Schools, colleges, MATs and their IT providers

DMARC for UK Schools, Colleges and Academy Trusts

The Department for Education asks schools to check that their email cannot be used to send imitation messages, and points them at a free NCSC tool. That tool was switched off on 31 March 2026. The standard still links to it.

That gap is where most school and trust email security currently sits: a real expectation, a method that no longer works, and nobody obliged to notice. This page sets out what the standard says, what it does not say, and how to close the gap without breaking a term's worth of parent communications.

What the DfE standard says

Under fifteen words, and no protocol named.

The text sits in the cyber security core standard within the DfE's digital and technology standards for schools and colleges, first published on 23 March 2022 and last updated on 24 June 2026. It is shorter than people expect.

description

The sentence itself

The core standard asks schools to "check that your email is setup to be secure and that it reduces the risk of third parties being able to send imitation emails". It appears twice, and each time it links out to the NCSC rather than naming a control of its own.

search_off

What is not in it

The words DMARC, SPF and DKIM do not appear anywhere in the standard. Any supplier telling a school the DfE requires DMARC is overstating it — a claim a business manager can check in thirty seconds. We would rather be the ones who told you.

schedule

The status of it

These are core standards the DfE says schools should be meeting now. That is an expectation rather than a statute. It is also exactly the kind of thing that gets asked about after an incident rather than before.

alt_route One thing this is not

The DfE also publishes a filtering and monitoring standard, and the two get conflated because both mention safety and both mention IT. They are unrelated. Filtering and monitoring concerns what pupils can reach on the web. Email authentication concerns whether an outsider can send a message that appears to come from the school. Meeting one says nothing about the other.

The broken link

The standard points at a tool that no longer exists.

Follow the standard literally and you arrive at NCSC Mail Check, the free service that collected DMARC aggregate reports and turned them into findings a school could act on. An IT lead doing exactly what the guidance asks now finds nothing waiting for them.

power_settings_new

What happened

  • removeThe NCSC retired Mail Check and Web Check on 31 March 2026, announced on 6 November 2025 after the services had run since 2017.
  • removeUsers no longer receive findings, and historic findings do not transfer, so a new baseline starts from today.
  • removeThe NCSC pointed organisations at commercial products through a vendor-neutral external attack surface management buyer's guide, which names no vendors.
  • check_circleEarly Warning and DNS Check continue via MyNCSC, and the free Email Security Check remains — an on-demand lookup that does not ingest aggregate reports.
school

Colleges have one extra thread

Cyber Essentials is a requirement for colleges under their funding agreement, which makes it a genuine contractual obligation rather than an expectation. So is the other half of it.

Cyber Essentials contains no DMARC, SPF or DKIM control. The v3.3 requirements published in April 2026 cover five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. So a college can hold a current certification and still have a domain anyone can send as. Both statements are true at once, and a proposal leaning on either alone is misleading.

Stated plainly: DMARC AI has no affiliation with the Department for Education or the NCSC, and is not approved, endorsed, accredited or assured by either. Neither endorses individual DMARC products, and there is no official successor to Mail Check. The Mail Check replacement page covers the migration mechanics.

Why the domain is worth stealing

A school address is trusted by design.

Parents are conditioned to act on messages from the school, and to act quickly, because most carry a deadline. Suppliers treat a school address as authoritative for the same reason. That trust is the asset, and unlike a password it cannot be reset.

Shape one

Finance office impersonation

A message appearing to come from the business manager, the head or the trust finance team, asking for a payment to be released or bank details updated. It works because the sender looks internal and the request looks routine.

Shape two

Parent payment requests

Trip balances, uniform, music tuition, catering top-ups. Schools genuinely send these, so a forged one does not look unusual, and the payment window is short enough that a parent is unlikely to ring the office first.

Shape three

Supplier redirection

The same technique aimed outwards: a forged message from the school to a contractor, changing where an invoice should be paid. The school finds out when the real supplier chases the money. A dormant predecessor domain works just as well for this as the live one.

Two things to keep straight. DMARC governs mail claiming to be your domain — it is not a filter on what arrives in staff or pupil mailboxes, and it is not a safeguarding control. Nor does it stop an attacker registering a similar-looking name. What it closes off are your real ones, which parents are most likely to believe.

The multi-academy trust problem

A trust rarely chose its domains. It inherited them.

