Managed DMARC service

Managed DMARC for UK Domains

DMARC is not a difficult protocol. The record is one line of DNS, and most organisations get something published inside an afternoon. What defeats people is what comes after: reading aggregate reports every week, on every domain, indefinitely, and noticing the week something changes.

A managed DMARC service is the purchase of that attention. You keep the domains, the DNS and the final word on policy. Someone else owns the reading, the diagnosis, the record drafting and the recommendation — and owns it on a schedule rather than whenever there is a free afternoon.

What managed actually means

A division of labour, written down before you sign it.

The word is used loosely. Some suppliers mean a platform with a support inbox attached; some mean a consultant who appears twice a year. Agree the split in writing before you buy, because almost every dispute in a managed engagement traces back to a task both parties assumed the other had.

A managed service can own everything except two things: access to your DNS, and the truth about who is allowed to send as you. The first is yours to grant. The second is knowledge only your organisation holds, and no automation manufactures it.

The rest — ingestion, parsing, attribution, alignment diagnosis, record drafting, the monthly write-up — is better done by people who do it across many domains than by someone doing it twice a year on one.

account_tree Who owns what
Report ingestion Service. Reports arrive daily from receivers worldwide and are parsed on arrival. Nobody in your organisation opens an XML attachment.
Sender attribution Service first, then you. We name the sources sending as your domain; you confirm which of them are genuinely yours.
Authentication fixes Service specifies the exact SPF include or DKIM selector needed. You apply it, or we do where DNS is delegated.
Policy escalation You decide, on our evidence. We recommend, show the pass-rate history behind it and name the risk. The change is never made silently.
Monthly reporting Service. Written for the person who has to table it at a management meeting, not for the engineer who configured it.
New sender alerts Service raises it. You answer the only question that matters: is this ours, and should it be?

how_to_reg Recommend, then act

A service that escalates policy without a named approver on your side will eventually quarantine your payroll notifications on a Friday. Insist on an approver and a change window, even when the recommendation is obviously right.

dns Delegated DNS is optional

Some organisations delegate the record so fixes do not queue behind a change board. Others keep every edit in-house and paste what we draft. Both work; the second is slower.

block What it is not

Not a gateway, not a filter, not an inbox scanner. DMARC governs mail sent claiming to be your domain, not mail arriving at your staff. A managed DMARC service sits beside your mail security, not on top of it.

The recurring work

The labour is the product.

Stripped of marketing, a managed DMARC service is a subscription to a rhythm. Here is the rhythm. None of it is individually hard — the difficulty is that it has to happen in the week two systems are migrating and half the team is on leave.

Daily

Ingestion and anomaly watch

Large receivers send aggregate reports on a daily cycle. The value of daily is not that a human reads every report — it is that something is watching the delta: a sending source that was not there yesterday, an unfamiliar network pushing volume, a pass rate that stepped down overnight.

Weekly

The read

A human pass over every domain that moved. New sources get triaged into legitimate, unknown or hostile, and the unknowns become a short list of questions for you. This is the task organisations fully intend to do themselves, and then quietly stop doing around week six.

Monthly

The report and the fix queue

A written position for each domain, plus the remediation queue: the SPF include a new supplier needs, the DKIM selector for the survey tool finance bought, the alignment repair on a third party still signing with its own generic domain rather than yours.

Quarterly

The policy review

Is each domain ready to move up a policy level. Are the domains that should never send mail properly locked down. Do DKIM keys need rotating, and has anything in the estate changed hands, been acquired, been rebranded or been quietly allowed to lapse.

And the work that does not wait for a calendar

  • boltA department signs up for a platform that sends on the organisation's behalf.
  • boltA merger, acquisition or rebrand adds domains nobody has inventoried.
  • boltA mailbox migration changes the sending path and breaks alignment overnight.
  • boltA dormant domain is picked up in a spoofing run and starts appearing in reports.

