Advisers, brokers, asset managers, payments firms and their compliance teams

DMARC for UK Financial Services Firms

DMARC is not named anywhere in the FCA Handbook. It is not in PS21/3 either. We looked, in the primary material rather than in somebody's summary, and the term does not appear.

That is an unusual sentence for a vendor page to open with, and it is the most useful thing we can tell a compliance officer who has been sent a proposal claiming the opposite. What follows is where email authentication genuinely fits in a principles-based regime, and what it does and does not protect.

The honest regulatory position

No FCA rule names DMARC, SPF or DKIM.

Three places a firm might reasonably expect to find one, and what is actually written in each. None of it is ambiguous, which is why we would rather put the finding on the page than leave it to be discovered after a purchase.

policy

PS21/3, operational resilience

Building operational resilience brought rules into force from 31 March 2022, with the transition period ending on 31 March 2025. It is built around important business services, impact tolerances and scenario testing that includes cyber-attack scenarios. It prescribes no technical control.

rule_folder

SYSC 6 and SYSC 15A

The compliance and financial crime provisions, and the operational resilience chapter, are written in the language of adequate policies, systems and controls appropriate to the nature and scale of the business. They set an outcome. They name no standard and no protocol.

link

SYSC 8, outsourcing

SYSC 8 governs reliance on third parties and requires appropriate management of the risk that arrangements create. It is the chapter most relevant to email authentication in practice, and it too names nothing technical.

verified Why we are saying it this bluntly

Financial services is the vertical where "the regulator requires this" is most often used to shorten a sales cycle. It does not survive contact with the Handbook, and a compliance officer who checks will discount everything else the supplier said.

We would rather be the page that told you first. Any vendor claiming the FCA mandates DMARC is wrong, and you can verify that in minutes using the links above.

What that actually means

A regime that names no controls is not a regime with no expectations.

The absence of a named protocol is a deliberate design choice rather than an oversight. It moves the work from checking a list to making and defending a judgement.

Prescriptive regulation ages badly. A rulebook naming a 2015 control list would have been obsolete by 2020, and firms would have spent a decade complying with the wrong thing. Principles-based drafting avoids that by describing the outcome and leaving the method to the firm — which is why the same paragraph applies to a two-adviser practice and a global asset manager.

The practical consequence for a control decision

  • check_circleThe choice of control is the firm's. There is no list to satisfy, and no supplier can certify you against a list that does not exist.
  • check_circleThe reasoning is what gets examined. Why this control, why now, what it addresses, what it does not, and who owns it afterwards.
  • check_circleEvidence has to be contemporaneous. A control demonstrably in place beforehand reads very differently from one reconstructed after an incident.
  • check_circleOverstating scope is its own risk. A control register that claims DMARC prevents impersonation generally is inaccurate on its face.

Stated plainly: DMARC AI has no affiliation with the FCA, the NCSC or IASME, and is not approved, endorsed or accredited by any of them. Nothing on this page is legal, regulatory or compliance advice, and we are not going to tell you what your firm's obligations are — that is a matter for your compliance function, your own advisers and, where appropriate, the regulator. We describe a technical control and what it does.

Where it fits

Four places the question shows up in a real firm.

Set the Handbook aside for a moment. These are the situations in which somebody inside a financial services firm actually starts asking about the domain, usually without using the word DMARC.

forum

Client communications

Valuations, statements, suitability reports and fee notices arrive by email and carry your domain. A client has no practical way to distinguish yours from a forgery, which makes the sending domain the only place the check can happen.

payments

Payment and instruction correspondence

Anywhere a client, a counterparty or an administrator acts on written details, an impersonated message is worth more to an attacker than data. Verification procedures carry most of that load; the domain control removes one route into it.

hub

Outsourced and third-party senders

Under SYSC 8 a firm has to manage the risks in its third-party arrangements. Every provider that sends mail as your domain is one of those arrangements, and each is a separate alignment question rather than a single supplier decision.

quiz

Due-diligence questionnaires

Firms in this sector are asked about email authentication constantly — by institutional clients, custodians, platforms and insurers. The question rarely comes from the regulator. It comes from a counterparty with a spreadsheet and a deadline.

That last one is worth noticing. For many firms the commercial pressure to publish a policy arrives long before any regulatory conversation does, and it arrives with a date on it.

Scope, precisely

What to write in the control register, and what not to.

