Skip to main content
ShieldMarc
UrgentGuide

NCSC Mail Check Has Retired: What UK Organisations Should Do Now

NCSC retired its Mail Check and Web Check services on 31 March 2026. If your organisation relied on Mail Check for DMARC monitoring, email anti-spoofing checks, or TLS reporting, you need to find an alternative before you lose visibility entirely. This page was verified against the NCSC announcement on 1 May 2026.

Updated June 2026

What happened

The NCSC announced the retirement of both Mail Check and Web Check as part of its Active Cyber Defence 2.0 roadmap. These services, which had been available to UK organisations for over eight years, stopped delivering findings on 31 March 2026.

The NCSC's published rationale is that there is now a wide commercial market for External Attack Surface Management (EASM) products that cover what Mail Check and Web Check provided, plus additional features. The announcement recommends transitioning to a commercial EASM product before retirement and points to the NCSC's own EASM buyer's guide. NCSC is refocusing on areas where being part of GCHQ provides an advantage that the private sector cannot replicate.

Timeline of changes

DateChange
2017 onwardsMail Check available to UK public-sector and registered private-sector organisations, providing DMARC, SPF, DKIM and TLS posture findings.
Late 2025NCSC announced the retirement of Mail Check and Web Check, recommending transition to commercial EASM products before the cut-off.
31 March 2026Mail Check and Web Check retired. From this date, NCSC users no longer receive findings related to those services.

Still available: Early Warning and DNS Check continue through your MyNCSC account. The NCSC also offers a free email security checker for quick one-off checks, though it does not provide ongoing monitoring.

Why this matters

Without ongoing DMARC monitoring, organisations lose visibility into:

  • Who is sending email on your behalf. DMARC aggregate reports (RUA) show every IP address that sends mail using your domain. Without them, you cannot detect unauthorised senders or shadow IT services.
  • Whether authentication is passing. SPF and DKIM can break silently when DNS records change, providers update their infrastructure, or new sending services are added. Without monitoring, failures go unnoticed.
  • Whether your domain is being spoofed. DMARC reports reveal phishing attempts using your domain. Without this data, attacks happen in the dark.
  • Progress towards enforcement. Moving from p=none to p=reject requires confidence that all legitimate mail passes authentication. Without data, you are guessing.

Our UK MSP DMARC Audit: Q1 2026 (a sample of 192 UK Managed Service Providers, methodology published in the linked report) found that 95% have a DMARC record published, but only 36% have reached p=reject. The gap between having a record and enforcing it is where monitoring matters most.

Step-by-step migration guide

Whether you managed one domain or hundreds through Mail Check, here is how to maintain your email security visibility.

1. Audit your current setup

Before choosing a replacement, understand where you stand. Run each of your domains through a free DMARC Checker to see your current DMARC policy, SPF configuration, and overall grade. For a broader view covering SSL, DNS, DNSSEC, impersonation risk, and domain registration, use the Security Grade. You should also check your email transport security with our MTA-STS Checker and scan for impersonation risks with the Lookalike Domain Scanner.

Document each domain's current state:

  • DMARC policy level (none, quarantine, or reject)
  • Whether a RUA (aggregate reporting) address is configured
  • SPF record and number of DNS lookups
  • DKIM signing status
  • Any alternate or parked brand domains

2. Choose a DMARC monitoring provider

Look for a provider that offers:

  • DMARC aggregate report (RUA) processing and visualisation
  • SPF and DKIM alignment monitoring
  • Alerting when authentication fails or records change
  • Support for multiple domains (especially if you are an MSP)
  • EU data residency with a UK-based company

ShieldMarc was built specifically for this transition. We offer DMARC reporting, SSL monitoring, domain trust scoring, and domain security tracking in a single dashboard, with a free plan that requires no credit card.

3. Update your DMARC RUA address

If your DMARC record currently sends aggregate reports to a Mail Check address (or any NCSC endpoint), you need to update the rua= tag to point to your new provider. For example:

v=DMARC1; p=quarantine; rua=mailto:your-new-rua@provider.example

Most providers give you a unique RUA address during onboarding. Update the TXT record at _dmarc.yourdomain.com in your DNS.

Not sure what DMARC, RUA, or aggregate reports mean? Read our complete guide to DMARC.