UK organisations used to get part of this free

The NCSC retired Mail Check and Web Check on 31 March 2026, announced on 6 November 2025. Those services had run since 2017 and users no longer receive findings. The free Email Security Check remains, but it is an on-demand lookup and does not ingest aggregate reports.

To be plain: DMARC AI is not NCSC-approved, endorsed or certified. The NCSC does not endorse individual DMARC products — it published a vendor-neutral buyer's guide that names no vendors and left the choice to the buyer.

The enforcement decision

One moment in the whole rollout can break real mail.

Everything before enforcement is observation. Publishing a record and cataloguing senders changes nothing about what happens to a message. The moment policy moves, receivers act on your instruction, and a sender you failed to find starts failing in public.

DMARCbis removed the tag that used to soften this. RFC 9989, published in May 2026 alongside RFC 9990 and RFC 9991, dropped the pct= tag, so a policy applies to all mail or none of it. Inventory quality is now the only real safety mechanism.

account_tree The three steps, and the gate before each one
p=none Observation only. Receivers act on nothing and the domain stays spoofable throughout. Gate to leave: a full reporting cycle with no unexplained sending source.
p=quarantine Failing mail is treated as suspect and usually lands in junk. Gate to leave: a stable pass rate for legitimate mail across several reporting cycles, and a named owner for every remaining failure.
p=reject Refused at the receiver. The protection you were buying. It is a steady state rather than an end state — the next unannounced sender can still break it.

A managed service does not make this faster by being clever. It makes it faster by removing the reason rollouts stall: nobody read the reports for a month, so the gate was never assessed.

approval The approver is always yours

Name one person who can say yes, and one change window per domain. Enforcement is a business decision dressed as a DNS edit: you are accepting that mail from misconfigured senders will be refused rather than delivered.

history Keep a rollback window

One business day of heightened attention after each move, with the change logged where your service desk can see it. A missed sender surfaces while reverting is still cheap and the ticket gets routed to the right place.

lock Non-sending domains skip the queue

A domain with no legitimate senders needs no inventory. It can go straight to enforcement with a null MX record. On most UK estates that covers the majority of domains and is the cheapest risk reduction available.

Your side of the line

What no managed service can take off you.

Suppliers who imply otherwise are selling a disappointment. These four things stay with the customer in every managed engagement, and a rollout moves at the speed of whichever one you are worst at.

key

DNS access

Either delegate the record, or nominate someone who can turn a drafted change into a live one within days. Rollouts stall on change boards far more often than on technical problems.

fact_check

Sender truth

Reports show a source. Only you can say whether the events platform a colleague signed up for last spring is legitimate, and those answers gate the next policy step.

campaign

Telling us about change

A new marketing platform, an acquisition, a tenant migration. We will see it in the reports eventually. Hearing it in advance is the difference between a change request and an incident.

gavel

The decision to enforce

Accepting that some mail will be refused is a call for the organisation, not the supplier. We can make it well evidenced and low risk. We cannot make it for you.

One UK detail that shapes the scope of any managed engagement: .co.uk is a public suffix, so the organisational domain for example.co.uk is that name itself. No higher-level record covers a whole suffix, so every domain in your estate needs its own record, inventory and decision — which is why managed DMARC is scoped and priced per domain.

Three delivery models

In-house, through your MSP, or fully managed.

The right answer depends less on budget than on one question: will anybody in your organisation still be reading aggregate reports in month seven, when the project that funded this has closed and the person who cared about it has moved on.

groups

In-house

Platform subscription plus your own time.

  • check_circleWorks with a named owner, standing diary time and a handful of domains.
  • check_circleCheapest in cash terms, and you keep the knowledge inside the organisation.
  • removeFails silently when that person leaves or gets a bigger problem to solve.
handshake

Through your MSP

The party that already holds your DNS.

  • check_circleNatural home: they hold the DNS, the tenant and the change process already.
  • check_circleNo new supplier relationship, and it folds into an existing contract.
  • removeAsk whether DMARC is a scoped line with a cadence and a report, or a best-effort favour. The MSP practice guide sets out what good looks like.
shield_person

Fully managed

The outcome, contracted, with a cadence.

