DMARC for UK Financial Services Firms
DMARC is not named anywhere in the FCA Handbook. It is not in PS21/3 either. We looked, in the primary material rather than in somebody's summary, and the term does not appear.
That is an unusual sentence for a vendor page to open with, and it is the most useful thing we can tell a compliance officer who has been sent a proposal claiming the opposite. What follows is where email authentication genuinely fits in a principles-based regime, and what it does and does not protect.
No FCA rule names DMARC, SPF or DKIM.
Three places a firm might reasonably expect to find one, and what is actually written in each. None of it is ambiguous, which is why we would rather put the finding on the page than leave it to be discovered after a purchase.
PS21/3, operational resilience
Building operational resilience brought rules into force from 31 March 2022, with the transition period ending on 31 March 2025. It is built around important business services, impact tolerances and scenario testing that includes cyber-attack scenarios. It prescribes no technical control.
SYSC 6 and SYSC 15A
The compliance and financial crime provisions, and the operational resilience chapter, are written in the language of adequate policies, systems and controls appropriate to the nature and scale of the business. They set an outcome. They name no standard and no protocol.
SYSC 8, outsourcing
SYSC 8 governs reliance on third parties and requires appropriate management of the risk that arrangements create. It is the chapter most relevant to email authentication in practice, and it too names nothing technical.
verified Why we are saying it this bluntly
Financial services is the vertical where "the regulator requires this" is most often used to shorten a sales cycle. It does not survive contact with the Handbook, and a compliance officer who checks will discount everything else the supplier said.
We would rather be the page that told you first. Any vendor claiming the FCA mandates DMARC is wrong, and you can verify that in minutes using the links above.
A regime that names no controls is not a regime with no expectations.
The absence of a named protocol is a deliberate design choice rather than an oversight. It moves the work from checking a list to making and defending a judgement.
Prescriptive regulation ages badly. A rulebook naming a 2015 control list would have been obsolete by 2020, and firms would have spent a decade complying with the wrong thing. Principles-based drafting avoids that by describing the outcome and leaving the method to the firm — which is why the same paragraph applies to a two-adviser practice and a global asset manager.
The practical consequence for a control decision
- check_circleThe choice of control is the firm's. There is no list to satisfy, and no supplier can certify you against a list that does not exist.
- check_circleThe reasoning is what gets examined. Why this control, why now, what it addresses, what it does not, and who owns it afterwards.
- check_circleEvidence has to be contemporaneous. A control demonstrably in place beforehand reads very differently from one reconstructed after an incident.
- check_circleOverstating scope is its own risk. A control register that claims DMARC prevents impersonation generally is inaccurate on its face.
Stated plainly: DMARC AI has no affiliation with the FCA, the NCSC or IASME, and is not approved, endorsed or accredited by any of them. Nothing on this page is legal, regulatory or compliance advice, and we are not going to tell you what your firm's obligations are — that is a matter for your compliance function, your own advisers and, where appropriate, the regulator. We describe a technical control and what it does.
Four places the question shows up in a real firm.
Set the Handbook aside for a moment. These are the situations in which somebody inside a financial services firm actually starts asking about the domain, usually without using the word DMARC.
Client communications
Valuations, statements, suitability reports and fee notices arrive by email and carry your domain. A client has no practical way to distinguish yours from a forgery, which makes the sending domain the only place the check can happen.
Payment and instruction correspondence
Anywhere a client, a counterparty or an administrator acts on written details, an impersonated message is worth more to an attacker than data. Verification procedures carry most of that load; the domain control removes one route into it.
Outsourced and third-party senders
Under SYSC 8 a firm has to manage the risks in its third-party arrangements. Every provider that sends mail as your domain is one of those arrangements, and each is a separate alignment question rather than a single supplier decision.
Due-diligence questionnaires
Firms in this sector are asked about email authentication constantly — by institutional clients, custodians, platforms and insurers. The question rarely comes from the regulator. It comes from a counterparty with a spreadsheet and a deadline.
That last one is worth noticing. For many firms the commercial pressure to publish a policy arrives long before any regulatory conversation does, and it arrives with a date on it.
What to write in the control register, and what not to.
Three attacks look identical to the recipient and need three different controls. DMARC addresses one of them completely and the other two not at all. Recording it as protection against impersonation generally would be wrong, and wrong in a document somebody may later read closely.
