Home / Study
How bad Italian e-commerce really is
We measured 1,263 Italian online shop domains and analysed 89 sites page by page. No estimates, no bought sample: automated checks on public data, repeatable by anyone. Here is what came out.
| Survey date | 7 September 2026 |
| Domains analysed for email | 1,263 |
| Sites analysed for accessibility | 89 of 105 |
| Tools | axe-core 4.13, DNS lookups |
| Rules | WCAG 2.2 AA, SPF, DKIM, DMARC, MTA-STS |
| Companies named | none |
The two numbers that matter
84.2%
of the shops measured can be impersonated by email. Anyone can send their customers a fake invoice that arrives with their domain in the sender, and no server stops it.
1 in 89
is how many sites pass an accessibility check without a single error. The other 88 carry between 1 and 1,509 non-compliant elements.
How we measured them
Method matters more than result, because without method the result is worth nothing. Ours is published in full.
| When | 7 September 2026 |
| What | Italian e-commerce domains collected from public directories of online shops. |
| Public DNS lookups of SPF, DKIM, DMARC and MTA-STS records. Nothing sent, no access attempted. | |
| Accessibility | axe-core on WCAG 2.2 level AA rules, 3 to 5 public pages per site, one page per second, declared user agent. |
| What we did not do | No access to restricted areas, no bypassing of protections, no collection of visitors’ personal data. |
| Stated limits | Of 105 sites started, 16 blocked automated analysis and are excluded from the counts rather than estimated. Automated checks find roughly a third of accessibility problems: the figures below are a floor, not a total. DKIM is detected by trying the most common selectors, so a domain with an unusual selector may show as having none when it does. |
| Names | No company is named, here or anywhere else. The data stays aggregated. |
Email: 84.2% of domains can be forged
DMARC is the record that tells mail servers what to do when an email claims your domain but does not come from you. Without it, or with the policy set to none, the answer is: deliver it anyway.
| Policy | Domains | What it means | Result |
|---|---|---|---|
| No DMARC record | 245 19.4% | Anyone can write in the domain name | FAIL |
| DMARC p=none | 818 64.8% | The record exists but asks to block nothing | FAIL |
| DMARC p=quarantine | 124 9.8% | Forged mail goes to spam | TO MEASURE |
| DMARC p=reject | 76 6% | Forged mail is rejected | PASS |
The mean score across the three records is 52 out of 100. Three more numbers saying the same thing from other angles: 116 domains (9.2%) have no SPF at all, 546 (43.2%) have no detectable DKIM signature, and 828 out of 1,263 close their SPF with ~all, which means "flag it but deliver" rather than "reject".
There is a commercial effect too. Google and Yahoo since February 2024, and Microsoft since May 2025, require authentication from bulk senders and treat unauthenticated mail with suspicion. These shops’ order confirmations and newsletters land in spam without anyone telling them.
Want to know how yours is doing? Check it now, in seconds, or do it yourself with the five-minute guide.
Accessibility: 9,214 non-compliant elements across 89 sites
A mean of 104 per site and 36 per page, median 69. The median sitting below the mean says the problem is not concentrated in a few extreme cases: it is widespread, and a few sites take it to an extreme.
Errors per site
| Non-compliant elements | Sites |
|---|---|
| 0 | 1 1.1% |
| 1-10 | 8 9% |
| 11-50 | 26 29.2% |
| 51-100 | 18 20.2% |
| 101-500 | 35 39.3% |
| over 500 | 1 1.1% |
By platform
| Platform | Sites | Mean errors |
|---|---|---|
| Magento | 58 | 102 |
| Shopify | 21 | 89 |
| WooCommerce | 4 | 133 |
| PrestaShop | 3 | 148 |
Numbers too small to claim one platform beats another. They say the theme and the customisations matter more than the platform.
The five most frequent causes
| Rule | Sites where it is the top cause | What it means |
|---|---|---|
color-contrast | 45 50.6% | Text or controls with insufficient contrast |
target-size | 11 12.4% | Touch targets too small or too close together |
link-name | 8 9% | Links with no readable name |
image-alt | 5 5.6% | Images with no text alternative |
listitem | 3 3.4% | Badly built lists |
Insufficient contrast is the leading cause on one site in two. It is also the cheapest defect to fix, because it usually comes down to a handful of colour values in a stylesheet.
One last figure worth reading twice: 43 sites out of 89 (48.3%) publish an accessibility statement. Almost half declare themselves accessible, and exactly one is, according to automated checks.
What a proper statement must say, and how to check before writing it: the guide.
Why now
European directive 2019/882, implemented in Italy by legislative decree 82/2022, has applied since 28 June 2025 to services sold to consumers, e-commerce included. Fines run from 5,000 to 40,000 euro. Microenterprises are exempt, meaning under 10 staff and under 2 million in turnover. Since 11 March 2026 the Italian agency AgID has run a public platform where anyone can report an inaccessible site.
Plainly: until recently the risk was theoretical because there was no easy way to report. Now there is, and one unhappy customer is enough.
How your own site is doing
The same check we ran on these 1,263 domains we run on yours and send you the result, free and with no commitment. We buy no lists and write to nobody who has not asked: the measurement starts when you ask for it.
Ask for your site’s measurement
This study names no company and is not legal advice. The aggregate data may be quoted freely with attribution.