Buyer’s guide · United Kingdom

How to Choose a DMARC Platform for a UK MSP Portfolio

This page ranks nothing and names no vendor. A league table published by a vendor is an advertisement with numbers on it, and you already know what would be at position one.

What follows is what to weigh when the thing you are buying runs across a book of client domains: what separates products, what to ask in a demo, which claims should stop the conversation.

The wrong question

Nothing is best. Something fits the shape you run.

Every serious product receives aggregate reports and shows a pass rate. That is the floor, which is why feature grids here all look alike. The gap opens somewhere less photogenic: how the work feels on the sixtieth domain, when a client’s invoices stop arriving.

So change the question. Not which is best, but which is built for a business your shape. Three UK providers buy quite differently.

group

Fifteen clients, one interested engineer

The constraint is attention, so what matters is how much the product does unprompted. A tool needing a trained operator gets abandoned by month four, and the domains sit at p=none indefinitely.

workspaces

Sixty clients and a delivery team

The constraint is delegation. Several people touch one book, so access scoping and an audit trail stop being nice-to-haves, and bulk operations become a requirement: manual work is done sixty times.

gavel

A book with regulated clients in it

One council or NHS supplier changes the criteria for the whole portfolio. Residency, sub-processors and certifications become gating questions, and you inherit whatever your vendor puts in writing.

The criteria that matter

Eight things that decide whether you still like the choice in year two.

None of these show up in a tidy fortnight trial. All show up later, roughly in the order below — which is how often each is the reason a provider switches.

01

Multi-tenancy that is actually multi-tenant

Is a client a real tenant, or a label on one shared list? The test is specific: give a junior engineer one client and nothing else, then hand that client to a colleague without exposing the book.

02

What it does with reports, not that it accepts them

Reports arrive daily, in volume, in a format written for machines, and everyone ingests them. The differentiator is the output: sources named as services rather than address ranges, forwarding noise separated from real failure, a new sender arriving as an alert.

03

The fix, or just the failure

A red bar beside a sender tells you what you had already guessed. The value is the next sentence: which include is missing, which selector needs a signing domain belonging to the client. Judge it on a messy domain; on a clean one everything looks clever.

04

Output you can send without rewriting it

Anything needing translation before it leaves your building is unbillable time every month. On white-labelling, ask exactly which elements are configurable, because some vendors mean a logo upload: colours, sending address, portal address, footer, and whether their name survives.

05

Adding a domain — and giving one back

Onboarding gets asked about in every demo. Offboarding almost never does, though you will do it under pressure. Walk the exit first: repointing the reporting address away, removing any delegation record the platform asked you to publish, exporting the sender inventory.

06

Residency, sub-processors and certifications

Aggregate reports are metadata, not message content, but they describe how a client’s mail moves. Regulated and public sector clients will ask where it lives, who processes it and what the vendor is certified against. Get it in writing, and read any G-Cloud listing.

07

Who answers when a client’s mail breaks

Nearly all the risk sits at one moment, and it is the moment policy moves. Ask what happens when payroll notifications fail at four on a Friday: which channel, which hours, and whether the person you reach understands alignment or reads a script.

08

Whether you can get your data out

Ask for an export during the trial, not a promise of one: inventory, policy history and report data, in a format something else reads. Historic findings rarely survive a migration, so switching costs a fresh monitoring window.

The currency test

Does their own documentation still teach a percentage ramp?

DMARCbis was published in May 2026 — RFC 9989 for the core protocol, obsoleting RFC 7489, with RFC 9990 and RFC 9991 for reporting. The pct= tag was removed.

Rollout is now p=none to p=quarantine to p=reject, all or nothing at each step. So search a vendor’s guides for a staged percentage rollout. If the advice still walks a domain from 25% to 50% to 100%, nobody has reviewed it since the specification changed.

The commercial side

Three questions the feature grid will never answer.

A platform people regret is usually one whose commercial shape did not survive the portfolio churning. The UK pricing page takes the models apart; these three go to the salesperson.

speed

What is the meter attached to?

Per domain, per seat, or per message. DMARC is published and reported per domain, so anything else opens a gap between what you operate and what you are billed for. Per seat charges least for large, well-resourced clients and most per unit of risk for the twelve-person conveyancer.

trending_down

Which way does it move with scale?

Ask whether the per-unit price falls as domains are added, and where the next threshold sits. A price improving with volume matches the work, since the fortieth domain takes less effort than the fourth. Spot early any model where growth pushes you into a quote cycle.

logout

What does leaving cost?

Not the technical handover in criterion five, but the paperwork: notice period, whether domains can be removed mid-term when a client leaves you, whether an export is chargeable, what happens to stored data. Portfolios churn both ways, and a contract assuming only growth costs more than it looks.

The demo checklist

Twelve questions to put to any vendor, in writing.

