NHS organisations, primary care and the supply chain

DMARC for the NHS and NHS Suppliers

In almost every UK sector, the honest answer to "does anything actually require DMARC" is no. Health and care is the exception. The NHS Data Security and Protection Toolkit names DMARC, DKIM and SPF in writing, and the HSCN domain policy attaches a consequence to getting them wrong that no other sector carries.

This page quotes what those documents say, sets out who they bind, and explains what "enforced on all inbound email" is actually asking your mail platform to do.

What the DSPT says

Data Security Standard 6 names the protocol, in writing.

The text sits in the assessment guide for email server software, questions 6.2.6 to 6.2.9, published by NHS England Digital and last edited on 8 October 2025. It is unusually specific for a UK requirement document.

shield

The line everyone quotes

Seven words, in the assessment guide itself: "DMARC should be enforced on all inbound email." No other UK sector requirement document states it that directly.

dns

And the records themselves

The same guide continues: "Your email service provider must implement Domain-based Message Authentication Reporting and Conformance (DMARC), Domain Keys Identified Mail (DKIM) and Sender Policy Framework (SPF) records should be implemented to make email spoofing more difficult." The sentence is awkwardly constructed. Its meaning is not in doubt.

how_to_reg

What you confirm at submission

The attestation reads: "You have implemented on your email, DMARC, Domain Keys Identified Mail (DKIM) and Sender Policy Framework (SPF) for your organisation's domains to make email spoofing difficult." Note the plural: domains, not domain. Organisations tick it thinking only of the one on the letterhead.

gavel How binding is it, precisely?

Completing the toolkit is mandatory for organisations that access NHS patient data or NHS systems, enforced through the NHS standard contract and through data-sharing agreements. That makes it a binding contractual and toolkit requirement rather than primary legislation. Describe it that way rather than calling it "the law" — an assessor will notice.

For an organisation that intends to keep an NHS contract, the practical difference is thin. The requirement is written down, asked about annually, and the answer has your name against it.

The HSCN domain policy

The requirement that comes with an actual penalty.

Requirements nobody enforces get quietly ignored. This one is enforced by taking the domain away — a consequence you will not find in any other UK email security guidance.

rule

What the policy asks for

Policies supporting domain name administrators and technical contacts, published by NHS England Digital and last edited on 28 August 2024, applies to any system or service using the HSCN DNS. Among the duties it places on those contacts is to "ensure that email security records relating to SPF, DMARC and DKIM are properly formatted".

warning

What happens if you do not

"Failure to comply with this policy will result in the domain being removed from your control and ultimately decommissioned."

That is not a finding on a report. It is the domain ceasing to be yours, and with it the mail flow, the system integrations and every address printed on a letter.

Three things people miss about that policy

  • boltIt follows the DNS, not the organisation type. Connected technical suppliers holding HSCN domains are covered as squarely as an NHS body.
  • bolt"Properly formatted" is doing quiet work. An invalid record, two TXT records at the same DMARC name, or an SPF record past the ten-lookup limit all fail that test.
  • boltNothing warns you. A record that parsed at the last change can be broken by the next one, silently, until somebody looks.

If you hold a domain on the HSCN DNS and cannot say today whether its records parse cleanly, that is an hour's work this week.

Who this applies to

Trusts, practices, and everybody in the supply chain.

The common misreading is that this is a hospital problem. The toolkit follows the data and the domain policy follows the DNS, so a small software supplier can face exactly the same question as an acute trust.

In scope

NHS organisations

Trusts, integrated care boards and other NHS bodies complete the toolkit as a condition of the contracts and data-sharing agreements they operate under. Standard 6 is not optional within that submission.

In scope

Primary care

GP practices, dental practices, community pharmacy and optometry complete the toolkit in their own right, usually with far less IT capacity than a trust and often through an outsourced provider who holds the DNS.

In scope

Suppliers touching patient data

If your contract requires a toolkit submission, Standard 6 is yours regardless of headcount. That catches software vendors, transcription and coding services, medical device companies with a data component, and anyone processing patient information on an NHS body's behalf.

In scope

Anyone holding an HSCN domain

The domain administration policy is a separate obligation from the toolkit. If a domain of yours sits on the HSCN DNS, the formatting duty and the decommissioning consequence apply whether or not you complete a submission.

lock Where the secure email standard fits, accurately

The secure email standard DCB1596 governs whether an organisation's email service is accredited to exchange patient-confidential information with health and care organisations. Its requirements concentrate on transport encryption and organisational policy rather than naming DMARC.

Treat it as a separate question. Accreditation under the secure email standard does not answer Standard 6, and a clean DMARC position does not accredit your service.

