UK MSP DMARC Adoption Report
More than half of UK managed service providers have not protected their own email domain. Across 8,724 UK MSP domains, 52.5% either publish no DMARC record at all or sit at a monitoring policy that instructs receivers to do nothing.
To be clear about what this measures: these are the providers' own domains — the ones on their letterhead and in their engineers' signatures — not the client estates they manage. It is the cobbler's-children problem, quantified.
This is the first edition of a recurring dataset drawn from our own domain-enrichment sweep. We publish it because we have not seen the UK MSP segment measured on its own terms. Most DMARC adoption research counts large brands or top-N domain lists; nobody seems to have asked how the channel that sells email security is doing at securing itself.
Data as at . Sample: 8,724 live domains belonging to UK managed service providers. Aggregate figures only — no individual domain, provider or organisation is identified.
What the UK MSP domain base actually looks like.
Effectively unprotected
4,584 provider domains publish no DMARC record, or one that tells receivers to take no action.
Reached enforcement
4,140 domains sit at quarantine or reject — the only policies that stop a forged message.
Collect no reports
3,768 domains have no aggregate reporting address, so nobody sees who is sending as them.
Run on Microsoft 365
Of provider domains receiving mail, 4,989 route it through Microsoft 365 — a strikingly concentrated channel.
Publishing a record is not the same as being protected.
74.6% of UK MSP domains publish a DMARC record, which sounds like a healthy number until you look at what those records say.
The largest single group is not reject, and not even quarantine. It is p=none — a record that collects data and blocks nothing. Combine it with the domains carrying no record at all and the majority of the base is spoofable today.
52.5% of these providers — 4,584 firms — can be impersonated without the receiver being told to stop it.
The UK is not ahead. It is not behind either.
The UK ran a free, government-backed DMARC reporting service from 2017 until it was withdrawn on 31 March 2026. It would be reasonable to expect that to show up as a UK adoption premium among technically capable firms. It does not.
Every headline measure lands within roughly one percentage point of the same sweep run without a country filter. UK providers are neither better nor worse at protecting their own domains than providers anywhere else.
The likeliest explanation is scope. Mail Check was aimed at public sector organisations, and MSPs are private companies who were never its intended audience. A free national service does not lift a segment it was not built for — which is worth remembering before assuming any future government scheme will close this particular gap.
Comparison baseline: the same nightly sweep across 39,534 managed domains in all countries, including the UK subset. Differences are in percentage points.
Two in five UK domains are flying blind.
A DMARC record without a reporting address still applies a policy, but nobody ever finds out which senders it affected. That matters most at the moment of escalation: without report history, moving a domain to enforcement is a guess about which legitimate senders are about to break.
No reporting at all
3,768 domains collect nothing. Any policy they carry was set without evidence and is maintained without feedback.
Self-collected
2,011 domains send reports to an address on their own domain — often a mailbox nobody has opened in months.
Sent to a platform
2,945 domains route reports to a third-party processor that parses the XML into something readable.
We have deliberately not published a breakdown of which reporting platforms hold which share. The useful finding for an MSP is the posture split above, not a vendor league table.
A Microsoft estate with a gateway problem.
UK providers are more Microsoft-concentrated than the global base: 59.4% of UK provider domains receiving mail do so through Microsoft 365, against 55.7% across all countries.
That concentration cuts both ways. It means one well-documented DKIM setup covers most of the channel — and it means a single misconfiguration pattern repeats across thousands of providers. The complication sits in the next layer down.
Microsoft 365
59.4%4,989 domains. Against 55.7% globally — the UK skews Microsoft.
Google Workspace
8.2%689 domains. Lower than the 9.6% global share.
Third-party security gateways
at least 15.8%Around 1,324 provider domains point their MX at a filtering gateway ahead of the mailbox. Stated as a minimum because the provider list is truncated at the top 20.
alt_route Why the gateway layer matters for DMARC
A gateway sitting in front of Microsoft 365 changes what the mailbox sees. Inbound mail arrives from the gateway rather than the original sender, which is why DMARC results recorded at the mailbox can disagree with what the sending domain's own reports show — and why a domain can appear to be enforcing while impersonation still reaches inboxes.
