Councils, public bodies and their suppliers

DMARC for UK Public Sector Organisations

Councils, public bodies, arm's-length bodies and the providers who serve them all lost the same thing on 31 March 2026: NCSC Mail Check, the free service that collected DMARC aggregate reports and turned them into findings somebody could put in front of an auditor.

The expectation that public sector email is authenticated did not retire with the tool. This page sets out what the government guidance actually says, exactly who it binds, and how to evidence your position now that the free evidence has gone — including the parts of the picture that are less tidy than most suppliers will tell you.

What the policy actually says

Addressed to the public sector. Binding through a narrower route.

This is worth reading slowly, because it is routinely overstated in sales material and just as routinely dismissed by organisations who assume it cannot apply to them. Both mistakes are expensive in front of an assessor.

description

The guidance, and its stated scope

GOV.UK's Securing government email guidance, updated 4 March 2024, states its applicability in one sentence: "This guidance applies to all email domains that public sector organisations run on the internet." It asks organisations to support TLS and DMARC as a minimum, and to have DMARC, DKIM and SPF records in place.

gavel

The binding driver is narrower

The hard mandate the guidance cites runs through a different document: "Central government organisations should already have implemented encryption and authentication in line with the Government Cyber Security Policy." That policy applies principally to central government, with arm's-length bodies generally picked up through their sponsoring department on a risk basis.

balance

So what binds a council?

Not a statute. There is no law compelling a council, a school or an NHS trust to publish a DMARC record, and any supplier telling you otherwise is guessing. What exists is a published government expectation for public sector email that has become a de-facto standard: it is what procurement asks about and what an assurance conversation starts from.

warning One honest caveat that will save you an afternoon

The guidance page still refers readers to Mail Check and has not been updated for its retirement. If you follow it literally you will be sent to a service that no longer produces findings, which is a poor position to discover halfway through an assurance meeting.

Confirm current expectations through your own assurance route — your departmental security team, your sponsoring department, or whoever owns your assurance framework — rather than assuming the published page reflects where things now stand. We would rather tell you that than pretend the picture is tidier than it is.

The Mail Check gap

What went, what stayed, and what nobody replaced.

The NCSC retired Mail Check and Web Check on 31 March 2026, announced on 6 November 2025. The services had run since 2017 and users no longer receive findings. The stated reasoning was that the external attack surface management market had matured, in line with the NCSC's Active Cyber Defence 2.0 roadmap.

power_settings_new

What you lost

  • removeContinuous ingestion of DMARC aggregate reports, presented as findings rather than raw XML.
  • removeA shared reference point both you and an assurance function treated as authoritative.
  • removeTrend data over time — historic findings do not transfer anywhere, so a new baseline starts from today.
  • removeThe convenient answer to "who watches our domains", which now needs a real one.
check_circle

What remains free

  • check_circleThe NCSC's Email Security Check: an on-demand lookup of anti-spoofing configuration and email privacy, meaning transport security.
  • check_circleEarly Warning and DNS Check, which continue via MyNCSC.
  • check_circleA vendor-neutral buyer's guide for external attack surface management, which names no vendors and sets out feature families: visibility and insight, security analysis, and supporting functions such as dashboards, shareable reports and workflow.
  • removeWhat none of these do: ingest your aggregate reports. That is the specific capability that left.

Stated plainly, because it comes up on every public sector deal: DMARC AI is not NCSC-approved, endorsed, certified or assured. The NCSC does not endorse individual DMARC products — its buyer's guide is deliberately vendor-neutral and leaves the selection to the buyer. Anyone claiming an NCSC endorsement, ours included, would be misrepresenting the position. The Mail Check replacement page covers the migration mechanics in full.

Evidencing your position

Evidence is now something you produce, not something you are sent.

The practical consequence of the retirement is administrative rather than technical. The controls have not changed. The proof has moved from a government service to your own record-keeping.

While Mail Check existed, "we are on Mail Check and it says we are fine" was an answer an assurance function accepted, because it came from a source both sides trusted. That sentence no longer means anything, and the organisations feeling it most never built an internal record because they did not need to.

A screenshot of a lookup tool is a weak substitute. It proves a record exists at one moment, but says nothing about whether unauthorised senders are using your domain or whether your legitimate mail actually authenticates.

