eliminate unauthorized order receipt spoofing.
Key Anti-Spoofing & Cryptographic Highlights
Frequently Asked Questions
What is Amazon's DMARC policy?
Amazon.com enforces "v=DMARC1; p=reject", instructing inbox providers to drop any spoofed message claiming to be from @amazon.com.
How do I verify an Amazon order confirmation email?
Check the sender address and authentication headers in IncogSay's Email Header Analyzer to ensure SPF and DKIM pass with d=amazon.com.
What is Amazon Trust Services (ATS)?
Amazon Trust Services is Amazon's in-house Certificate Authority, launched in 2016. ATS issues SSL/TLS certificates used across amazon.com, AWS services, and Amazon's global CDN (CloudFront). ATS roots are trusted by all major browsers.
What SPF record does amazon.com use?
Amazon.com's root domain uses include:amazon.com with -all hardfail termination. However, Amazon SES (Simple Email Service) uses separate subdomain SPF records for transactional emails sent on behalf of third-party senders.
How do fake Amazon delivery notification scams work?
Attackers register lookalike domains (amazon-delivery.com, amaz0n.com) and configure their own SPF/DKIM to pass checks on those domains. They then send phishing emails that display Amazon's branding. The sender domain passes authentication, but it is not amazon.com — always check the exact From: domain.
Does amazon.com use DMARC reporting (rua)?
Yes. Amazon.com's DMARC record includes rua=mailto:dmarc-reports@amazon.com, collecting aggregate XML reports from all receiving mail servers to monitor unauthenticated mail claiming to originate from @amazon.com.