Single schools usually have a manageable estate. Trusts have an archaeological one, assembled through conversions and joinings, spread across several suffixes, with the older layers registered by people who left years ago. The first step is counting, and the number is always higher than expected.

account_tree What a trust estate typically contains
The trust name Usually the only one anybody manages. Central mail, finance and HR run from it, so it gets the attention and often already has a record.
Each school One per academy, often on a different suffix from its neighbours, and still the address printed on letters, signage and the parent app.
Predecessor names Kept alive so old addresses keep working. Nothing legitimate sends from them, which makes them both the easiest to secure and the easiest to forget.
Side ventures A sixth form, a nursery, a teaching school hub, a lettings arm, a fundraising site. Each is its own name and its own forgotten DNS zone.
Held by others Names still registered to a previous IT provider, a web agency or a former business manager's personal account. Find these before the renewal date.

These are public suffixes, so the organisational domain is the label directly below them. A record on one name never covers another, however closely related the schools are.

  • .sch.uk
  • .ac.uk
  • .org.uk
  • .co.uk

block No trust-wide shortcut

There is no record you can publish once that protects every school in the trust. Each domain needs its own, so the effort scales with domain count rather than pupil numbers — and a small trust with a long history can be more work than a large modern one.

key Find out who holds the DNS

In schools this stalls projects far more often than the technical work does. Establish before you start whether the trust, the local authority, the MIS supplier or a web agency can actually edit each zone, and how long a change takes.

forward_to_inbox A trust is often a bulk sender

Google's bulk sender requirements have applied since 1 February 2024 to anyone sending 5,000 or more messages a day to personal Gmail accounts: SPF, DKIM and DMARC at a minimum monitoring policy, spam complaints under 0.3%, and one-click unsubscribe on marketing mail. A trust-wide newsletter reaches that easily. Gmail escalated enforcement from November 2025, and Microsoft has comparable requirements for high-volume senders.

A rollout that fits the year

Plan it around term dates, not sprint dates.

Schools have the most predictable calendar of any sector, which is an advantage if you use it. The observation work wants term time, when every system is sending. The one risky step wants a holiday.

Before term

Count the domains

Registrar exports, DNS zones, old letterheads, anything a predecessor school used. Sort into three piles: sends mail and should, sends mail and should not, should never send at all. The third pile is usually the largest, and it can go straight to an enforcing policy with a null MX record.

First weeks of term

Publish monitoring and watch

Put a monitoring policy and a working reporting address on every sending domain. Do it in term time deliberately: admissions, the MIS, the parent messaging app, payments, catering and trips are all active, so the inventory is the real one rather than the August one.

Across the term

Fix alignment, sender by sender

Reports name every source sending as each domain. Work through them: the missing SPF include for the payments provider, the DKIM selector the parent messaging platform needs so it signs as the school rather than as itself. Allow a half-term — an annual mailing will not appear in the first fortnight.

A holiday

Escalate, with somebody contactable

Move one domain at a time, with a named approver and a rollback window. Avoid the week before an admissions deadline, results day or the first week of term. If a sender was missed, a holiday makes that an inconvenience rather than a queue of parents who never received something.

One protocol change makes the sequencing matter more than it used to. DMARCbis, published in May 2026 as RFC 9989, removed the percentage tag, so a policy now applies to all of a domain's mail or none of it. The old habit of easing enforcement in on a fraction of messages is gone, and the term's inventory is now the only thing standing between a trust and a broken parent mailing.

For the IT provider

Serving several schools or trusts at once.

Education providers hold a lot of domains for relatively small contract values — exactly the shape that makes per-project DMARC work uneconomic and a portfolio service line sensible.

hub

Domains, not seats

A trust with a dozen academies can carry several times that many names once predecessors and side ventures are counted. Scope and price the work per domain, because that is where the effort sits.

groups

One calendar, many clients

Every school holidays at roughly the same time. Batch observation into term time and enforcement into the breaks, and the year plans itself.

summarize

Reporting a governor can read

The output has to survive a governors' meeting without an engineer present to translate it. That, rather than the protocol work, makes the service line renewable.

Start with one trust, or one school

Add the domains, point the aggregate reports somewhere that parses them, and you have a real inventory within a couple of days — including the predecessor names nobody had thought about since conversion. That inventory is usually what gets the rest of the work funded.

Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains. There is no free tier, only a free trial — which we would rather say plainly than advertise a free plan that stops being useful.

Related sectors: councils and public bodies, where a maintained school's IT often sits, NHS and healthcare, the one sector with an explicit requirement, and charities.