Three attacks look identical to the recipient and need three different controls. DMARC addresses one of them completely and the other two not at all. Recording it as protection against impersonation generally would be wrong, and wrong in a document somebody may later read closely.

rule Three attacks, three different answers
Exact-domain forgery In scope. An attacker places your real domain in the From header of a message sent from infrastructure they control. With an enforcing policy published and every legitimate sender aligned, receiving providers reject or quarantine it before delivery.
Account compromise Out of scope entirely. Mail sent from a real account with a stolen credential is genuinely from your domain and authenticates cleanly. This is an identity and access problem — multi-factor authentication, conditional access, session monitoring and detection of new mailbox rules.
Attacker-owned domain Also out of scope. A separate registration that reads like your name is under their control, with whatever records they choose to publish. Your policy has no reach into a domain you do not own. This needs registration monitoring and a takedown route.
Across all three Out-of-band verification. Confirming instructions on a separately held telephone number is the only control that covers every version, and no technical measure on this page is a reason to weaken it.

Because .co.uk is a public suffix, the organisational domain for example.co.uk is that whole name. A lookalike such as example-wealth.co.uk is a wholly separate domain that can never align with yours.

edit_note Wording that survives scrutiny

"Prevents unauthorised use of the firm's domains in the From header of email, at enforcement" is defensible. "Prevents email impersonation of the firm" is not, and the difference will matter to whoever reviews the register.

insights The visibility is the underrated half

Aggregate reports name every source sending as your domains, authorised or not. For firms with a long tail of outsourced senders that inventory is frequently the first complete picture anyone has held.

The part that takes the time

The domain count is small. The sender count is not.

A firm rarely has many domains. What it has is a long list of parties that send mail carrying its name — and unlike most sectors, a good number of them are contractual relationships rather than tools someone signed up for.

description

Statement and document providers

Platforms, custodians, administrators and print-and-post bureaux frequently despatch client documents on a firm's behalf. Each one either aligns to your domain or it does not, and finding out is a question for their support team.

campaign

Marketing and research distribution

Newsletters, market commentary, event invitations and webinar tooling, often run by an agency and often changed without telling anyone technical. This is the category that breaks a rollout after it has been signed off.

apps

Operational systems

CRM, e-signature, client portals, complaints handling, HR and recruitment tools. Individually minor, collectively the reason a sender inventory assembled from memory is always incomplete.

stairs Why the inventory carries all the risk now

The sequence is p=none, then p=quarantine, then p=reject. DMARCbis removed the percentage tag in RFC 9989, published May 2026, so each step now applies to all of your mail or none of it.

There is no partial ramp left to absorb a missed sender. In this sector the consequence of an incomplete list is a client statement or a regulatory-style notification that does not arrive, which is a worse outcome than the one you were mitigating.

Evidencing it

A screenshot proves a record existed for one second.

Where a control decision is examined, the interesting period is the twelve months around it rather than the moment somebody took a picture of a DNS lookup. Continuous records are the difference.

Worth holding

What a durable record looks like

  • check_circleEvery domain the firm holds, with its policy position and the date it reached it.
  • check_circleThe sender inventory, with each third party classified and an owner named.
  • check_circleAuthentication pass rates over time, which no point-in-time lookup can produce.
  • check_circleChange history: what moved, when, and who approved it.
  • check_circleA written scope statement, including the two attacks this control does not address.
What changed

The free UK service has gone

The NCSC retired Mail Check and Web Check on 31 March 2026, announced on 6 November 2025 after the services had run since 2017. Users no longer receive findings, and the NCSC pointed organisations to commercial products via a vendor-neutral buyer's guide. Early Warning and DNS Check continue through MyNCSC.

The free Email Security Check remains: an on-demand lookup of anti-spoofing configuration and transport privacy. It does not ingest aggregate reports, so it cannot produce a sender inventory or a trend.

Cyber Essentials does not cover this either. Its current requirements — v3.3, April 2026, effective 27 April 2026, administered by IASME — are firewalls, secure configuration, security update management, user access control and malware protection.

Whether you run it or someone runs it for you

Smaller firms usually hand this to the provider who already holds their DNS and their mail platform. Larger ones keep it in-house and want the reporting to sit alongside everything else the second line reviews.

The pricing is the same in both cases: transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains. There is no free tier, only a free trial.

Professional services with the same regulatory shape: accountancy practices and law firms. Continuous reporting: DMARC monitoring. Replacing the retired NCSC service: the Mail Check replacement page.

Common questions

Questions UK MSPs ask us.

Does the FCA require DMARC? add

No. DMARC is not named anywhere in the FCA Handbook, and it is not named in PS21/3 either. We checked the primary material directly — SYSC 6, SYSC 8, SYSC 15A and the operational resilience policy documents — rather than relying on a summary, and the term does not appear.

SPF and DKIM are absent in the same way. No FCA rule obliges a firm to publish any email-authentication record.

