After the retirement

Replace Mail Check-Style Monitoring with MSP-Ready DMARC

A free service that thousands of UK organisations relied on for nine years has been switched off. If you are a public sector body, a supplier to one, or the MSP holding the DNS for both, this page sets out exactly what was withdrawn, what is still available at no cost, and what a working replacement has to do.

It is written to be useful even if you buy nothing from us. Follow the migration steps with any competent DMARC platform and your domains will be in a better state than they were on 30 March 2026.

What actually happened

The dates, without the vendor spin.

Read the announcement yourself: Retiring Mail Check and Web Check on the NCSC website.

This was a planned withdrawal with five months of notice, not an outage. It follows the NCSC's ACD 2.0 roadmap, under which the organisation delivers a solution only where the commercial market cannot. The stated judgement was that the external attack surface management market has matured, with many products now covering what these services did, plus more besides.

In its own words: “By 31 March 2026, organisations should have alternatives to Mail Check and Web Check in place.” That sentence is the whole brief. The NCSC did not tell anyone which alternative to pick.

2017

Both services launch

Mail Check and Web Check begin operating as part of the Active Cyber Defence programme. Over the following nine years they become the default free baseline for UK public sector email and web hygiene.

6 November 2025

Retirement announced

The NCSC publishes the retirement notice and gives organisations until the end of March to arrange alternatives. Users of both services are notified directly.

31 March 2026

Findings stop

Mail Check and Web Check are retired. From this date users no longer receive findings from either service. Any DMARC record still pointing rua= at a Mail Check address is now reporting into nothing.

Alongside

A buyer's guide, no vendors

The NCSC publishes a vendor-neutral external attack surface management buyer's guide. It names no products and recommends no supplier.

Lost and kept

Less went away than people assume — but the important part did.

Only Mail Check and Web Check were retired. Several free NCSC services carry on, and it is worth being clear about which is which before spending money you may not need to spend.

unpublished

What you lost

  • remove_circleContinuous ingestion of DMARC aggregate reports on your behalf, and the findings built from them.
  • remove_circleThe history. Trend data held in Mail Check does not transfer to anything, and cannot be reconstructed after the fact.
  • remove_circleA named, free, government-run reporting endpoint you could put in a DMARC record without a procurement conversation.
  • remove_circleThe web-side checks that Web Check performed, which are outside DMARC entirely and need their own answer.
check_circle

What you kept

  • checkEarly Warning and DNS Check, both continuing through MyNCSC accounts.
  • checkEmail Security Check, a free on-demand lookup covering email anti-spoofing configuration and email privacy — whether TLS protects your mail in transit.
  • checkThe published guidance itself, which is unchanged. The protocols did not move; only the tooling did.

Use Email Security Check. It is genuinely good and it costs nothing. Just understand its shape: it inspects what your DNS says, not what your mail does. It does not ingest aggregate reports, so it cannot show you who is sending as your domain over time. Its SPF check looks for syntax errors rather than verifying that the record is complete — a record can be flawless and still omit half your senders.

info

DMARC AI has no affiliation with the NCSC.

We are not NCSC-approved, assured, certified, recommended or partnered, and we are not a successor to Mail Check. The NCSC does not endorse individual DMARC products. Its buyer's guide names no vendors and recommends no supplier, which is a deliberate position and one we are not going to blur.

This page uses the name Mail Check descriptively, because that is the service people are searching for and the honest way to describe what they lost. Nothing on it should be read as continuity, succession or transfer from a government service to a commercial one.

If any supplier tells you they are the official or NCSC-endorsed replacement for Mail Check, that claim is false. Ask them to put it in writing and watch what happens.

Selection criteria

What an alternative to Mail Check actually has to do.

The NCSC buyer's guide groups external attack surface management capability into three families: visibility and insight, security analysis, and supporting functions such as dashboards, downloadable or shareable reports, and workflow features like comments and status fields. Those families translate cleanly into DMARC requirements. Take this list to any supplier, including us.

travel_explore

Visibility and insight

It must ingest DMARC aggregate reports continuously and turn them into a named sender inventory. A tool that only reads your DNS record is a checker, not a monitor, and it will not replace what you lost.

