United Kingdom

DMARC for UK MSPs

The UK spent years with a free, government-run DMARC reporting service. That ended on 31 March 2026, when the NCSC retired Mail Check and Web Check. Thousands of UK domains — public sector, charity, and every SME sitting behind an MSP — lost their aggregate report parsing at the same time that Google and Microsoft started rejecting mail from domains that cannot authenticate.

This is the UK overview: what actually changed, what UK rules do and do not require, and how to run DMARC across a portfolio of .co.uk clients as a service line rather than a stream of one-off projects.

What changed in 2026

The free UK safety net came down in the same year enforcement got stricter.

Two things moved in opposite directions. The tooling that gave UK organisations free visibility into their own email authentication was withdrawn, and the receivers that decide whether your clients' mail lands in an inbox tightened their requirements. An MSP portfolio feels both changes at once, because it feels them across every client at once.

None of this is a reason to panic. It is a reason to move DMARC from "something we set up once when a client asked" to a monitored, reported, recurring line of work — which is what most UK MSPs were quietly heading towards anyway.

power_settings_new

Mail Check was retired

The NCSC retired Mail Check and Web Check on 31 March 2026, having announced the change on 6 November 2025. Users no longer receive findings. The stated reasoning was that the external attack surface management market had matured; the NCSC published a vendor-neutral buyer's guide and directed organisations to commercial products. Early Warning and DNS Check continue via MyNCSC.

mark_email_read

Receivers stopped being polite

Google's bulk sender requirements have been in force since 1 February 2024: senders pushing 5,000+ messages a day to personal Gmail accounts must have SPF, DKIM and DMARC (minimum p=none), keep spam complaints under 0.3%, and offer one-click unsubscribe on marketing mail. From November 2025 Gmail ramped up enforcement with temporary and then permanent rejections. Microsoft has introduced comparable requirements for high-volume senders.

rule

DMARCbis changed the rollout

DMARCbis was published in May 2026 as RFC 9989 (core, obsoleting RFC 7489), RFC 9990 (aggregate reporting) and RFC 9991 (failure reporting). The pct= tag was removed, so enforcement is all-or-nothing at each level. The rollout is p=nonep=quarantinep=reject, and the quality of your sender inventory is now the only thing standing between a client and a broken mail flow.

The compliance picture

What UK rules actually require — and what they don't.

There is a lot of loose selling around DMARC and UK compliance. It is worth being precise, because an MSP that overstates the position in a proposal has to walk it back in front of an assessor later.

Public sector: yes, it is required

GOV.UK's Securing government email guidance (updated 4 March 2024) states that public sector organisations must support DMARC and must have DMARC, DKIM and SPF records in place. This is guidance published under the Government Cyber Security Policy rather than text written into GovS 007, so describe it accurately: it is a policy expectation for public sector email, not a statute.

Cyber Essentials: no, it is not a control

Cyber Essentials does not require DMARC, SPF or DKIM. The current requirements — v3.3, published April 2026 and effective from 27 April 2026, administered by IASME — cover five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. Email authentication is not among them. DMARC is worth doing on its own merits; selling it as a Cyber Essentials requirement is simply wrong.

Private sector: the market requires it

No UK law compels a business to publish a DMARC record. The pressure comes from the receivers instead, and it is more immediate than regulation: a client whose invoices stop reaching Gmail recipients will call you the same week. Increasingly the pressure also comes from procurement, where a supplier questionnaire asks about anti-spoofing controls and a blank answer costs the contract.

Why this lands on UK MSPs

The work did not disappear. It moved to whoever holds the DNS.

Read the deeper practice guide on running DMARC as a managed service, then come back for the UK specifics.

A UK SME with 30 mailboxes was never going to parse aggregate report XML itself. While Mail Check existed, a certain number of those organisations got a usable answer for free, and their MSP could reasonably treat DMARC as out of scope. That option has gone. The organisations still need the visibility, and the only party with the DNS credentials, the Microsoft 365 tenant access and the relationship is the MSP.

The portfolio shape is what makes it awkward with general-purpose tooling. A typical UK MSP is not managing one domain — it is managing a legal firm on .co.uk, a multi-academy trust on a mixture of .sch.uk and .org.uk, a manufacturer with three legacy brand domains nobody sends from any more, and a charity that discovered a fundraising platform sends on its behalf. Each one needs its own record, its own inventory and its own report the client can put in front of a board.

There is also a timing advantage. Mail Check's retirement is a legitimate reason to open a conversation with every existing client — not a manufactured urgency, just a service that used to be free and no longer exists. MSPs who ran that conversation in the first half of 2026 found it converted far better than a cold security upsell, because the client had usually already received the NCSC notification.

What the platform does

Aggregate reports in, decisions out.

DMARC AI collects the aggregate reports receivers send back, parses them, and turns them into a sender inventory, a pass rate and a recommendation. The portfolio is the primary object rather than an afterthought, which is the part that matters when you are managing sixty clients rather than one. The UK MSP platform page covers the multi-tenant architecture and the service-line economics in full.

dashboard

Multi-tenant by design

Every client domain in one view, with per-tenant separation so you can hand a colleague a single client without exposing the rest of the book.

travel_explore

Sender discovery

Every source sending as the domain, named and classified — including the marketing platform and the payroll provider nobody mentioned during onboarding.

troubleshoot

Automated analysis

Alignment failures explained in terms of the fix — the missing SPF include, the DKIM selector that needs a custom signing domain — rather than raw XML.

description

Client-ready reporting

Output designed to be sent to a client, not rewritten by an engineer first. That is the difference between a monthly report and three hours of unbillable work.

payments

Pricing you can quote on the first call

Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains. There is no free tier — a free trial only, which we would rather say plainly than advertise a free plan that stops being useful at the point you need it. Full detail on the UK pricing page.

handyman

Free checkers alongside the platform

Point-in-time lookups for the protocols DMARC depends on: DMARC validator, SPF analyzer, DKIM validator and MTA-STS check. Useful for a prospect audit; not a substitute for continuous monitoring.