Because .co.uk is a public suffix, the organisational domain for example.co.uk is that whole name. A lookalike such as example-wealth.co.uk is a wholly separate domain that can never align with yours.
edit_note Wording that survives scrutiny
"Prevents unauthorised use of the firm's domains in the From header of email, at enforcement" is defensible. "Prevents email impersonation of the firm" is not, and the difference will matter to whoever reviews the register.
insights The visibility is the underrated half
Aggregate reports name every source sending as your domains, authorised or not. For firms with a long tail of outsourced senders that inventory is frequently the first complete picture anyone has held.
The domain count is small. The sender count is not.
A firm rarely has many domains. What it has is a long list of parties that send mail carrying its name — and unlike most sectors, a good number of them are contractual relationships rather than tools someone signed up for.
Statement and document providers
Platforms, custodians, administrators and print-and-post bureaux frequently despatch client documents on a firm's behalf. Each one either aligns to your domain or it does not, and finding out is a question for their support team.
Marketing and research distribution
Newsletters, market commentary, event invitations and webinar tooling, often run by an agency and often changed without telling anyone technical. This is the category that breaks a rollout after it has been signed off.
Operational systems
CRM, e-signature, client portals, complaints handling, HR and recruitment tools. Individually minor, collectively the reason a sender inventory assembled from memory is always incomplete.
stairs Why the inventory carries all the risk now
The sequence is p=none, then p=quarantine, then p=reject. DMARCbis removed the percentage tag in RFC 9989, published May 2026, so each step now applies to all of your mail or none of it.
There is no partial ramp left to absorb a missed sender. In this sector the consequence of an incomplete list is a client statement or a regulatory-style notification that does not arrive, which is a worse outcome than the one you were mitigating.
A screenshot proves a record existed for one second.
Where a control decision is examined, the interesting period is the twelve months around it rather than the moment somebody took a picture of a DNS lookup. Continuous records are the difference.
What a durable record looks like
- check_circleEvery domain the firm holds, with its policy position and the date it reached it.
- check_circleThe sender inventory, with each third party classified and an owner named.
- check_circleAuthentication pass rates over time, which no point-in-time lookup can produce.
- check_circleChange history: what moved, when, and who approved it.
- check_circleA written scope statement, including the two attacks this control does not address.
The free UK service has gone
The NCSC retired Mail Check and Web Check on 31 March 2026, announced on 6 November 2025 after the services had run since 2017. Users no longer receive findings, and the NCSC pointed organisations to commercial products via a vendor-neutral buyer's guide. Early Warning and DNS Check continue through MyNCSC.
The free Email Security Check remains: an on-demand lookup of anti-spoofing configuration and transport privacy. It does not ingest aggregate reports, so it cannot produce a sender inventory or a trend.
Cyber Essentials does not cover this either. Its current requirements — v3.3, April 2026, effective 27 April 2026, administered by IASME — are firewalls, secure configuration, security update management, user access control and malware protection.
Whether you run it or someone runs it for you
Smaller firms usually hand this to the provider who already holds their DNS and their mail platform. Larger ones keep it in-house and want the reporting to sit alongside everything else the second line reviews.
The pricing is the same in both cases: transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains. There is no free tier, only a free trial.
Professional services with the same regulatory shape: accountancy practices and law firms. Continuous reporting: DMARC monitoring. Replacing the retired NCSC service: the Mail Check replacement page.
The rest of the UK cluster.
By sector
Questions UK MSPs ask us.
Does the FCA require DMARC? add
No. DMARC is not named anywhere in the FCA Handbook, and it is not named in PS21/3 either. We checked the primary material directly — SYSC 6, SYSC 8, SYSC 15A and the operational resilience policy documents — rather than relying on a summary, and the term does not appear.
SPF and DKIM are absent in the same way. No FCA rule obliges a firm to publish any email-authentication record.
We put that on the page because financial services is the sector where "the regulator requires this" is most often used to shorten a sales cycle. Any vendor telling you the FCA mandates DMARC is wrong, and it takes about five minutes in the Handbook to confirm it.
Does PS21/3 or the operational resilience regime bring it in indirectly? add
PS21/3 "Building operational resilience" brought rules into force from 31 March 2022, with the transition period ending on 31 March 2025. It is built around identifying important business services, setting impact tolerances and testing the firm's ability to remain within them, including under cyber-attack scenarios.
