NCSC Mail Check has closed: what small businesses and charities can use instead
NCSC Mail Check and Web Check closed on 31 March 2026. What that means for a small business or charity's email and website, and what to use instead.
By Doug Hall · Updated
- The NCSC retired Mail Check and Web Check on 31 March 2026. Mail Check had already stopped processing DMARC reports on 24 March 2025.
- Your records still work, but nobody is watching them or reading the reports for you any more.
- Check where your DMARC reports go, then choose a free one-off check or a monitoring service that suits your size.
What happened, and when
Mail Check was the National Cyber Security Centre's free service for checking an organisation's email security: SPF, DKIM, DMARC and TLS. Web Check did the same for websites. Both were part of the NCSC's Active Cyber Defence programme, and the NCSC's own guidance described Mail Check as available to any UK organisation with a domain name, so plenty of small businesses and charities signed up.
Both were wound down in two steps:
| Date | What changed | Source |
|---|---|---|
| 24 March 2025 | Mail Check stopped DMARC aggregate reporting, DMARC Insights and the related DKIM checks, and TLS reporting (TLS-RPT). Checks of DMARC policy, SPF, MTA-STS and inbound TLS carried on. | NCSC Mail Check update |
| 6 November 2025 | The NCSC announced that Mail Check and Web Check would be retired. | NCSC blog |
| 31 March 2026 | Both services retired. Users no longer receive findings from either. | NCSC blog |
The NCSC's reason is that the market has caught up: there are now commercial products for organisations of every size, and it aims to deliver services only where the market can't. It points organisations to its buyer's guide for external attack surface management tools and to its free Check your email security tool.
What it means for your domain
Nothing broke on 31 March. Mail Check never hosted your records; it read them from public DNS and told you when something was wrong. So your email keeps flowing exactly as before.
What you lost is the watching:
- Nobody tells you if someone changes or deletes your SPF or DMARC record, or if a new service pushes SPF over its 10-lookup limit.
- If your DMARC reports went to Mail Check, they have been going nowhere useful since March 2025. That matters most if you were still at
p=none: the reports are how you find out which services send as you before tightening the policy. - From Web Check, nobody warns you about an expiring or misconfigured certificate on your website.
First job: check where your DMARC reports go
Look up your domain's DMARC record with the free DMARC checker, or ask whoever manages your DNS. The part to look at is rua=, the address aggregate reports are sent to:
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.org.uk
If the rua still contains the address Mail Check gave you, replace it. You can point it at a mailbox you own (and read the XML yourself), or at a reporting service, which will give you its own address. A record can list more than one address, separated by commas, so you can run a new service alongside an old one while you switch. If there's no rua at all, add one: see how to fix missing DMARC reporting.
A reporting address on a different domain from yours needs that domain to publish a small authorisation record, or receivers won't send to it. Any reporting service handles that for you. If you're curious what the reports contain, our guide on how to read a DMARC report goes through one line by line.
What Mail Check and Web Check covered
To replace them properly, it helps to list what they did for you. Between them, they covered roughly this:
| Area | What to keep an eye on | Free tool to check it now |
|---|---|---|
| SPF | Present, one record only, under 10 lookups | SPF checker |
| DKIM | A key for each sending service, of a sensible length | DKIM checker |
| DMARC | Policy, reporting address, progress towards reject | DMARC checker |
| MTA-STS and TLS-RPT | Whether mail to you must arrive encrypted, and reports on it | MTA-STS checker |
| Website certificate | Expiry and validity on the bare domain and www | Domain health check |
Our free domain health check runs all of these at once and adds the domain's own expiry date: a lapsed registration takes the website and email down together.
Your options, from free to paid
The NCSC's Check your email security. Still running, free, and no sign-up: type in a domain and it checks anti-spoofing (SPF, DKIM, DMARC) and email privacy (encryption in transit). It's a one-off check, so it won't tell you when something changes next month, but it's a good second opinion. Check your email security.
Free one-off tools. Ours, and many others', check a domain on demand. Fine if you remember to run them. Most people don't, which is why Mail Check was useful in the first place.
Reading the reports yourself. Point rua at a mailbox you own and open the attachments. It costs nothing but time, and the files are compressed XML. Our DMARC report analyser turns one into a readable table without storing it, which is fine for an occasional look.
A monitoring service. Checks every day, reads the DMARC reports for you and alerts you when something changes. The dmarc.org products and services list, which the NCSC's own guidance on choosing a tool links to, is a good place to compare. Domain Health Hub is one of these: it covers the email records, DMARC and TLS reports, certificates and the domain's expiry, from £15 a month for up to 25 domains.
The NCSC's Early Warning service also carries on, and any UK organisation with a domain name or static IP address can sign up (NCSC services). It alerts you to suspicious activity linked to your network, such as a compromised machine. It doesn't check your email records, so it complements the options above rather than replacing Mail Check.
Choosing a tool
For a small business or charity, the questions that matter:
- Does it check daily and tell you when something changes? That's the gap Mail Check left.
- Does it read DMARC reports and explain them in plain English? Raw counts by IP address won't help a trustee or an office manager.
- Does it cover the website and domain too? Web Check has gone as well; one tool for both is simpler.
- Where is the data held? DMARC reports are about your mail flow. UK or EU hosting keeps things simple under UK GDPR.
- Is the price fixed? Some services charge by email volume, which is hard to predict. A fixed price per domain is easier to budget.
If an IT company or web agency looks after your domain, ask them first: they may already monitor it, or be glad to add it to what they do for you.
A one-afternoon plan
- List every domain you own, including old names and the .org.uk beside the .org. Unused domains can be spoofed too, and need
p=reject. - Run a free check on each, and note anything marked as failing.
- Change any
ruastill pointing at Mail Check, as above. - Fix the urgent items: a missing DMARC record, two SPF records, a certificate close to expiry. Each failure links to a step-by-step fix.
- Decide how it will be watched from now on: a reminder to re-run free checks monthly, or a service that does it daily.
- If you're still at
p=none, plan the move to reject using the reports. The DMARC guide explains the steps.
Doing this for clients? Domain Health Hub checks every client domain each day and puts the results in a monthly report card with your logo. Start a free trial; no card needed.
Questions
Will my email stop working now Mail Check has closed?
No. Mail Check only watched your records; it didn't serve them. Your SPF, DKIM and DMARC records are in your own DNS and carry on working.
Do I need to remove the Mail Check address from my DMARC record?
Yes, it's worth doing. Mail Check stopped processing aggregate reports in March 2025, so reports sent there aren't helping you. Replace it with an address that someone or something actually reads.
Is there still anything free from the NCSC?
Yes. Check your email security is a free one-off check of any domain, with no sign-up. Early Warning, which tells you about suspicious activity seen on your network, is still open to UK organisations with a domain name or static IP address.
We're a small charity with one domain. Do we need a paid service?
Not necessarily. If your DMARC policy is already at reject and nothing changes, a periodic free check may be enough. If you're still at p=none, you need the reports read to move forward safely, and that's where a service earns its keep.
Watch every client's domains, every day.
Reports read for you, and a monthly report card your clients will understand.