Ask: how long is report history retained, can I see a new sender appear the day it appears, and can I export the raw data if I leave?

troubleshoot

Security analysis

It must explain failures in terms of the fix — the missing SPF include, the DKIM selector that needs a custom signing domain, the sender that will never align — rather than handing you a pass rate and leaving you to guess.

Ask: does it tell me when a domain is safe to move to p=quarantine, and on what evidence?

description

Supporting functions

Dashboards, downloadable and shareable reports, and workflow features — comments, owners, status fields — so a finding can be assigned and closed rather than rediscovered every quarter.

Ask: can I hand the report to a board, an auditor or a client without rewriting it first?

One criterion the guide cannot answer for you: scale. A single organisation monitoring one domain has very different needs from a provider monitoring two hundred across sixty clients. That difference is the subject of the UK MSP platform page, and it is where per-seat licensing quietly falls apart.

The migration

Five steps. The DNS change is the easy part.

These steps work with any DMARC platform. Nothing below depends on choosing us, and if you follow them with a different tool you will still end up in the right place.

Step 1

Inventory every domain, not just the ones that send

List every domain the organisation owns, including parked ones, legacy brands and the campaign domain from four years ago. Record the current DMARC state of each: no record, p=none, or enforcement. Flag any whose rua= still points at a retired Mail Check address — those domains have been reporting into a void since 31 March 2026, and they are the ones most likely to be silently wrong.

Step 2

Repoint rua= and leave the policy alone

Edit the _dmarc TXT record on each domain and replace the reporting address with your new endpoint. Do not change p= in the same edit. Two changes at once means you cannot tell which one caused the outcome. Reports usually start arriving within 24 to 48 hours, because most large receivers send on a daily cycle. If nothing arrives in 72 hours, the record is wrong.

Step 3

Re-baseline from zero

This is the step people skip. Your Mail Check history does not migrate, so you are starting a fresh evidence trail. Give it two to four weeks at your existing policy before drawing conclusions — a monthly biller, a quarterly statement run or an annual renewal mailing will not appear in the first week, and moving to enforcement without them in the inventory is how you break exactly the mail that matters most.

Step 4

Fix alignment, then escalate one step at a time

Work the sender inventory: add the SPF include, enable DKIM, move third-party senders onto a custom signing domain so they align. Then p=nonep=quarantinep=reject. DMARCbis (RFC 9989) removed the pct= tag, so each step is all-or-nothing — there is no partial ramp to hide behind, and the completeness of your inventory is now the only safety mechanism you have.

Step 5

Write down who owns it now

Mail Check made ownership ambiguous in a comfortable way: the findings arrived, someone glanced at them, nobody was formally accountable. A commercial tool does not resolve that on its own. Name the person or the supplier responsible for reviewing reports, the review cadence, and the escalation route when a new unauthenticated sender appears. Put it in the contract if a supplier holds it. This is the difference between having a replacement and having a subscription.

Mail Check replacement for MSPs

One retirement, multiplied by every client domain you hold.

The broader practice mechanics — tiering, pricing, offboarding — live in the DMARC for MSPs guide.

For a single organisation this is an afternoon of DNS edits and a diary note. For a provider it is a portfolio migration: dozens of zones, several DNS providers, a mixture of clients who knew they were using Mail Check and clients who had no idea a government service was quietly watching their email.

Three things change at portfolio scale. The migration itself has to be templated, or it becomes fifty separate small projects that never quite finish. The monitoring has to be multi-tenant, so one client's data stays in one client's view and a colleague can be handed a single tenant without seeing the rest of the book. And the reporting has to be client-ready as it comes out, because a report that needs an engineer to rewrite it before sending is unbillable work repeated every month.

On cost: transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains. There is no free tier — a free trial only. We would rather say that plainly than advertise a free plan that stops being useful at the point you actually need it. The UK pricing page has the detail.