Common questions

Questions UK MSPs ask us.

Does the DfE require schools to have DMARC? add

No, and it is worth being precise because the claim gets made a lot. The words DMARC, SPF and DKIM do not appear anywhere in the DfE cyber security core standard. A supplier telling a school otherwise is overstating it, and a business manager can check that in about thirty seconds.

What the standard does say is that schools should "check that your email is setup to be secure and that it reduces the risk of third parties being able to send imitation emails". That sentence appears twice, and each time it links out to the NCSC rather than naming a control of its own. The NCSC material it points to is about anti-spoofing, so DMARC, SPF and DKIM are how you would meet the expectation in practice — they are simply not what the DfE wrote down.

Status matters too. These are core standards the DfE says schools should be meeting now: an expectation rather than a statutory duty.

The standard links to NCSC Mail Check. Does that still work? add

No. The NCSC retired Mail Check and Web Check on 31 March 2026, announced on 6 November 2025 after the services had run since 2017. Users no longer receive findings, and historic findings do not transfer anywhere, so any new baseline starts from today. The DfE standard has not caught up, so a school following the guidance literally arrives at a tool that no longer produces anything.

The free NCSC Email Security Check remains and is worth running: it is an on-demand lookup of your anti-spoofing configuration and transport privacy. What it does not do is ingest DMARC aggregate reports, so it cannot tell you which sources are sending as your domain or whether the parent messaging platform is authenticating properly. That continuous view is the specific thing that left. Early Warning and DNS Check continue via MyNCSC.

We are a college with Cyber Essentials. Does that cover email spoofing? add

It does not, and both halves of this are worth knowing. Cyber Essentials is a requirement for colleges under their funding agreement, which makes it a genuine contractual obligation rather than an expectation — so a college has a harder requirement than a school does, just not on this subject.

Cyber Essentials contains no DMARC, SPF or DKIM control. The v3.3 requirements published in April 2026 cover five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Email authentication is not among them. A college can therefore hold a current certification and still have a domain that anyone in the world can send as. Answer the two questions separately rather than letting one stand in for the other.

Is this the same as the DfE filtering and monitoring standard? add

No. The two get conflated in conversation because both involve IT and both touch on keeping people safe, but they address different things entirely.

Filtering and monitoring concerns what pupils can reach on the internet and how that activity is supervised. Email authentication concerns whether somebody outside the school can send a message that appears to come from the school. Meeting one tells you nothing about the other, and a compliance answer that cites filtering in response to an email spoofing question will not survive a follow-up.

One related distinction while we are drawing lines: DMARC governs mail sent claiming to be your domain. It is not a filter on what arrives in staff or pupil mailboxes, and it is not a safeguarding control.

Our trust has domains from schools that converted years ago. Do those need anything? add

Yes, and they are the cheapest part of the job to deal with. A predecessor name that no longer sends any legitimate mail needs no sender inventory and no monitoring period. It can go straight to an enforcing policy with a null MX record to signal that it receives nothing either.

These names matter because they are still trusted by recipients and watched by nobody. A parent or a supplier who receives a message from a former school name has no easy way to tell it is not genuine, and since nothing legitimate sends from the domain, no one internally has any reason to look at it.

Bear in mind that the UK second-level suffixes are public suffixes, so the organisational domain for a school on .sch.uk is the school's own name below that suffix. A record on the trust domain never covers an academy domain, however closely related they are. Every name needs its own.

When in the school year should we move to enforcement? add

Observe in term time, enforce in a holiday. Term time is when every system is sending — admissions, the MIS, the parent messaging app, payments, catering, trips — so the inventory you build then is the real one. Give it at least a half-term before drawing conclusions, because a termly newsletter or an annual mailing will not show up in the first fortnight.

Make the actual policy move in a break, with a named approver and a rollback window, and avoid the week before an admissions deadline, results day or the first week of term. If a sender was missed, a holiday turns that into an inconvenience and a quick reversal instead of a queue of parents who never received something they needed.

One protocol change makes this sequencing matter more than it used to: DMARCbis, published in May 2026 as RFC 9989, removed the percentage tag. A policy now applies to all of a domain's mail or none of it, so there is no partial ramp to hide a missing sender behind.

Find out what is sending as your school domains.

Start a free trial, point the aggregate reports at DMARC AI, and get a dated sender inventory for every domain in the trust inside 48 hours — predecessor names included. Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.