What the wording means in practice

"Enforced on all inbound email" — and the half that sentence leaves out.

DMARC has two sides and the toolkit sentence names only one. They are configured in different places, by different people, and doing one does nothing for the other. Both are needed before the attestation is honestly true.

account_tree The two halves, and where each one lives
Inbound enforcement Your mail platform, not your DNS. For every arriving message, your gateway looks up the policy published by the domain it claims to come from, and acts on it. This is the sentence in the assessment guide.
Outbound policy Your DNS, not your mail platform. The record you publish tells every other receiver in the world what to do with mail claiming to be you. Nothing about your inbound configuration protects your name in a patient's inbox.
Reporting The address in the record. Receivers return daily aggregate reports naming every source sending as your domain. Without a working address here you are enforcing blind.
Subdomains Inherited unless overridden. A subdomain follows the organisational domain's policy unless a subdomain policy tag says otherwise — which is how a forgotten research subdomain gets quarantined a week after you move the parent.

On the outbound side the sequence runs p=none, then p=quarantine, then p=reject. DMARCbis removed the percentage tag in RFC 9989, published May 2026, so each step applies to all of your mail or none of it. There is no partial ramp to hide a missing sender behind, and in a clinical setting that means an appointment reminder which never lands.

account_balance nhs.uk is a public suffix

The organisational domain for example.nhs.uk is that whole name, not nhs.uk. No central record covers you, and the same is true of any commercial or charity names you hold.

toggle_on Check the inbound default

Some gateways ship with DMARC honouring switched off, or substitute their own verdict for the sender's published policy. Confirm the actual behaviour rather than the presence of a setting — the question is about enforcement, not availability.

inventory_2 Non-clinical domains count

Research programmes, recruitment sites, a charity arm, a predecessor organisation's name. The attestation says domains, plural. The ones that should never send mail are the quickest to lock down.

Evidencing it

The attestation is one line. The evidence behind it is yours to hold.

Ticking the box takes a second. Showing, six months later, that it was true on the day you ticked it is the part that takes organisation.

Until recently a good deal of that proof came free. The NCSC retired Mail Check and Web Check on 31 March 2026, announced on 6 November 2025 after the services had run since 2017, and users no longer receive findings.

The free Email Security Check remains and is worth running: an on-demand lookup of anti-spoofing configuration and transport privacy. It does not ingest aggregate reports, so it cannot tell you which sources are using your domain.

A screenshot of a lookup proves a record existed at one moment. It says nothing about the twelve months either side, which is the window an assessor asks about.

What to hold against Standard 6

  • check_circleEvery domain the organisation owns, with its DMARC, SPF and DKIM position, dated. The plural in the attestation is the point.
  • check_circleThe inbound side: a dated record of how your mail platform handles DMARC on arriving messages.
  • check_circleThe sender inventory: every source sending as each domain, classified as legitimate or not, with the clinical systems named.
  • check_circleAuthentication pass rates over time, which a point-in-time lookup can never give you.
  • check_circleThe policy per domain, plus a dated plan and a named owner wherever a domain is not yet at enforcement.
  • check_circleChange history: what changed, when, and who approved it — including HSCN-held domains.

Stated plainly: DMARC AI has no affiliation with NHS England, NHS England Digital or the NCSC, and is not approved, accredited, endorsed or assured by any of them. No product makes an organisation DSPT compliant. A DMARC platform supports one technical control inside Standard 6 and produces the evidence for it. The submission, and the accuracy of every answer in it, stay with the organisation.

For providers and MSPs

Serving several NHS-adjacent clients at once.

Providers with health and care clients get this question in clusters rather than one at a time, because submission deadlines are shared. The work is no harder than any other rollout; the shape of the reporting differs.

event_repeat

The deadline is shared

Several clients ask the same Standard 6 question in the same few weeks. A portfolio view lets you answer it once instead of repeating a discovery exercise five times.

badge

The output must be per client

Each submission belongs to one organisation and names one set of domains, so evidence has to come out separated, dated and attributable to a single client rather than as a portfolio dashboard.

hub

Domains outnumber clients

A practice group, a merged supplier, a service that rebranded. Every UK second-level suffix puts the organisational boundary one label down, so each name needs its own record and decision.

Where to go next

If you run the estate yourself, the question is who performs the weekly read of the aggregate reports once the funding project has closed. If you run it for other organisations, the question is how the reporting comes out per client.

Pricing is the same either way: transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains. There is no free tier, only a free trial.

Neighbouring sectors, where the requirement picture is weaker and the pages say so: councils and public bodies, schools and academy trusts, charities. Migrating off the retired NCSC service: the Mail Check replacement page.