One UK-specific detail stands out: the most common gateway in this sample appears at roughly 2.3 times its global share. UK providers carry proportionally more of this architecture than the worldwide base, so the interaction is worth understanding before enforcing a policy — on your own domain or a client's. We cover the mechanics in why DMARC fails with a gateway in front of Microsoft 365.
Two global platforms, then a distinctly British long tail.
DMARC is a DNS change, so whoever holds the zone holds the work. Cloudflare and GoDaddy between them account for 43.1% of UK MSP domains with resolved nameservers — but below them sits a set of UK-domiciled hosts that barely register in the global figures.
Share of the 8,506 UK provider domains with resolved nameservers. Providers are brand-normalised from the first authoritative nameserver. Bar length is relative to the largest provider, not to 100%.
Three UK-domiciled providers — livedns.co.uk, StackDNS and phase8.net — hold roughly four times the share here that they hold globally. If you are building a rollout runbook for UK work, those control panels are worth knowing as well as the two large platforms, because a DMARC record that cannot be published is a rollout that stops on day one.
Four things an MSP can act on this quarter.
home_work Start with your own domain
On these numbers there is a coin-flip chance your own domain is one of the unprotected ones. It takes a single lookup to find out. A provider whose own domain sits at p=none is a provider who cannot honestly sell enforcement to a client — and one whose invoices can be forged.
visibility_off Records without reporting are the quiet failure
More providers carry a policy than carry a reporting address. Those domains look compliant on a checklist and cannot be safely escalated, because nobody knows which legitimate senders would break. Fixing reporting is cheaper than fixing an outage — and it is the same diagnosis you would give a client.
hub Templating pays off faster in the UK
With 59.4% of UK providers on one mail platform, the runbook you write to fix your own domain is very likely the same one that fixes most of your clients. Doing your own first is not a detour — it is building the template.
schedule The free safety net is gone
Whatever visibility UK organisations had from the retired NCSC service, they no longer have. For clients who relied on it, the gap is now yours to fill — and it is a reason to open the conversation. See the Mail Check replacement page.
How these numbers were produced — and what they are not.
We would rather publish the limitations than have someone else find them. This is a real sample with a real bias, and reading it as "the UK" would be wrong.
badge What counts as an MSP here
Every company in this sample was checked against its own published company information and confirmed to be providing managed IT services to other organisations. This is a verified classification rather than a self-selected label or a guess from an industry code.
That definition is deliberately practical rather than narrow. It covers any firm delivering managed IT to other businesses — which includes smaller IT support practices and firms whose managed services sit alongside other work, not only large providers with a formal MSP badge. If you compare 8,724 against published UK MSP market-size estimates, expect this figure to be higher: most of those estimates count a tighter category than the one measured here.
The sample
8,724 live domains belonging to those UK providers — the providers' own company domains, not the client estates they administer. Scoped by the company's registered country. Figures are aggregate; no domain, provider or organisation is identified, and none will be in future editions.
How it was measured
A nightly sweep resolves each domain's nameservers, MX records and DMARC TXT record at _dmarc. Policy is read from the published record. Providers are brand-normalised from the first authoritative nameserver and the primary MX host.
The bias you should assume
These are technically capable IT businesses — firms that configure DNS for a living. If anything they should be better protected than UK companies generally, which is what makes the result notable rather than reassuring. Do not read it as a proxy for UK business at large: it is a specific, self-selecting population, and citing it as "UK companies" would be wrong.
What we left out
Provider tables are truncated to the largest entries, so long-tail shares are understated and the gateway figure is a minimum. We have not published the reporting-platform market shares that the same sweep produces.
