Security Architecture Overview: stripe.com
Stripe operates global economic infrastructure for the internet. Stripe protects billing receipts, invoice links, and merchant communications with strict DMARC enforcement.
Key Anti-Spoofing & Cryptographic Highlights
Frequently Asked Questions
Is Stripe's email infrastructure secure?
Yes, Stripe employs financial-grade SPF, DKIM, and DMARC reject policies on all merchant notifications.
Why does stripe.com's SPF include Mailgun?
Stripe uses Mailgun as part of its transactional email infrastructure for developer-facing alerts, webhook failure notifications, and API key emails. Mailgun is whitelisted in Stripe's SPF record to ensure DMARC alignment for these mail streams.
What is TLS Preload HSTS and why does Stripe use it?
HTTP Strict Transport Security (HSTS) preloading means stripe.com is hard-coded into browsers' HTTPS-only lists. Even on a user's first visit, the browser refuses to connect over plain HTTP. This eliminates SSL stripping attacks targeting payment pages.
What does a fake Stripe phishing email typically look like?
Common Stripe phishing emails mimic payout failed, account suspended, or new login detected notifications. They link to lookalike pages at domains like stripe-support.com or payments-stripe.com. These domains pass their own SPF/DKIM checks but are not stripe.com.
How do I verify a Stripe webhook or email is authentic?
For webhooks, use the Stripe-Signature header and your endpoint's secret key to verify HMAC-SHA256 integrity. For emails, use IncogSay's Email Header Analyzer to confirm SPF and DKIM pass with d=stripe.com alignment.
What SSL certificate authority does stripe.com use?
Stripe.com uses DigiCert Global Root G2-issued OV (Organization Validated) certificates. DigiCert's G2 root is pre-trusted in all modern browsers and provides 2048-bit RSA or ECC P-256 key material.