Common questions

Questions UK MSPs ask us.

Is DMARC actually required for NHS organisations? add

Yes, and health and care is the one UK sector where that answer is unambiguous. The NHS Data Security and Protection Toolkit assessment guide for email server software, covering questions 6.2.6 to 6.2.9 under Data Security Standard 6 and last edited on 8 October 2025, states: "DMARC should be enforced on all inbound email." The same guide asks that DMARC, DKIM and SPF records be implemented to make email spoofing more difficult, and the attestation organisations confirm reads: "You have implemented on your email, DMARC, Domain Keys Identified Mail (DKIM) and Sender Policy Framework (SPF) for your organisation's domains to make email spoofing difficult."

Describe the status precisely. Completing the toolkit is mandatory for organisations that access NHS patient data or NHS systems, and it is enforced through the NHS standard contract and through data-sharing agreements. That makes it a binding contractual and toolkit requirement rather than primary legislation. For an organisation that wants to keep an NHS contract, the practical difference is small — but an assessor will notice if you call it the law.

We supply the NHS but are not an NHS body. Does this apply to us? add

Usually, yes, and on two separate bases. If your contract requires a toolkit submission because you process patient data or access NHS systems, Standard 6 is yours to answer regardless of your size. A five-person software supplier answers the same email question as an acute trust.

The second basis is the domain policy, which is independent of the toolkit. The HSCN guidance on policies supporting domain name administrators and technical contacts applies to any system or service using the HSCN DNS, and it names connected technical suppliers as well as NHS organisations. If a domain of yours sits on the HSCN DNS, the obligations attach to that domain whether or not you complete a submission.

What does "DMARC should be enforced on all inbound email" mean in practice? add

It means your mail platform should check the DMARC policy published by the domain each arriving message claims to come from, and act on it. That is a receiver-side setting in your gateway or tenant, not a DNS record. Worth confirming the real behaviour rather than the presence of a switch: some platforms ship with DMARC honouring disabled, and some substitute their own spam verdict for the sender's published policy, which is not the same thing as enforcing it.

The sentence only covers half of DMARC, though. The other half is the record you publish for your own domains, which tells every receiver in the world what to do with mail claiming to be you. Inbound enforcement protects your staff from other people's spoofed mail. Only your own outbound record protects your name in a patient's inbox, and the toolkit attestation asks about both.

Can a domain really be decommissioned for badly formatted email security records? add

That is what the policy says. The HSCN guidance on policies supporting domain name administrators and technical contacts, last edited on 28 August 2024, places a duty on administrators and technical contacts to "ensure that email security records relating to SPF, DMARC and DKIM are properly formatted". The consequence is stated in the same document: "Failure to comply with this policy will result in the domain being removed from your control and ultimately decommissioned."

Two practical points. "Properly formatted" catches more than a missing record — a syntactically invalid record, duplicate TXT records at the same DMARC name, or an SPF record that exceeds the ten-lookup limit all fail that test. And nothing warns you when it breaks: a record that parsed cleanly at the last DNS change can be broken by the next one, silently, until somebody checks.

Does the secure email standard DCB1596 require DMARC? add

Not in the way people often assume, and it is worth being accurate. DCB1596 governs whether an organisation's email service is accredited to exchange patient-confidential information with health and care organisations. Its requirements concentrate on transport encryption and on organisational policy rather than naming DMARC in the requirement list.

Treat it as a separate question from Standard 6. Accreditation under the secure email standard does not answer the toolkit email question, and a clean DMARC position does not accredit your service. Where a supplier blurs the two, they are usually offering one and hoping you assume the other.

Does using DMARC AI make us DSPT compliant, and are you NHS-approved? add

No to both, and we would rather say so plainly than let it sit ambiguous on a page about NHS requirements. DMARC AI has no affiliation with NHS England, NHS England Digital or the NCSC, and is not approved, accredited, endorsed or assured by any of them. No product confers DSPT compliance on an organisation.

What a DMARC platform does is support one technical control inside Standard 6 and produce the evidence behind it: the position of every domain you own, the sources sending as them, the pass rates over time, and a change history. The submission itself, and the accuracy of every answer in it, remain yours. That is also why the free NCSC Email Security Check is not enough on its own — it is an on-demand lookup and does not ingest DMARC aggregate reports, which is the capability that left when Mail Check was retired on 31 March 2026.

Answer Standard 6 with evidence, not a guess.

Start a free trial, point the aggregate reports at DMARC AI, and get a dated sender inventory for every domain your organisation holds inside 48 hours. Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.