Citing this report
Journalists and researchers are welcome to quote these figures with attribution to the UK MSP DMARC Adoption Report, August 2026 edition, DMARC AI, linking to this page. Please carry the sample description with the number — 8,724 UK managed service providers' own domains — so it is not mistaken for a survey of UK businesses generally, or for the client estates those providers manage.
We intend to refresh this dataset on a recurring basis so the trend becomes visible. Where a future edition contradicts this one, the newer figures stand and the change will be noted rather than quietly corrected.
The rest of the UK cluster.
By sector
Questions UK MSPs ask us.
Where does this data come from? add
A nightly domain-enrichment sweep, scoped to accounts registered in the United Kingdom. For the August 2026 edition that is 8,724 live UK managed service provider domains.
An important clarification, because it changes what the numbers mean: these are the providers' own company domains, not the client estates they administer. The report measures how well UK MSPs have secured themselves.
The sweep resolves each domain's nameservers, MX records and DMARC TXT record and records what is published. Everything is aggregate — no individual domain, provider or organisation is identified.
How did you decide which companies count as MSPs? add
Each company was checked against its own published company information and confirmed to be providing managed IT services to other organisations. It is a verified classification, not a self-selected label and not an inference from an industry classification code.
The definition is practical rather than narrow: it covers any firm delivering managed IT to other businesses, including smaller IT support practices and firms whose managed services sit alongside other work. It is not limited to large providers carrying a formal MSP badge.
That is worth knowing if you are comparing the sample size against published UK MSP market-size estimates, which usually count a tighter category and therefore produce smaller numbers.
Is this a representative sample of UK businesses? add
No. It is a sample of one specific population: UK managed service providers, measured on their own domains.
If anything that population should score better than UK businesses generally, because these are firms that configure DNS professionally. That is what makes 52.5% unprotected a notable result rather than a reassuring one. Do not cite it as "UK companies" or as a picture of the client estates these providers manage — it is neither.
Why is "publishing DMARC" not the same as being protected? add
A DMARC record carries a policy telling receivers what to do with mail that fails authentication. The policy p=none tells them to do nothing — it collects reporting data while allowing forged mail through exactly as before.
In this sample 74.6% of provider domains publish a record, but 27.2% sit at that monitoring-only policy. Add the 25.4% with no record at all and the majority of UK providers have no working protection on their own domain, despite the headline adoption number looking respectable.
Why does the UK not do better, given it had a free government service? add
That was the finding we least expected. Every headline measure sits within about one percentage point of the same sweep run globally.
The most plausible explanation is scope rather than indifference. The NCSC Mail Check service, retired on 31 March 2026, was built for public sector organisations. MSPs are private companies and were never its intended audience, so its presence — or its withdrawal — does not show up as a UK premium among them.
Why is there no breakdown of which DMARC platforms are being used? add
The same sweep does produce reporting-platform shares, and we have chosen not to publish them. A vendor league table on a vendor's own website is marketing rather than research, whichever way the numbers fall.
The posture split is the part a provider can act on: 43.2% collect no aggregate reports at all, 23.1% send them to an address on their own domain, and 33.8% route them to a platform that parses them. Which platform matters far less than whether anyone is reading the output.
How often will this be updated? add
The intention is a recurring refresh so the trend becomes visible over time — a single snapshot tells you the state of things, but the direction of travel is the more useful number.
Where a later edition contradicts this one, the newer figures stand and we will note the change rather than quietly editing the old ones.
Can we cite these figures? add
Yes, with attribution to the UK MSP DMARC Adoption Report, August 2026 edition, DMARC AI, and a link to this page.
Please carry the sample description alongside the number — 8,724 UK managed service providers' own domains — so readers do not mistake it for a survey of UK businesses in general, or for the client estates those providers manage. If you need a figure that is not on the page, ask and we will tell you whether the sweep can answer it.
Check your own domain before a client checks it for you.
Check your own domain first, then the client estates you manage. The platform shows the same policy and reporting breakdown for any portfolio you point at it. Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.