4. Verify with a free check

After updating your DNS, allow 24-48 hours for propagation, then run your domain through the DMARC Checker again to confirm the new RUA address is in place and all records are valid. If you need to create a new DMARC record from scratch, use the DMARC Generator to build one with the correct policy and reporting address. Once reports start arriving, use the DMARC Report Viewer to inspect the raw XML in a human-readable format without uploading anything to a server.

5. Do not forget your other domains

Many organisations have parked, alias, or legacy domains that also need DMARC protection. Our UK MSP audit found that 80% of UK MSPs leave their alternate brand domains unprotected. Every domain you own can be used for spoofing. Non-sending domains should have:

v=spf1 -all
v=DMARC1; p=reject; rua=mailto:your-rua@provider.example

Use the Security Grade tool to scan your domain across every security layer.

Specific guidance for MSPs

If you are a Managed Service Provider managing email security for multiple clients, the Mail Check retirement creates both a risk and an opportunity.

The risk:clients who relied on NCSC tooling may assume “someone is watching” when in fact nobody is. Proactively contact any client whose DMARC reporting pointed to an NCSC address.

The opportunity: DMARC monitoring is a natural addition to your managed security offering, and our guide on running DMARC as a managed service walks through how to operate it across a client base now that Mail Check is gone. It is a recurring service that directly protects your clients from impersonation and phishing, and the data it generates (authentication pass rates, sender inventory, policy compliance) provides clear reporting value.

ShieldMarc is built for multi-tenant management with per-organisation dashboards, domain grouping, and role-based access. See our pricing for MSP-friendly plans.

Migration checklist

  • 1Audit all domains currently registered in Mail Check
  • 2Run each domain through a free DMARC checker to document current state
  • 3Choose a DMARC monitoring provider with RUA processing
  • 4Update the rua= tag in each domain's DMARC record
  • 5Wait 24-48 hours for DNS propagation
  • 6Verify the new configuration with a free check
  • 7Add DMARC records to any parked, alias, or non-sending domains
  • 8Set a calendar reminder to review DMARC reports monthly

Frequently asked questions

What happens now that NCSC Mail Check is retiring?

Mail Check stopped delivering findings on 31 March 2026, so organisations that relied on it no longer receive DMARC, SPF, DKIM or TLS posture reports through MyNCSC. Your DMARC records keep working, but if your rua= tag pointed at an NCSC endpoint you are now collecting no aggregate data and have lost visibility into who is sending mail as your domain. The NCSC recommends moving to a commercial monitoring or External Attack Surface Management product before you lose that insight.

What can I use instead of NCSC Mail Check?

Use a commercial DMARC monitoring service that ingests your aggregate (RUA) reports, tracks SPF and DKIM alignment, alerts on authentication failures and record changes, and supports multiple domains. ShieldMarc is a UK-owned option built for exactly this transition, EU hosted by default with UK hosting available on request, and offers a free Starter tier so you can replace Mail Check at no cost. The NCSC email security checker still works for one-off spot checks, but it does not provide ongoing reporting.

When did NCSC Mail Check retire?

NCSC Mail Check, alongside Web Check, retired on 31 March 2026 as part of the Active Cyber Defence 2.0 roadmap. From that date NCSC users stopped receiving findings related to those services. You can confirm the dates and rationale in the NCSC retirement announcement.

What should UK councils do about DMARC after Mail Check retirement in March 2026?

UK councils and other public sector bodies should audit every domain they own, move their DMARC reporting address to a replacement monitoring provider, and continue the report-driven progression from p=none to p=quarantine and then p=reject once reports confirm legitimate mail passes authentication. Early Warning and DNS Check remain available through MyNCSC, but they do not replace DMARC aggregate reporting. Choosing a UK-owned provider with EU data residency (and UK hosting on request) keeps the service aligned with public sector procurement and data handling expectations.

Is there a free alternative to NCSC Mail Check?

Yes. ShieldMarc offers a free Starter tier (£0 per month) that processes DMARC aggregate reports for a single domain with no credit card required, so a council, charity or small team can keep monitoring after Mail Check has gone. Paid plans at £50 and £100 per month add more domains and features for MSPs and multi-domain IT teams. The free NCSC email security checker still exists for ad-hoc checks but does not provide continuous report processing or alerting.

Start your migration today

Check your domain's current email security posture for free, then set up ongoing monitoring in under five minutes.