What it is not is control-prescriptive. It describes outcomes and leaves the method to the firm. It does not mandate specific technical controls, and it names no email-authentication protocol.
Whether email authentication is relevant to a particular firm's important business services is a judgement for that firm. We are not going to make it for you, and we would be suspicious of a supplier who offered to. DMARC AI has no affiliation with the FCA and nothing here is regulatory or compliance advice.
If nothing requires it, why would a firm do it at all? add
Because the regime is principles-based rather than empty. SYSC 6 and SYSC 8 are written in the language of adequate policies, systems and controls appropriate to the nature and scale of the business — an outcome, with the method left to the firm. That moves the work from satisfying a list to making and being able to justify a judgement.
DMARC is one control a firm may choose in that context, and one it can evidence with dated, continuous records rather than an assertion. It is not an FCA requirement and should never be recorded as one.
There is also a plainer commercial reason. Institutional clients, custodians, platforms and insurers ask about email authentication in due-diligence questionnaires constantly, and that request usually arrives with a deadline attached long before any regulatory conversation does.
What exactly does DMARC protect against, and what does it not? add
It covers exactly one of three attacks that look identical to the recipient, and the distinction matters because it determines what you can honestly write in a control register.
In scope: forgery of your exact domain. An attacker puts your real domain in the From header of a message sent from their own infrastructure. With an enforcing policy published and every legitimate sender aligned, receiving providers reject or quarantine it before delivery.
Out of scope: account compromise. Mail sent from a real account using a stolen credential is genuinely from your domain and authenticates cleanly. That is an identity and access problem — multi-factor authentication, conditional access, session monitoring, detection of new mailbox rules.
Also out of scope: a domain the attacker registered. Because .co.uk is a public suffix, the organisational domain for example.co.uk is that whole name, and a lookalike such as example-wealth.co.uk is a wholly separate domain under their control. Your policy has no reach into it.
So "prevents unauthorised use of the firm's domains in the From header of email, at enforcement" is defensible wording. "Prevents email impersonation of the firm" is not.
We use a lot of outsourced senders. How much work is this really? add
The domain count is usually small and the sender count usually is not. That asymmetry is the defining feature of a financial services rollout.
Expect statement and document providers, platforms, custodians, administrators and print-and-post bureaux; marketing and research distribution, often run by an agency; and the operational tail of CRM, e-signature, client portals, complaints handling, HR and recruitment tools. Under SYSC 8 third-party arrangements have to be managed appropriately, and each provider sending as your domain is a separate alignment question rather than one supplier decision.
Publish a monitoring policy with a working reporting address first and let a full cycle of aggregate reports build the list, because one assembled from memory is always incomplete. Then move to p=quarantine and p=reject. DMARCbis removed the percentage tag in RFC 9989, published May 2026, so each step applies to all of your mail or none of it — there is no partial ramp left to absorb a missed sender, and in this sector the visible consequence is a client statement that does not arrive.
Does Cyber Essentials or an existing certification cover this? add
Cyber Essentials does not. Its current requirements — v3.3, April 2026, effective from 27 April 2026, administered by IASME — cover firewalls, secure configuration, security update management, user access control and malware protection. There is no DMARC, SPF or DKIM control among the five, so a certificate does not answer the question.
Other assurance schemes vary and we cannot speak for the one your firm holds. The safest approach is to check the control list rather than assume email authentication sits inside a scope statement written for something else.
How do we evidence the control if we are asked about it later? add
With something continuous rather than a screenshot. A DNS lookup captured on one afternoon proves a record existed at that moment and says nothing about the twelve months either side, which is normally the period of interest.
A durable record covers every domain the firm holds with its policy position and the date it reached it; the sender inventory with each third party classified and an owner named; authentication pass rates over time; a change history showing what moved, when and who approved it; and a written scope statement that names the two attacks the control does not address.
That last item is the one most often left out, and it is the one that makes the rest credible. Where the question is what your firm is actually obliged to demonstrate, that belongs with your compliance function or your own advisers rather than with us.
Start with the sender inventory, not the policy.
Start a free trial, point the aggregate reports at DMARC AI, and get a dated list of every source sending as each of your firm's domains inside 48 hours. Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.