To be explicit, because the question comes up on every public sector deal: DMARC AI is not NCSC-approved, endorsed or certified. The NCSC does not endorse individual DMARC products — it published a vendor-neutral buyer's guide and left the choice to the buyer. Anyone claiming an NCSC endorsement is misrepresenting the position.

UK domain specifics

Why .co.uk trips people up.

DMARC works on any DNS zone, and a .co.uk domain behaves like any other once you have the organisational-domain boundary right. That boundary is the thing UK portfolios get wrong.

.co.uk is a public suffix. The organisational domain for example.co.uk is therefore example.co.uk — not co.uk. The same applies to .org.uk, .ac.uk, .gov.uk and .sch.uk.

Two consequences follow. First, the DMARC record for example.co.uk lives at _dmarc.example.co.uk, and there is no higher-level record that can cover a whole UK second-level suffix. Every client domain needs its own record; there is no shortcut for a portfolio.

Second, relaxed alignment is evaluated against that organisational domain. Mail sent from mail.example.co.uk can align in relaxed mode with a DKIM signature or envelope sender on example.co.uk. Mail from example-mail.co.uk — a separate registration a marketing agency set up years ago — will not align, no matter how similar it looks to a human. UK clients accumulate these lookalike registrations, and every one is a separate domain requiring its own DMARC record and its own decision.

Subdomain policy is worth checking at the same time. If a client has delegated a subdomain to a third party, the organisational domain's policy applies unless a subdomain policy says otherwise — which is exactly how a forgotten campaign subdomain ends up quarantined the week after you move the parent to enforcement.

Where to start

Three steps, in this order.

Sequence matters more than speed. Since DMARCbis removed pct=, there is no partial enforcement to hide behind — each policy step is all-or-nothing, so the sender inventory has to be right before you take it.

Step 1

Audit the book

Run every client domain through a DMARC lookup and sort them into three piles: no record at all, a record stuck at p=none, and a record at enforcement. Add the legacy brand domains and any that still point rua= at a retired Mail Check address. The pile sizes tell you what the service line is worth before you build it.

Step 2

Point the reports somewhere useful

Publish p=none with a reporting address on the platform for every domain in the portfolio. Reports usually begin arriving within 24 to 48 hours, because most large receivers send on a daily cycle. Give it two to four weeks before you draw conclusions — a monthly biller or an annual mailing will not show up in the first week.

Step 3

Escalate one domain at a time

Fix alignment for every legitimate sender, then move to p=quarantine, then p=reject once the pass rate has been stable across several reporting cycles. Keep a rollback window of one business day at each step and put the change in the client's change calendar so the service desk routes the tickets correctly.

Migrating from Mail Check specifically? The mechanical step is small — repoint rua= and confirm reports arrive — but historic findings do not transfer, so plan a fresh monitoring window. The Mail Check replacement page covers the migration in full.

Common questions

Questions UK MSPs ask us.

Is DMARC a legal requirement in the UK? add

Not for private-sector organisations. There is no UK law compelling a business to publish a DMARC record.

For UK public sector email domains it is a policy requirement: GOV.UK's "Securing government email" guidance states that public sector organisations must support DMARC, and must have DMARC, DKIM and SPF records in place to make spoofing difficult.

Commercially, the bigger driver for most UK businesses is inbox access rather than regulation — Google requires bulk senders to publish a DMARC policy, so domains without one increasingly see delivery problems regardless of sector.

Does Cyber Essentials require DMARC? add

No. We checked the current Cyber Essentials requirements document (v3.3, April 2026, effective 27 April 2026) and it contains no DMARC, SPF or DKIM control. The five technical controls are firewalls, secure configuration, security update management, user access control and malware protection.

Be sceptical of any vendor that tells you otherwise. DMARC is worth doing on its own merits — it just is not a Cyber Essentials control, and claiming it is will not survive contact with an assessor.

What happened to NCSC Mail Check? add

The NCSC retired Mail Check and Web Check on 31 March 2026, having announced the change in November 2025. Users no longer receive findings from those services.

The NCSC pointed organisations towards commercial products and published a buyer's guide for external attack surface management tools. Its free Email Security Check remains available as an on-demand lookup, but it does not process the aggregate reports that tell you who is actually sending as your domain.

Do you support .co.uk, .org.uk and .ac.uk domains? add

Yes. DMARC operates on any DNS zone, and the platform treats a .co.uk, .org.uk, .gov.uk or .ac.uk domain exactly as it treats any other.

One UK-specific detail does matter: organisational-domain boundaries. Because .co.uk is a public suffix, the organisational domain for example.co.uk is example.co.uk rather than co.uk. That affects relaxed alignment and where a DMARC record has to sit, and it is a common source of confusion on UK portfolios.

How quickly will we see results? add

Aggregate reports typically begin arriving within 24 to 48 hours of publishing a record with a reporting address, because most large receivers send on a daily cycle.

A realistic full rollout runs longer. Expect two to four weeks at p=none to build a reliable sender inventory, then a move to p=quarantine, then p=reject once the pass rate is stable. Portfolios with many third-party senders take longer than portfolios that only send from Microsoft 365.

Start with one UK client domain.

Add a domain, point the aggregate reports at DMARC AI, and see real sender data inside 48 hours. Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.