DMARC services for UK organisations
ShieldMarc is a UK-built DMARC monitoring platform run by ShieldMarc Ltd, a company registered in England and Wales. This page sets out what the service covers, what it costs in pounds, where the data is held and what is not included, so a UK IT team or managed service provider can judge the fit without a sales call.
What a DMARC service has to do
A DMARC record on its own changes nothing. It becomes useful once the aggregate reports it requests are collected and read. Receiving providers send those reports as compressed XML, at least daily, from dozens of separate sources. The job of a monitoring service is to take that feed, deduplicate it, identify every sender behind it, and turn it into a decision: whether the domain can move from p=none to p=quarantine to p=reject without cutting off legitimate mail.
ShieldMarc parses aggregate and forensic reports, names each sender it finds, and tracks a report-driven route to enforcement rather than a checkbox exercise. Alongside DMARC it runs 16 outside-in checks across SPF, DKIM, DMARC, MTA-STS, TLS-RPT, DNSSEC, CAA, TLS and registration hygiene, and grades every domain A+ to F on the result.
What setup involves
Add a domain, change one DNS record, and DMARC reports start landing in the dashboard within 24 to 48 hours. There is no agent, no proxy and no traffic rerouting, so nothing sits in your mail flow. Certificate, DNS, uptime and lookalike monitoring start the moment a domain is added, because those checks read public records rather than report data.
What it costs
Pricing is published rather than quoted: £0, £50 and £100 per month on annual billing, with Enterprise on application. The free tier covers a single domain. The MSP plan carries 100 brand-grouped domain slots for £100 per month on annual billing, which works out at about £1 per domain per month, and brand grouping means the TLD variants of one brand take a single slot rather than one each. Paid plans come with a 30-day free trial that needs no card, a 30-day money-back period on annual billing, and cancellation at any time. The current figures are on the pricing page.
Where your data is held
ShieldMarc is a UK owned and run company. All customer monitoring data is EU hosted by default, and dedicated UK hosting is available on request for organisations that require UK data residency, supplied on an enterprise plan. AI-assisted features default to US model providers under API-only terms that prohibit training on customer data, and EU AI routing is available on request. ShieldMarc Ltd is registered in England and Wales, company number 17352242, registered office 66 Paul Street, London, EC2A 4NA. The full picture is on the security and trust page.
Replacing NCSC Mail Check
NCSC Mail Check was retired on 31 March 2026. UK public sector teams that relied on it now have to source DMARC aggregate report processing commercially, while NCSC continues to recommend that public sector domains reach an enforced policy of p=reject. ShieldMarc supports that through report-driven progression, with tailored DPIA and procurement documentation available on request. The practical steps are set out in our Mail Check migration page.
For managed service providers
The MSP plan is a multi-domain plan, not a channel programme. It gives 100 brand-grouped domain slots, unlimited team members and unlimited monitors, and expands in blocks of 50 domains. It is worth being clear about what is missing: ShieldMarc does not publish a reseller or partner programme, and there are no PSA integrations today. If a formal partner tier or a PSA connector is a hard requirement for you, raise it before you commit rather than after. How the day-to-day work looks across many client domains is covered in our guide to DMARC for MSPs.
Evidence rather than claims
Every quarter we re-scan the same 192 UK Managed Service Providers and grade them with the same outside-in checks we run for customers. In Q2 2026 the average MSP scores a C, only 6% earn an A, and just 18% publish MTA-STS. The data and the methodology are both public, and the audit covers providers who are not customers. You can read the Q2 2026 UK MSP DMARC audit in full.
Where to start
The quickest way to judge any of this is to run the same outside-in scan an attacker or an underwriter would run against your own domain, which needs no account and takes about ten seconds. From there you can add the reporting address and let a week of real report data settle the question.