What a defensible evidence pack contains

  • check_circleThe current DMARC, SPF and DKIM position for every domain in the estate, dated — not just the main one.
  • check_circleThe sender inventory: every source sending as each domain, classified as legitimate or not.
  • check_circleAuthentication pass rates over time, which is the part a point-in-time lookup can never give you.
  • check_circleThe policy position per domain, plus a dated plan for the next step where a domain is not yet at enforcement.
  • check_circleA register of domains that should never send mail, and confirmation they are locked down.
  • check_circleChange history: what changed, when, and who approved it.

A policy of p=none with a dated plan attached is a perfectly respectable position to hold in front of an auditor. A policy of p=none published in 2019 with nobody able to say who reads the reports is not, and it is the more common of the two.

Procurement and supplier assurance

The questions that turn up in the questionnaire.

These arrive from both directions: public bodies ask them of their suppliers, and suppliers to the public sector answer them to win work. Either way the answers below are the ones that survive follow-up questions.

Question

Do you have DMARC, SPF and DKIM on all sending domains?

The trap is the word "all". Most estates carry domains from campaigns, partnerships and rebrands that nobody has inventoried, and answering yes on the strength of the main domain is how a supplier ends up with a finding. Count first, answer second.

Question

What DMARC policy do those domains enforce?

A monitoring policy is a legitimate answer when it comes with a date and an owner attached. On its own it invites the follow-up nobody enjoys, which is how long the domain has been sitting there and who has been reading the reports in the meantime.

Question

Is this covered by your Cyber Essentials certification?

No, and say so. Cyber Essentials contains no DMARC, SPF or DKIM control. The current requirements — v3.3, published April 2026, effective 27 April 2026, administered by IASME — cover firewalls, secure configuration, security update management, user access control and malware protection. Treat any supplier who claims otherwise with caution.

Question

How do you monitor for spoofing of your own domains?

Before 2026 a lot of public sector answers to this pointed at Mail Check. That answer has expired, and the replacement needs to describe who receives the aggregate reports, who reads them, and how often — not merely which product was purchased.

Question

Where are your aggregate reports being sent?

Worth checking on your own estate before anyone asks. A rua= tag still pointing at a retired service means your domains have been reporting into a void, and nothing has been watching them for months.

Question

Can you evidence this to a third party?

The one that separates a real position from a configured one. Evidencing means a dated pack covering every domain, the senders behind them and the pass rates over time — produced on request rather than reconstructed the night before.

Rollout across a large estate

Rolling out across an estate nobody has counted.

The characteristic public sector problem is not technical difficulty. It is domain count. A body that has absorbed services, run campaigns and rebranded departments over twenty years is carrying domains no current member of staff registered, several of which still resolve and any of which can be spoofed.

account_tree A sequence that survives a big estate
Step 1 Count everything. Registrar exports, DNS zone lists, certificate transparency logs, and the campaign domains a service area pays for on its own budget line.
Step 2 Sort into three piles. Sends mail and should. Sends mail and should not. Should never send mail at all. The third pile is usually the largest and nobody expects that.
Step 3 Lock the third pile immediately. A domain with no legitimate senders needs no inventory and no monitoring window. Publish an enforcing policy and a null MX record, and a large part of the estate is closed in an afternoon.
Step 4 Monitor the senders. Publish a monitoring policy with a working reporting address on the first pile, build the inventory over a full cycle, then repair alignment sender by sender.
Step 5 Escalate, then keep going. One domain at a time, each with a named approver and a rollback window, while the weekly read and the evidence pack carry on underneath.

Since DMARCbis removed the pct= tag in RFC 9989, each policy step applies to all mail or none of it. There is no partial ramp, so the completeness of the inventory in step 4 is the only thing protecting service users from a broken mail flow.

account_balance gov.uk is a public suffix

The organisational domain for example.gov.uk is example.gov.uk, not gov.uk. No central record covers you, and the same is true across the other UK second-level suffixes. Every domain needs its own.

groups Shared services and providers

Many bodies run email through a shared service or an external provider. The work lands with whoever holds the DNS, so agree that before the project starts. A managed DMARC service exists precisely for the case where nobody internally will own the weekly read.

forward_to_inbox You are probably a bulk sender

Google's bulk sender requirements have applied since 1 February 2024 to anyone sending 5,000 or more messages a day to personal Gmail accounts: SPF, DKIM and DMARC at a minimum monitoring policy, spam complaints under 0.3%, and one-click unsubscribe on marketing mail. Council tax and waste notifications reach those volumes easily. Gmail escalated enforcement from November 2025, and Microsoft has comparable requirements for high-volume senders.