Deliberately specific, because a specific question gets either a specific answer or a vague one, and both tell you something. Ask us these too.

checklist Print this, or paste it into the email
Tenancy Show me a user who sees exactly one client and nothing else. Is there an audit trail of who viewed what?
Tenancy A client wants a read-only login. Possible, at what cost, and what can they see of my other clients?
Report quality Open a domain with five or more third-party senders. How many are named as services rather than addresses?
Report quality How do you tell forwarding and mailing-list failures apart from real misconfiguration? Show me one of each.
Remediation Pick a failing sender in front of me. What exactly do you tell me to change, and where?
Remediation What tells me a domain is ready to move up a policy level, and what evidence sits behind it?
Client output Send me last month’s report for a real domain, branded as my client would receive it. Not a template.
Client output List every white-label element I can configure, and everywhere your name still appears, including the sending address.
Assurance Where is report data processed and stored, who are the sub-processors, and what are you certified against? In writing.
Support A client at enforcement has mail failing now. Who picks it up, when, and have they configured DMARC?
Exit Walk me through offboarding a client, including every record I remove from their DNS. Then export that domain.
Currency Describe your recommended rollout. If a percentage ramp appears, ask when that guidance was last reviewed.

draft In writing, not on a call

Anything you would repeat to a client belongs in an email. You may have to forward it to a procurement team, and a remembered answer is not evidence.

groups_2 Bring the daily operator

If the engineer who reads the reports weekly is not in the demo, nobody in the room has to live with the answer.

Claims to distrust

Five things said in this market that are not true.

Each is checkable, each is wrong, and each ends with you repeating it to an assessor who can look it up.

block

“DMARC is required for Cyber Essentials”

It is not, and it is not hidden inside another control. The current version — v3.3, April 2026, effective 27 April 2026, administered by IASME — has five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.

verified_user

“NCSC-approved” or “the official Mail Check replacement”

Neither exists. The NCSC does not endorse individual DMARC products, and there is no official successor to Mail Check, retired on 31 March 2026. It published a vendor-neutral buyer’s guide naming no vendors.

account_balance

“The FCA requires DMARC”

It does not. DMARC is not named in the FCA Handbook, and it is not named in PS21/3. Operational resilience expectations are real and worth taking seriously, but they do not name this control — and a client can confirm that quickly.

gpp_maybe

“100% protection” or “stops all phishing”

DMARC does one thing well: it stops mail forging the exact domain. It does nothing about a compromised mailbox, where the attacker sends as a real user and authenticates properly, and nothing about a lookalike domain registered last week, which never claimed to be yours.

percent

“Start at 10%, then 50%, then 100%”

Sound advice for years, now out of date. RFC 9989 removed the tag that made a percentage rollout possible, so policy applies to all mail or none. A vendor still teaching the old ramp is not lying, but is working from stale material — and sender-inventory quality is the only safety mechanism left.

Running the evaluation

Treat it as procurement, not a product tour.

Four steps, in this order. The order is what people skip, and skipping it is how a shortlist gets decided by whichever interface looked nicest.

Step 1

Write the requirement before you look at anything

One page: domains today and in two years, how many people need access, what the messiest client looks like, what regulated clients demand. Written first, that is a specification. Written afterwards, it describes a demo.

Step 2

Trial on the client you least want to touch

The one with the marketing platform, the booking system, the payroll provider and a domain someone set up in 2014. Every product handles a simple estate; the awkward client is where differences show.

Step 3

Score the work removed, not the features listed

Time an engineer on one task in each candidate: an unknown sender, from first appearance to a written recommendation you would send a client. Minutes on a stopwatch beat a comparison table.

Step 4

Model the whole book, over the term you will sign

Not the pilot. Take the real client list, count every domain including parked and legacy ones, and run each model across all of it. Models that look alike on one domain diverge across a book.

Agree one more thing first: who signs it off, and on what evidence. An evaluation with no decision rule runs until the incumbent contract renews by default.

balance

Our own position, stated plainly

We make DMARC AI, a DMARC monitoring platform. This guide is written by an interested party and you should read it that way. We have not put ourselves at the top of a table on our own website, and we have named nobody else, because a vendor ranking is advertising.

The criteria above are the ones we would want a buyer to apply, including where they lead elsewhere. If your book suits per-seat pricing, or you need one supplier covering DMARC, MTA-STS and BIMI, or someone can put a certification in writing today that we cannot, buy from them.

What we say about ourselves is narrow and checkable. Pricing is per domain, from £1 per domain per month, volume-based so the per-domain price falls as you add domains. There is a free trial and no free tier. Everything else, test rather than take from us.

Common questions

Questions UK MSPs ask us.

Which is the best DMARC platform for a UK MSP? add

There is no answer to that question that is worth reading, and certainly not one published by a vendor. Products in this market all ingest aggregate reports and all show a pass rate, so the ranking anybody writes reflects what they wanted to sell rather than what you need to run.