  • check_circleSuits a large or messy estate, thin internal capacity, or an assurance process to satisfy.
  • check_circleThe weekly read happens whether or not your week went to plan.
  • check_circleYou still own DNS, sender truth and the enforcement decision — by design.

Are you the buyer, or the provider?

This page is about the service wrapper around one organisation's estate: who reads, who drafts the record, who signs off enforcement. If you are the provider rather than the buyer — an MSP running DMARC across many customers' domains — the page you want is the UK MSP platform page, which covers multi-tenancy and portfolio reporting.

Platform pricing is transparent either way: from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains. There is no free tier, only a free trial.

Public sector body, or supplying one? The public sector page covers what the government guidance actually says and how to evidence your position. Coming off a retired NCSC service? The Mail Check replacement page covers the migration mechanics.

Common questions

Questions UK MSPs ask us.

What is the difference between a DMARC platform and a managed DMARC service? add

A platform ingests aggregate reports, parses them and shows you what they say. A managed service adds the person who reads the output on a schedule, decides what it means, drafts the record change and writes the report you can table at a management meeting.

The distinction matters because the platform is the easy half. Most organisations that stall on DMARC are not stuck on a technical problem — they published a record, collected reports for a fortnight, and then nobody looked again. Buying managed is buying the second half.

Who decides when to move to enforcement? add

You do. A managed service should recommend the move, show the pass-rate history behind the recommendation and name the residual risk, but the change itself belongs to a named approver on your side with a change window agreed in advance.

That matters more since DMARCbis. RFC 9989 removed the pct= tag, so a policy applies to all of your mail or none of it — there is no partial ramp to soften an incomplete sender inventory. The sequence is p=none, then p=quarantine, then p=reject, with a gate before each step and a rollback window after it.

Do we have to hand over DNS access? add

No. Delegating the record, or the whole zone, means fixes can be applied the day they are identified rather than queuing behind a change board. Plenty of organisations do it for exactly that reason.

The alternative works too: we draft the exact record, before and after, and your team publishes it. It is slower, and slow rollouts are where sender inventories go stale, but it keeps every change inside your own change process. What cannot work is nobody having practical DNS access at all — that is the single most common reason a rollout stops.

How long does a managed rollout take? add

Aggregate reports usually begin arriving within 24 to 48 hours of publishing a record with a reporting address, because most large receivers send on a daily cycle.

The rollout itself runs longer. Expect a few weeks at p=none to build a sender inventory you would bet on, then remediation for each legitimate sender, then escalation one domain at a time. Estates with many third-party senders — a marketing platform, a payroll provider, a fundraising tool, a survey system — take longer than an estate that only sends from one mail service. Domains that should never send mail are the exception: they can go straight to enforcement with a null MX record, and on most UK estates that covers the majority of domains.

Will managed DMARC stop phishing aimed at our staff? add

No, and it is worth being clear about this before anyone buys it as inbound protection. DMARC governs mail sent claiming to be your domain. It does not inspect mail arriving at your mailboxes, so it does nothing about a phishing message sent from a lookalike domain or a compromised third-party account.

What it stops is someone spoofing your exact domain at people who trust it: your customers, your suppliers, your residents, your own staff. That is a real and common attack, and enforcement closes it. Inbound filtering is a separate control that sits alongside it, not underneath it.

What happens if we stop the service? add

You keep the domains, the DNS and the published records — none of that is ours. Three things should happen on the way out: the rua= reporting address is repointed to wherever you want reports to go next, any delegation or verification records we relied on are removed, and the current policy state of every domain is documented in writing so the next owner does not roll enforcement back by accident.

Ask for the sender inventory as a static document as well. It is the most valuable artefact of the engagement, it took weeks of report data to build, and you should not have to rebuild it because you changed supplier.

See what is actually sending as your domain.

Start a free trial, publish a record with our reporting address, and get a real sender inventory inside 48 hours — before you decide who should own the weekly read. Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.