We put that on the page because financial services is the sector where "the regulator requires this" is most often used to shorten a sales cycle. Any vendor telling you the FCA mandates DMARC is wrong, and it takes about five minutes in the Handbook to confirm it.

Does PS21/3 or the operational resilience regime bring it in indirectly? add

PS21/3 "Building operational resilience" brought rules into force from 31 March 2022, with the transition period ending on 31 March 2025. It is built around identifying important business services, setting impact tolerances and testing the firm's ability to remain within them, including under cyber-attack scenarios.

What it is not is control-prescriptive. It describes outcomes and leaves the method to the firm. It does not mandate specific technical controls, and it names no email-authentication protocol.

Whether email authentication is relevant to a particular firm's important business services is a judgement for that firm. We are not going to make it for you, and we would be suspicious of a supplier who offered to. DMARC AI has no affiliation with the FCA and nothing here is regulatory or compliance advice.

If nothing requires it, why would a firm do it at all? add

Because the regime is principles-based rather than empty. SYSC 6 and SYSC 8 are written in the language of adequate policies, systems and controls appropriate to the nature and scale of the business — an outcome, with the method left to the firm. That moves the work from satisfying a list to making and being able to justify a judgement.

DMARC is one control a firm may choose in that context, and one it can evidence with dated, continuous records rather than an assertion. It is not an FCA requirement and should never be recorded as one.

There is also a plainer commercial reason. Institutional clients, custodians, platforms and insurers ask about email authentication in due-diligence questionnaires constantly, and that request usually arrives with a deadline attached long before any regulatory conversation does.

What exactly does DMARC protect against, and what does it not? add

It covers exactly one of three attacks that look identical to the recipient, and the distinction matters because it determines what you can honestly write in a control register.

In scope: forgery of your exact domain. An attacker puts your real domain in the From header of a message sent from their own infrastructure. With an enforcing policy published and every legitimate sender aligned, receiving providers reject or quarantine it before delivery.

Out of scope: account compromise. Mail sent from a real account using a stolen credential is genuinely from your domain and authenticates cleanly. That is an identity and access problem — multi-factor authentication, conditional access, session monitoring, detection of new mailbox rules.

Also out of scope: a domain the attacker registered. Because .co.uk is a public suffix, the organisational domain for example.co.uk is that whole name, and a lookalike such as example-wealth.co.uk is a wholly separate domain under their control. Your policy has no reach into it.

So "prevents unauthorised use of the firm's domains in the From header of email, at enforcement" is defensible wording. "Prevents email impersonation of the firm" is not.

We use a lot of outsourced senders. How much work is this really? add

The domain count is usually small and the sender count usually is not. That asymmetry is the defining feature of a financial services rollout.

Expect statement and document providers, platforms, custodians, administrators and print-and-post bureaux; marketing and research distribution, often run by an agency; and the operational tail of CRM, e-signature, client portals, complaints handling, HR and recruitment tools. Under SYSC 8 third-party arrangements have to be managed appropriately, and each provider sending as your domain is a separate alignment question rather than one supplier decision.

Publish a monitoring policy with a working reporting address first and let a full cycle of aggregate reports build the list, because one assembled from memory is always incomplete. Then move to p=quarantine and p=reject. DMARCbis removed the percentage tag in RFC 9989, published May 2026, so each step applies to all of your mail or none of it — there is no partial ramp left to absorb a missed sender, and in this sector the visible consequence is a client statement that does not arrive.

Does Cyber Essentials or an existing certification cover this? add

Cyber Essentials does not. Its current requirements — v3.3, April 2026, effective from 27 April 2026, administered by IASME — cover firewalls, secure configuration, security update management, user access control and malware protection. There is no DMARC, SPF or DKIM control among the five, so a certificate does not answer the question.

Other assurance schemes vary and we cannot speak for the one your firm holds. The safest approach is to check the control list rather than assume email authentication sits inside a scope statement written for something else.

How do we evidence the control if we are asked about it later? add

With something continuous rather than a screenshot. A DNS lookup captured on one afternoon proves a record existed at that moment and says nothing about the twelve months either side, which is normally the period of interest.

A durable record covers every domain the firm holds with its policy position and the date it reached it; the sender inventory with each third party classified and an owner named; authentication pass rates over time; a change history showing what moved, when and who approved it; and a written scope statement that names the two attacks the control does not address.

That last item is the one most often left out, and it is the one that makes the rest credible. Where the question is what your firm is actually obliged to demonstrate, that belongs with your compliance function or your own advisers rather than with us.

Start with the sender inventory, not the policy.

Start a free trial, point the aggregate reports at DMARC AI, and get a dated list of every source sending as each of your firm's domains inside 48 hours. Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.