The question that does have an answer is narrower: which platform fits the shape of your business. A provider with fifteen clients and one interested engineer needs a product that does more unprompted. A provider with sixty clients and a delivery team needs access scoping, bulk operations and an API. A provider with a council or an NHS supplier on the book needs residency and certification answers in writing before anything else matters.

Decide which of those you are first, then evaluate against it.

What separates DMARC platforms, if they all parse the same reports? add

Ingestion is the floor. Aggregate reports arrive daily, in volume, in a format written for machines, and every serious product accepts them. Nothing is differentiated there.

The gap opens on what comes out. Whether a sending source is named as a recognisable service or shown as an address range. Whether forwarding and mailing-list noise is separated from genuine authentication failure. Whether a source that appeared yesterday reaches you as an alert or waits to be found. And, above all, whether the product tells you the fix or only shows you the failure.

Test that on a genuinely messy client domain rather than a clean one. On a tidy estate every product looks equally capable.

Why does per-seat pricing suit an MSP portfolio badly? add

Because it meters something DMARC has nothing to do with. DMARC is published, evaluated and reported per domain, so a domain with 400 mailboxes and a domain with 12 generate the same record, the same sender inventory and broadly the same work.

Under per-seat pricing those two clients cost wildly different amounts, which distorts your cost of goods in an unhelpful direction. It charges you least for the large, well-resourced clients and most per unit of risk for the small ones — the twelve-person conveyancing firm or insurance broker, where a spoofed invoice does the most damage of anything on your book.

Whichever model you buy under, ask which way the price moves as the portfolio grows. A per-unit price that falls with volume matches how the work behaves; one that rises does not.

How do I check whether a vendor is current with DMARCbis? add

Search their own documentation for a staged percentage rollout. DMARCbis was published in May 2026 as RFC 9989 for the core protocol, obsoleting RFC 7489, with RFC 9990 for aggregate reporting and RFC 9991 for failure reporting. The pct= tag was removed.

Rollout is now p=none, then p=quarantine, then p=reject, and each step applies to all mail or none of it. So if a vendor guide still walks a domain up from 25% to 50% to 100%, that material has not been reviewed since the specification changed.

It is a cheap and checkable proxy. It costs you five minutes and it tells you something about how current the rest of their advice is.

Is any DMARC product NCSC-approved, or an official Mail Check replacement? add

No, and any vendor claiming either is misrepresenting the position. The NCSC does not endorse individual DMARC products, and there is no official successor to Mail Check, which was retired along with Web Check on 31 March 2026 after running since 2017.

What the NCSC did publish was a vendor-neutral buyer's guide for external attack surface management tools. It names no vendors and leaves the choice to the buyer. Early Warning and DNS Check continue via MyNCSC, and the free Email Security Check remains — but that is an on-demand lookup and does not ingest aggregate reports, so it does not replace what Mail Check provided.

DMARC AI has no affiliation with the NCSC and is not approved, endorsed or certified by it.

Do UK rules require DMARC, and can a vendor claim otherwise? add

Be careful with anyone who says yes without qualification. Cyber Essentials contains no DMARC, SPF or DKIM control: the current requirements, v3.3, published April 2026 and effective from 27 April 2026 under IASME, cover firewalls, secure configuration, security update management, user access control and malware protection. DMARC is not among them. The FCA Handbook does not name DMARC either, and neither does PS21/3.

Where an expectation genuinely exists is public sector email. GOV.UK guidance on securing government email, updated 4 March 2024, states that public sector organisations must support DMARC and have DMARC, DKIM and SPF records in place.

The other real pressure is commercial rather than regulatory. Since 1 February 2024, senders pushing 5,000 or more messages a day to personal Gmail accounts have needed SPF, DKIM and DMARC at minimum p=none, a spam rate under 0.3% and one-click unsubscribe on marketing mail, with Gmail escalating enforcement from November 2025.

What should I ask about offboarding before I sign anything? add

Ask a vendor to walk the exit with you during the evaluation, because you will do it under time pressure and nobody asks about it in a demo. There are three parts.

The technical handover: repointing the rua= address away from the platform, and removing any delegation record the vendor asked you to publish in the client's DNS. The data: whether you can export the sender inventory, the policy history and the underlying report data in a format something else can read, and whether that export is included or chargeable. The contract: notice period, whether domains can be removed mid-term when a client leaves you, and what happens to stored data after termination.

One thing to plan for whoever you choose: historic findings rarely survive a migration intact, so a platform change usually costs a fresh monitoring window before you can safely make enforcement decisions again.

Put us through your own checklist.

Start a free trial, point your most awkward client domain at DMARC AI, and work down the twelve questions above. Pricing is per domain, from £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.