Serving public sector clients rather than running the estate? See the UK MSP platform page and the UK pricing page. Neighbouring sectors: NHS and healthcare, schools and academy trusts, charities.

Common questions

Questions UK MSPs ask us.

Is DMARC a legal requirement for UK councils? add

No. There is no statute compelling a council, a school or an NHS trust to publish a DMARC record, and a supplier telling you otherwise is overselling.

What exists is a published government expectation. GOV.UK's "Securing government email" guidance, updated 4 March 2024, states that it "applies to all email domains that public sector organisations run on the internet", and asks organisations to support TLS and DMARC as a minimum and to have DMARC, DKIM and SPF records in place. The binding driver it cites is narrower: central government organisations should already have implemented encryption and authentication in line with the Government Cyber Security Policy, which applies principally to central government, with arm's-length bodies generally covered through their sponsoring department on a risk basis.

The practical position for a council is therefore that it is a de-facto standard rather than a legal duty: it is what procurement asks about, what assurance conversations start from, and what a supplier questionnaire expects a clean answer to.

Mail Check has gone. Does that change what we are expected to do? add

No. The expectation sits in the guidance, not in the tool, so retiring the tool removed the free evidence rather than the obligation to have the controls.

One caveat worth knowing before you follow the guidance literally: the page still refers readers to Mail Check and has not been updated for its retirement on 31 March 2026. Confirm current expectations through your own assurance route — your departmental security team, your sponsoring department, or whoever owns your assurance framework — rather than assuming the published page is up to date.

Is the NCSC Email Security Check enough on its own? add

It is a sensible free first check, and not a replacement for what Mail Check did. Email Security Check is an on-demand lookup: it inspects your published anti-spoofing configuration and your email privacy, meaning transport security, at the moment you run it.

What it does not do is ingest DMARC aggregate reports. That means it cannot tell you which sources are sending as your domain, whether your legitimate mail is actually authenticating, or whether anything changed since the last time somebody looked. That continuous, report-based view is the specific capability that left on 31 March 2026.

A supplier questionnaire asks whether DMARC is covered by our Cyber Essentials certification. What do we say? add

Say no, because it is not. Cyber Essentials contains no DMARC, SPF or DKIM control. The current requirements — v3.3, published April 2026, effective from 27 April 2026, administered by IASME — cover five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.

Answer the DMARC question on its own terms instead: which domains have records, what policy each one is at, who receives the aggregate reports and who reads them. That answers what the assessor actually wants to know, and it will not fall apart under a follow-up question the way a Cyber Essentials claim would.

We have dozens of old domains nobody uses. Do those need DMARC too? add

Yes, and they are the easiest part of the job. A domain that has no legitimate senders needs no sender inventory and no monitoring window — it can go straight to an enforcing policy, with a null MX record to signal that it receives no mail either.

On a typical public sector estate this pile is larger than anyone expects: absorbed services, old campaign sites, partnership names, departments that were rebranded years ago. Because .gov.uk is a public suffix, the organisational domain for example.gov.uk is example.gov.uk rather than gov.uk, so there is no central record covering any of them. Each needs its own. Locking down the non-sending domains is the cheapest risk reduction available and usually closes most of the estate in an afternoon.

Is DMARC AI NCSC-approved or an official Mail Check replacement? add

No. DMARC AI has no affiliation with the NCSC and is not approved, endorsed, certified or assured by it. The NCSC does not endorse individual DMARC products.

What the NCSC did was publish a vendor-neutral buyer's guide for external attack surface management tools, which names no vendors, and direct organisations to choose a commercial product that fits their requirements. There is no official successor to Mail Check. Any supplier claiming to be one — including us, if we ever did — would be misrepresenting the position.

Find out what is sending as your domains.

Start a free trial, point the aggregate reports at DMARC AI, and get a dated sender inventory for every domain in the estate inside 48 hours. Transparent pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.