Should: Recommended in official guidance, such as the DfE's. Not a legal requirement in itself.National Cyber Security Centre (NCSC)

DMARC record for your school's email

A DMARC record on your email domains helps stop criminals sending emails that look as if they come from your school.

Check this on my website

Who it applies to

Published on
School and trust websites
School type
Academies and maintained schools
School stage
All stages, from early years to sixth form
Does not apply to
No school types are excluded

When it's due

Keep it up to date

There's no fixed date. Update it whenever something changes.

What's needed

Set up a DMARC TXT record on every email domain you hold, including parked domains, with an address for aggregate reports, starting at p=none and moving to reject.

What it must contain

4 parts
  • Has a DMARC record on every domain, including parked domainsShould: Recommended in official guidance, such as the DfE's. Not a legal requirement in itself.
  • Publishes the DMARC record as a TXT recordShould: Recommended in official guidance, such as the DfE's. Not a legal requirement in itself.
  • Sets the DMARC policy to rejectShould: Recommended in official guidance, such as the DfE's. Not a legal requirement in itself.
  • Gives an address for DMARC aggregate reportsGood practice: Recommended as good practice. Not required.

What the official sources say

Set out in 3 official sources:

NCSC: implement a DMARC policy of none

Version 2026-09-13

  • All of your domains, including parked domains , should have DMARC records in place, regardless of whether the domain is used for email or not.

    Should: Recommended in official guidance, such as the DfE's. Not a legal requirement in itself.§ Page 7 of 14 > Implement a DMARC policy of ‘none’ (introduction)

  • Your DMARC record name is: _dmarc.yourdomain.gov.uk It should be configured as a TXT record, with an initial value similar to this: v=DMARC1;p=none;rua=mailto: [email protected]

    Should: Recommended in official guidance, such as the DfE's. Not a legal requirement in itself.§ Page 7 of 14 > How to create the DMARC record

Show 4 more from this source
  • We recommend you apply DMARC gradually, iterating your DMARC configuration over time. Start by implementing a DMARC policy of ‘ none ’. You can view this policy as a ‘monitoring phase’, during which the DMARC processing tool you selected in Step 1 collects and reports on which systems and services are sending emails from your domains. This does not interfere with your email traffic in any way.

    Good practice: Recommended as good practice. Not required.§ Page 7 of 14 > Implement a DMARC policy of ‘none’ (introduction)

  • “rua” is a comma separated list of URI(s) for aggregate report delivery. This report contains details of the emails being sent from your domain, including whether they passed or failed the SPF and DKIM authentication checks. You can include up to 2 email addresses for which to send the aggregated data reports. If you’re eligible to use Mail Check and do, you need to include our email address, to ensure that you send the aggregated data to Mail Check – details are provided within Mail Check.

    Good practice: Recommended as good practice. Not required.§ Page 7 of 14 > How to create the DMARC record

  • In this ‘monitoring only phase’ we recommend keeping your DMARC record as simple as shown above. You do not need to add additional ‘DMARC tags’ (see https://tools.ietf.org/html/rfc7489#page-17 ) at this stage.

    Good practice: Recommended as good practice. Not required.§ Page 7 of 14 > How to create the DMARC record > Note

  • Semi-colons are used to separate the tags. Commas are used to separate multiple email addresses (where more than one is used). You do not need a semi-colon (or full stop) at the end of the DMARC record.

    Good practice: Recommended as good practice. Not required.§ Page 7 of 14 > How to create the DMARC record

NCSC: reject spoof emails (DMARC p=reject)

Version 2026-09-13

  • As soon as you are confident DKIM and SPF are continuing to work correctly, you should move to a DMARC policy of ‘reject’ .

    Should: Recommended in official guidance, such as the DfE's. Not a legal requirement in itself.§ Page 12 of 14 > 5. Reject spoof emails (introduction)

  • Having a DMARC policy of ‘ reject ’ on all of your domains is the best way to prevent spoofing of your email. The goal for this section is to help you get to that point.

    Good practice: Recommended as good practice. Not required.§ Page 12 of 14 > 5. Reject spoof emails (introduction)

Show 2 more from this source
  • An example record applied to 50% of your email looks like this: v=DMARC1;p=reject;sp=reject;fo=1;pct=50;rua=mailto: [email protected]

    Good practice: Recommended as good practice. Not required.§ Page 12 of 14 > Iterating a DMARC record

  • We recommend you now update your DMARC record to a policy of p=reject and apply it to a small percentage of your email.

    Good practice: Recommended as good practice. Not required.§ Page 12 of 14 > Iterating a DMARC record

Email security and anti-spoofing (SPF, DKIM, DMARC)

Version 2026-09-13

  • Domain-based Message Authentication, Reporting and Conformance (DMARC) allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks. This includes untrusted emails, which should be discarded. DMARC also generates reports, which you can use to understand how your email is being handled.

    Good practice: Recommended as good practice. Not required.§ Page 1 of 14 > introduction, point 1 (In summary)

Questions schools ask

Do schools need a DMARC record?

For academies and maintained schools, it's recommended in official guidance, but isn't a legal requirement in itself.

What does a school's DMARC record need to include?

Has a DMARC record on every domain, including parked domains; Publishes the DMARC record as a TXT record; Sets the DMARC policy to reject; an address for DMARC aggregate reports.

When do we need to check our DMARC record?

Keep it up to date. There's no fixed date. Update it whenever something changes.

Where does the requirement for the DMARC email record come from?

It is set out in NCSC: implement a DMARC policy of none, NCSC: reject spoof emails (DMARC p=reject) and Email security and anti-spoofing (SPF, DKIM, DMARC).

Recent changes to the official guidance

The official sources for this requirement don't publish dated change notes. We check them for changes ourselves.

We last checked these sources on 21 September 2026.

Get an email when the requirements change

The DfE updates what schools must publish most years. We'll tell you what changed.

A few emails a year. Unsubscribe at any time. Privacy notice

Is this on your school's website?

Enter your school email address and we'll check your website for this requirement.

It's free, and the result arrives by email.

We email the result here. Privacy notice

Free: up to 3 single checks a year. Paid: every requirement, audited every month. See prices →

Or audit your whole website for free →
Official wording that does not apply to schools (1)
Within 24 hours of publishing your records you’ll start receiving email reports from major email recipient domains . These will come to the two addresses you specified in your DMARC record.
NCSC: implement a DMARC policy of none§ Page 7 of 14 > DMARC ReportsVersion 2026-09-13ncsc.gov.uk ↗

Official sources last checked 21 September 2026 · register version 1.0.4