DMARC monitoring UK
DMARC monitoring for UK organisations, billed in pounds.
DMARCTrust turns the daily DMARC reports Gmail, Microsoft, and 90+ other providers send about your domain into readable charts and DNS alerts. Aggregate reports are free for 1 domain; paid plans start at £13.90/mo in GBP.
- Built by ex-Mailjet deliverability engineers
- EU or US data hosting, chosen at signup
- GDPR-ready data handling
- No credit card to start
Built by Marc Lelu, ex-Mailjet deliverability engineer. Last updated August 27, 2026.
DMARC for UK business: the sender deadlines have already passed
The two mailbox providers that dominate UK inboxes now require DMARC from bulk senders, and both requirements are already in force.
Google — since 1 February 2024
Google's Email sender guidelines require a DMARC record from any sender that sends close to 5,000 or more messages to personal Gmail accounts within 24 hours. p=none satisfies the requirement, and Google states the bulk-sender classification is permanent. Below that volume, every sender must still authenticate with SPF or DKIM.
Microsoft — since 5 May 2025
Domains sending more than 5,000 messages a day to Outlook consumer addresses (outlook.com, hotmail.com, live.com) need SPF and DKIM to pass, plus a DMARC record of at least p=none aligned with SPF or DKIM. Mail that fails is rejected with 550 5.7.515.
These are provider rules, not UK law, but there is no UK carve-out: a Manchester retailer sending order confirmations hits exactly the same wall as a sender anywhere else. The only way to know whether your domain clears the bar — and whether anyone is spoofing it — is to read the DMARC reports those providers already send about you.
What the NCSC tells UK organisations about DMARC
The National Cyber Security Centre's Email security and anti-spoofing guidance tells organisations to implement SPF, DKIM, and DMARC on all of their domains, including domains hosted on common cloud email providers. It recommends starting with a DMARC policy of p=none — explicitly described as a monitoring phase — and applying DMARC gradually, iterating the configuration over time. Within 24 hours of publishing your records, reports from major recipient domains start arriving.
For government itself the bar is firmer: the GOV.UK guidance on setting up government email services securely states that DMARC policies must be in place, published at p=none and rising to p=quarantine or p=reject during implementation.
Mail Check is retired — bring your own monitoring
The NCSC retired Mail Check (and Web Check) on 31 March 2026, after removing its key reporting features in March 2025. Its stated reason: the commercial market now covers and extends what the services did, and the NCSC only delivers solutions where the market cannot. Its lighter replacement, the Check your cyber security service, runs point-in-time checks — it does not collect or analyse your DMARC aggregate reports.
That continuous-monitoring role is exactly what DMARCTrust does: a dedicated reporting address for your rua= tag, automatic parsing of every report, per-source alignment breakdowns, and alerts when your DNS records change or failures spike.
DMARC compliance UK: what is actually required
"Is DMARC mandatory?" has a different answer depending on who is asking. Here is the honest table:
| Framework | DMARC status |
|---|---|
| UK government email (GOV.UK secure email guidance) | Required — p=none rising to p=quarantine or p=reject. |
| Google and Microsoft bulk-sender rules | Required at 5,000+ messages/day to their consumer domains — p=none minimum. |
| NCSC email security guidance | Recommended for every organisation, on every domain. |
| Cyber Essentials v3.2 (Willow) | Not required. The five controls are firewalls, secure configuration, security update management, user access control, and malware protection — DMARC is not among them. It complements a certification rather than being part of it. |
| UK GDPR | No DMARC mandate. For the data you hand to a monitoring provider, DMARCTrust lets you choose an EU or US data region at registration. |
In short: nothing forces a UK SMB to publish a DMARC record today — except that the two providers delivering most of its customers' mail already do, and the national cyber authority says it should.
Check your domain's DMARC posture now
Free, no signup: see whether your domain publishes DMARC, SPF, and BIMI records, and what they say.
We will generate a shareable URL for your domain.
Try popular examples: google.com, amazon.com, booking.com
DMARC monitoring UK pricing, in pounds
These are the prices UK customers are billed — pounds sterling, not a converted display. Annual billing gives you 2 months free.
Free
£0
- 1 domain
- Dedicated reporting address
- 50 detailed aggregate reports/month
- 7-day detail retention
Starter
£13.90/mo
- 2 domains
- Unlimited reports
- 90-day detail retention
- Failure reports and DNS change alerts
- TLS-RPT and API access
Pro
£35.90/mo
- 5 domains
- 180-day detail retention
- SPF Optimizer
- Hosted MTA-STS
Extra domains are £9/mo each on any paid plan. Full details on the pricing page.
Works alongside
Frequently asked questions
- Is DMARC a legal requirement in the UK?
- No UK law requires private-sector organisations to publish a DMARC record. UK government email services must implement DMARC under the GOV.UK secure email guidance, starting at p=none and rising to quarantine or reject. For everyone else the pressure is commercial: Google and Microsoft now require DMARC from bulk senders, and the NCSC recommends it for every organisation.
- Is DMARC required for Cyber Essentials?
- No. The Cyber Essentials v3.2 (Willow) requirements cover five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. DMARC is not one of them. The NCSC recommends SPF, DKIM, and DMARC in its separate email security and anti-spoofing guidance, so DMARC complements a Cyber Essentials certification rather than being part of it.
- What happened to NCSC Mail Check?
- The NCSC retired Mail Check (and Web Check) on 31 March 2026, saying the commercial market now covers and extends what the services did. Key reporting features had already been removed in March 2025. The NCSC now points organisations to commercial tooling and to its lighter-weight Check your cyber security service, which runs one-off checks rather than continuous DMARC report monitoring.
- Does DMARCTrust bill in pounds?
- Yes. UK customers are billed in GBP: Starter is £13.90 per month for 2 domains, Pro is £35.90 per month for 5 domains, and extra domains are £9 per month each. Annual billing gives you 2 months free.
- Where is my data stored?
- You choose a preferred data region, European Union or United States, when you register, and you can change it later in your account settings. That choice covers the storage of your account data and supports GDPR and UK GDPR data-residency requirements.
- Is DMARC monitoring free?
- Yes, for 1 domain. The free plan includes your dedicated reporting address, automatic XML parsing, the dashboard, and basic DNS status checks, with 7 days of detail retention plus a 2-day grace period. Paid plans add more domains, longer retention, failure reports, and DNS change alerts.
- Do I need to give DMARCTrust access to my mailbox?
- No. You publish our reporting address as your DMARC rua tag. Mail providers send reports to us directly. We never touch your existing mailbox.
Start free DMARC monitoring for your UK domain
One DNS record. Reports arrive within 24 hours. Billed in pounds when you upgrade.