There is a commercial point worth naming honestly. This retirement is a legitimate reason to open a conversation with every client on the book — not manufactured urgency, just a free service that no longer exists. Lead with what they lost and what is still free, and the conversation goes better than a cold security upsell.

Public sector

The tool was retired. The requirement was not.

GOV.UK's Securing government email guidance, last updated 4 March 2024, states that public sector organisations must support DMARC and must have DMARC, DKIM and SPF records in place. That expectation sits under the Government Cyber Security Policy. It is guidance published under that policy rather than text written into GovS 007, and it is worth describing accurately: overstating it in a proposal is embarrassing in front of an assessor.

The point stands regardless of how it is framed. The obligation attaches to the domain, not to the tool you used to observe it. Nothing about the retirement of Mail Check reduces what a public sector body is expected to have in place — it removes the free instrument that made it easy to see.

One observation, offered as an observation rather than advice: at the time of writing, that guidance page still refers readers to Mail Check and appears not to have been updated for the retirement. If your assurance process cites it, do not assume the referenced tooling is still available. Confirm current expectations through your own assurance route rather than through a vendor page, including this one.

For suppliers to the public sector, the practical consequence is procurement rather than policy. Anti-spoofing questions appear in supplier questionnaires, and a blank answer is scored as a gap. Continuous monitoring is what lets you answer with evidence instead of an assertion — the DMARC monitoring page covers how that evidence is produced.

Common questions

Questions UK MSPs ask us.

Has NCSC Mail Check actually been withdrawn? add

Yes. The NCSC retired Mail Check and Web Check on 31 March 2026. The retirement was announced on 6 November 2025, and as of that date users no longer receive findings from either service.

The NCSC's stated reasoning was that the external attack surface management market had matured to the point where commercial products cover what these services provided. Early Warning and DNS Check continue via MyNCSC.

Is DMARC AI an NCSC-approved replacement? add

No, and we want to be precise here: DMARC AI has no affiliation with the NCSC, and the NCSC does not endorse or approve individual DMARC products.

The NCSC published a vendor-neutral buyer's guide for external attack surface management products and directed organisations to choose a commercial tool that fits their requirements. This page describes how DMARC AI covers the email-authentication monitoring that Mail Check provided; it is not a claim of endorsement.

What exactly do we lose without Mail Check? add

The main loss is continuous, report-based visibility: Mail Check collected DMARC aggregate reports and presented them as findings, so you could see which senders were failing authentication over time without parsing XML.

The NCSC's free Email Security Check still covers the configuration lookup — whether your DMARC record is present and correctly formed, and whether transport security is in place. What it does not do is process aggregate reports, which is the part that tells you who is sending as your domain.

We are a public sector body. Are we still required to use DMARC? add

Yes. The requirement sits in GOV.UK's "Securing government email" guidance, not in Mail Check itself, so the retirement of the tool does not remove the obligation.

That guidance states public sector organisations must support DMARC, and must have DMARC, DKIM and SPF records in place. Note that the guidance page has not been fully updated for the Mail Check retirement and still refers readers to the service — verify current expectations with your own assurance route.

Can an MSP manage this on behalf of several public sector clients? add

That is the shape the platform is built for. Each client domain sits in its own tenant with its own reporting, while the MSP sees the whole portfolio in one view.

For public sector clients the reporting matters as much as the monitoring, because the organisation usually needs to evidence its position to an assurance process rather than simply know it internally.

How do we migrate from Mail Check to a commercial platform? add

The mechanical step is small: change the rua= address in each domain's DMARC record to point at your new platform's reporting endpoint, then confirm reports begin arriving within about 48 hours.

The larger task is re-establishing your baseline. Historic Mail Check findings do not transfer, so plan for a fresh monitoring window at your current policy before making enforcement decisions, and treat the migration as a good moment to audit which senders each domain actually uses.

Repoint one domain and see what your reports say.

Start a free trial, change the rua= address on a single domain, and you should see real aggregate report data within 48 hours. Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.