Back to blog

How to Implement DMARC for Email Security in UK

A practical step-by-step guide for UK organisations

Published: July 22, 2026

DMARC for UK organisations: a full guide

DMARC is the email authentication standard that tells receiving mail servers what to do with messages that fail to prove they came from you. Without it, anyone can send an email that looks like it came from your domain. Your customers, suppliers, and staff cannot tell the difference.

According to live data from DmarcDkim.com monitoring 70,000+ UK domains as of July 2026, 73.9% have no effective DMARC protection. Only 9.5% have full enforcement at p=reject with 100% coverage. The UK trails the global average of 11.2% by 1.7 percentage points.

This gap matters more than ever in 2026. On 31 March 2026 the NCSC retired Mail Check, the free service thousands of UK organisations relied on to monitor DMARC. The safety net is gone, and the responsibility now sits with you.

This guide walks through each step using DmarcDkim.com's tools. You can do each step manually if you prefer, and the manual approach is included, but the tools remove the technical overhead and cut the time to full enforcement from months to weeks.

Why UK organisations lost their safety net in 2026

For almost a decade the NCSC ran Mail Check and Web Check as free services under its Active Cyber Defence programme, launched in 2017. Mail Check gave UK public sector domains visibility into SPF, DKIM, DMARC, MTA-STS, and TLS. It parsed DMARC aggregate reports and flagged misconfigurations that could break legitimate mail or leave a domain open to spoofing.

That era has ended. The NCSC scaled back Mail Check's detailed DMARC aggregate reporting in March 2025, then retired both Mail Check and Web Check outright on 31 March 2026. The move is part of its Active Cyber Defence 2.0 roadmap, which shifts email and web monitoring from government provided tools to the commercial market. Early Warning and DNS Check continue, but the DMARC reporting and monitoring that Mail Check provided does not.

What this means in practice:

  • Public sector bodies no longer receive automatic findings on email authentication. Misconfigurations can now persist unnoticed.

  • The risks Mail Check was built to catch have not gone away. Spoofing and impersonation attempts have grown more sophisticated, not less.

  • Any organisation that leaned on Mail Check needs a replacement source of DMARC aggregate reporting and monitoring. The NCSC itself recommends finding one.

DmarcDkim.com fills exactly this gap. It receives and parses your daily DMARC aggregate reports, tracks SPF, DKIM, and MTA-STS in one place, and flags misconfigurations on a single dashboard. For a former Mail Check user, moving across takes minutes.

What DMARC actually does

DMARC publishes a policy in your DNS that instructs receiving mail servers how to handle messages that fail SPF or DKIM authentication checks. You choose between three modes: p=none (monitor only), p=quarantine (send failures to spam), or p=reject (block failures outright).

At the same time, DMARC generates aggregate reports. Every major mailbox provider, including Google, Microsoft, and Yahoo, sends daily XML reports to an address you specify. These reports show which servers are sending email on your behalf, what percentage pass authentication, and where failures occur.

DMARC does not replace SPF or DKIM. It depends on them. For a message to pass DMARC, either SPF must pass and align with your From domain, or DKIM must pass and align. This is why implementation is a process, not just a DNS record.

Step 1: Check your current status

Before changing anything, find out where you stand.

Using DmarcDkim.com: Run a free check at dmarcdkim.com/dmarc-checkdmarcdkim.com/dmarc-check. Enter your domain and get an instant view of your current DMARC record, SPF configuration, and DKIM status. No sign up required. The check also shows whether your domain is currently vulnerable to spoofing and flags any obvious misconfigurations.

Manually: Look up your DNS TXT records using a command line or any DNS lookup tool. Check for a record at _dmarc.yourdomain.com. Check your SPF record at the root of your domain. Check DKIM by looking up selector._domainkey.yourdomain.com. You will need to know your DKIM selector, which is usually provided by your email platform.

Step 2: Publish a DMARC monitoring record

The first thing to put in place is a DMARC record at p=none. This does not block or filter any mail, it simply tells mailbox providers to start sending you daily reports about who is sending email on behalf of your domain. You cannot fix what you cannot see, and this is how you get visibility.

Using DmarcDkim.com: Sign up at app.dmarcdkim.com and add your domain. The platform generates the correct DMARC record for you and receives and parses your daily aggregate reports automatically, no manual XML handling required. Use the DMARC Generator if you want to build the record yourself before adding it to DNS.

Manually: Publish the following TXT record at _dmarc.yourdomain.com:

v=DMARC1; p=none; rua=mailto:dmarc[at]yourdomain.com

Replace dmarc[at]yourdomain.com with an address you control. You will receive raw XML report files from Google, Microsoft, and others. These require parsing to be useful.

If you want to fully customize your record you can do so in our DMARC Record Generator.

Allow at least a week for reports to accumulate before moving to the next step.

Step 3: Identify all sending sources from your reports

Your aggregate reports will reveal every service sending email as your domain: your primary mail server, marketing platform, CRM, ticketing system, invoicing software, and anything else. This is the data you need before touching SPF or DKIM.

Using DmarcDkim.com: The DMARC Dashboard at app.dmarcdkim.com translates raw aggregate report data into a readable list of sending sources, their authentication pass rates, and their alignment status. You can see at a glance which sources are failing and drill into the detail to understand why.

