ShouldNational Cyber Security Centre (NCSC)

DMARC email record

A DMARC record on every email domain the school or trust holds, which helps stop criminals sending emails that appear to come from it. It should move to a policy of reject, and nothing on the website is involved.

Check this on my website

Who it applies to

Published on
School and trust websites
School type
Academies and maintained schools
School stage
All stages, from early years to sixth form
Does not apply to
No school types are excluded

When is it due?

Renewal
No fixed date

The official sources set no renewal date. Keep it accurate whenever it changes.

What's needed

Publish a DMARC record in the DNS for the school's email domain, starting at p=none and moving to quarantine or reject (guidance says schools should).

What it must contain

4 parts
  • Has a DMARC record on every domain, including parked domainsShould
  • Publishes the DMARC record as a TXT recordShould
  • Sets the DMARC policy to rejectShould
  • Gives an address for DMARC aggregate reportsGood practice

What the official sources say

Set out in 3 official sources:

NCSC: implement a DMARC policy of none

Version 2026-09-13

  • All of your domains, including parked domains , should have DMARC records in place, regardless of whether the domain is used for email or not.

    Should§ Page 7 of 14 > Implement a DMARC policy of ‘none’ (introduction)

  • Your DMARC record name is: _dmarc.yourdomain.gov.uk It should be configured as a TXT record, with an initial value similar to this: v=DMARC1;p=none;rua=mailto: [email protected]

    Should§ Page 7 of 14 > How to create the DMARC record

Show 4 more from this source
  • We recommend you apply DMARC gradually, iterating your DMARC configuration over time. Start by implementing a DMARC policy of ‘ none ’. You can view this policy as a ‘monitoring phase’, during which the DMARC processing tool you selected in Step 1 collects and reports on which systems and services are sending emails from your domains. This does not interfere with your email traffic in any way.

    Good practice§ Page 7 of 14 > Implement a DMARC policy of ‘none’ (introduction)

  • “rua” is a comma separated list of URI(s) for aggregate report delivery. This report contains details of the emails being sent from your domain, including whether they passed or failed the SPF and DKIM authentication checks. You can include up to 2 email addresses for which to send the aggregated data reports. If you’re eligible to use Mail Check and do, you need to include our email address, to ensure that you send the aggregated data to Mail Check – details are provided within Mail Check.

    Good practice§ Page 7 of 14 > How to create the DMARC record

  • In this ‘monitoring only phase’ we recommend keeping your DMARC record as simple as shown above. You do not need to add additional ‘DMARC tags’ (see https://tools.ietf.org/html/rfc7489#page-17 ) at this stage.

    Good practice§ Page 7 of 14 > How to create the DMARC record > Note

  • Semi-colons are used to separate the tags. Commas are used to separate multiple email addresses (where more than one is used). You do not need a semi-colon (or full stop) at the end of the DMARC record.

    Good practice§ Page 7 of 14 > How to create the DMARC record

NCSC: reject spoof emails (DMARC p=reject)

Version 2026-09-13

  • As soon as you are confident DKIM and SPF are continuing to work correctly, you should move to a DMARC policy of ‘reject’ .

    Should§ Page 12 of 14 > 5. Reject spoof emails (introduction)

  • Having a DMARC policy of ‘ reject ’ on all of your domains is the best way to prevent spoofing of your email. The goal for this section is to help you get to that point.

    Good practice§ Page 12 of 14 > 5. Reject spoof emails (introduction)

Show 2 more from this source
  • An example record applied to 50% of your email looks like this: v=DMARC1;p=reject;sp=reject;fo=1;pct=50;rua=mailto: [email protected]

    Good practice§ Page 12 of 14 > Iterating a DMARC record

  • We recommend you now update your DMARC record to a policy of p=reject and apply it to a small percentage of your email.

    Good practice§ Page 12 of 14 > Iterating a DMARC record

Email security and anti-spoofing (SPF, DKIM, DMARC)

Version 2026-09-13

  • Domain-based Message Authentication, Reporting and Conformance (DMARC) allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks. This includes untrusted emails, which should be discarded. DMARC also generates reports, which you can use to understand how your email is being handled.

    Good practice§ Page 1 of 14 > introduction, point 1 (In summary)

Questions schools ask

Does every school have to publish the DMARC email record?

The official sources we check set no requirement for academies. The official sources we check set no requirement for maintained schools.

When does the DMARC email record need to be published?

Renewal: No fixed date. The official sources set no renewal date. Keep it accurate whenever it changes.

What must the DMARC email record include?

Has a DMARC record on every domain, including parked domains; Publishes the DMARC record as a TXT record; Sets the DMARC policy to reject; Gives an address for DMARC aggregate reports.

Where does the requirement for the DMARC email record come from?

It is set out in NCSC: implement a DMARC policy of none, NCSC: reject spoof emails (DMARC p=reject) and Email security and anti-spoofing (SPF, DKIM, DMARC).

Changes to the official sources

The sources for this item do not publish dated change notes. Their current versions are listed above.

We last checked these sources on 21 September 2026.

Is this on your school's website?

We check your site the way an inspector or a parent would find it: page by page, against the official wording of each requirement. If it's there, you get the page and the words we found. If it isn't, you get every place we looked.

Check this one requirement free, or scan your whole site against every requirement.

Any format works: .co.uk, .sch.uk, .org.uk or .com.

We email the result here. Privacy notice

Free: check up to 3 requirements a year, results by email. Paid: every requirement checked, re-checked after you fix it, and monitored all year.

Or scan your whole site free →
Official wording that does not apply to schools (1)
Within 24 hours of publishing your records you’ll start receiving email reports from major email recipient domains . These will come to the two addresses you specified in your DMARC record.
NCSC: implement a DMARC policy of none§ Page 7 of 14 > DMARC ReportsVersion 2026-09-13ncsc.gov.uk ↗

Official sources last checked 21 September 2026 · register version 1.0.4