Manually: Download and parse the XML files from your reporting inbox. For each IP address listed, identify whether it is a legitimate sender you control or authorise.

 

Step 4: Fix SPF and DKIM for each sending source

With your sending sources identified, configure SPF and DKIM for each one. Every legitimate source must pass at least one of these checks and align with your From domain before you can safely enforce DMARC.

Using DmarcDkim.com: Use the SPF Check Tool to verify your SPF record after each change. Use the DKIM Check Tool to confirm DKIM signatures are in place and correct. If your SPF record has grown over time and may be approaching the ten DNS lookup limit, use SPF X-ray to get a full analysis of what your record resolves to, spot duplicate includes and redundant entries, and clean it up properly. The SPF Merge Tool can help combine multiple SPF records into one where needed.

DmarcDkim.com also publishes configuration guides for specific platforms at dmarcdkim.com/setup, covering Microsoft 365, Google Workspace, Mailchimp, HubSpot, Salesforce, and dozens more. If you want hands on help at this stage, every new customer receives a free 30 minute onboarding call with active setup support.

Manually: For SPF, ensure your TXT record at the root domain lists all IP addresses and services that send email on your behalf, ending in ~all or -all. For DKIM, confirm that your email platform has generated a key pair and that the public key is published in DNS. Most platforms have a domain authentication section in their settings.

 

Step 5: Move to p=reject with a controlled pct rollout

Once your reports show consistent pass rates across all legitimate sources (at least 98%), move directly to p=reject. Rather than going via p=quarantine, use the pct parameter to roll out enforcement gradually. This gives you full control without risking legitimate mail being blocked at scale.

Start at pct=5. This applies the reject policy to 5% of failing messages. Watch the reports for any unexpected failures, then increase to 15, 50, and finally 100 as you confirm no legitimate mail is affected.

Using DmarcDkim.com: Update your record according to your custom rollout plan (https://app.dmarcdkim.com/domains/yourdomain.com/protection). The dashboard continues to show aggregate report data during the rollout so you can monitor the effect of each pct increase in real time.

Manually: Update your _dmarc.yourdomain.com TXT record:

v=DMARC1; p=reject; pct=5; rua=mailto:dmarc[at]yourdomain.com

Increase pct progressively. When pct=100 is stable, your domain is fully protected.

 

What UK organisations need to know in 2026

The regulatory and provider picture has tightened at the same time as the NCSC's free tools have gone.

Google and Yahoo required DMARC for bulk senders from February 2024. Microsoft extended the same requirement to Outlook, Hotmail, and Live in May 2025. Organisations sending more than 5,000 messages per day must have SPF, DKIM, and DMARC in place or face delivery failures.

The NCSC still recommends DMARC as part of its email security guidance and drove strong adoption across UK government domains. But with Mail Check retired on 31 March 2026, that adoption now depends on organisations sourcing their own reporting and monitoring. The private sector remains well behind: 73.9% of UK domains monitored by DmarcDkim.com had no effective DMARC protection as of July 2026.

The practical takeaway for UK organisations is simple. The mandates are firmer, the free government safety net is gone, and the responsibility to monitor and enforce sits entirely with you.

 

Frequently asked questions

What replaced NCSC Mail Check?

Nothing from the NCSC. Mail Check and Web Check were retired on 31 March 2026 as part of the Active Cyber Defence 2.0 roadmap, with Early Warning and DNS Check the only related services that continue. The NCSC recommends moving to a commercial DMARC reporting and monitoring tool. DmarcDkim.com receives and parses your daily aggregate reports and tracks SPF, DKIM, and MTA-STS in one dashboard, so a former Mail Check user can restore visibility in minutes.

 

Do I need DMARC if I do not send bulk email?

The mailbox provider mandates apply above 5,000 messages per day. But any domain without DMARC can be spoofed regardless of send volume. Attackers target low volume domains precisely because they are less likely to have protection in place.

 

Will moving to p=reject break my email?

Not if you follow the process. Starting at p=none and using pct for gradual rollout means you catch every legitimate source before full enforcement. The DmarcDkim.com dashboard makes this visible at every stage.

 

What is the SPF ten lookup limit?

SPF allows a maximum of ten DNS lookups during evaluation. Organisations with multiple sending services often exceed this without realising, causing SPF failures even for legitimate mail. SPF X-ray at DmarcDkim.com analyses your full SPF resolution chain and identifies exactly where the problem lies.

 

How long does full implementation take?

With the DmarcDkim.com dashboard and a free onboarding call, four to eight weeks from first record to full p=reject is achievable for most organisations. The main variable is how many sending sources need to be identified and configured. For non sending domains you can go straight to p=reject at 100%.

 

Get started

Run a free DMARC check on your domain now: dmarcdkim.com/dmarc-check

Sign up for the DMARC Dashboard to start monitoring: app.dmarcdkim.com

Book a free 30 minute onboarding call: dmarcdkim.com/contact-us

More articles

Bulletproof emails with DMARC

Check domain and follow the instructions to nail down your DMARC configuration.
No expert knowledge needed!