Prepare for the Mail Check deadline

The National Cyber Security Centre (NCSC) is modifying Mail Check services to discontinue certain features, such as DMARC aggregate reporting, while continuing others. These changes aim to expand Mail Check’s accessibility to all UK-based organisations and manage service complexity and costs. Public sector organisations relying on Mail Check for DMARC aggregate reporting should seek an alternative service provider before 24 March 2025.

Without adopting an alternative provider, such as Red Sift OnDMARC, security teams risk being exposed to phishing and spoofing attempts, Business Email Compromise (BEC) attacks, and misconfigured security. The main changes and what to expect include:

  • Discontinuation of DMARC aggregate reporting: Mail Check will no longer provide DMARC aggregate reporting, which has been essential for monitoring unauthorized use of domains and identifying potential email-based threats.
  • Cessation of DMARC insights and DKIM checks: The service will stop offering DMARC insights and DomainKeys Identified Mail (DKIM) checks, tools crucial for diagnosing and resolving email authentication issues.
  • End of TLS reporting (TLS-RPT): Mail Check will discontinue Transport Layer Security Reporting, which has been used to monitor and ensure the security of email transmissions.

After 24 March 2025, Mail Check will continue to assess DMARC policies, SPF policies, MTA-STS policies, and inbound TLS configurations.

Don’t take a risk on compliance

If UK public sector organisations fail to adopt a new service provider following the upcoming changes to Mail Check, they could face several serious consequences:

  1. Compliance and regulatory risks

Many UK public sector organisations must comply with NCSC guidelines, GDPR, and the Cyber Assessment Framework (CAF) and PCI-DSS 4.0. Without DMARC aggregate reporting, organisations risk non-compliance, leading to potential fines, audits, or reputational damage due to lack of full visibility into outbound email communications.

  1.  No DMARC aggregate reporting: No visibility

Without DMARC aggregate reporting and insights, organisations will lose visibility into unauthorized use of their domains. This makes it easier for cybercriminals to impersonate government entities, send fraudulent emails, and launch BEC attacks.

  1. Lack of threat intelligence and incident response capabilities

The discontinuation of TLS-RPT and forensic DMARC insights means organisations will lose access to crucial security data that helps detect threats in real-time. Without this visibility, responding to cyber incidents will be slower and less effective, increasing the risk of data breaches and operational disruptions.

Red Sift OnDMARC is here to help

The NCSC advises affected departments to transition to a solution that ensures continued DMARC implementation and ongoing support for the services Mail Check will no longer provide. To assist with this shift, Red Sift is offering an extended free trial, available beyond Mail Check’s service end date, running until March 31, 2025.

What’s the key difference?

Mail Check 
(after March)
Red Sift OnDMARC
DMARC Aggregate Reporting
DMARC Insights & Forensic Reporting 
SPF & DKIM checks
TLS Reporting (TLS-RPT)
DMARC policy assessment
SPF policy strength evaluation
Inbound TLS configuration checks
MTA-STS policy assessment

Red Sift OnDMARC provides a seamless alternative, delivering the same essential reporting features as Mail Check while enhancing data insights for improved security oversight. Along with TLS reporting, OnDMARC simplifies the adoption of new security measures like MTA-STS, offering a one-click deployment to streamline policy management and hosting.

Start your Red Sift ONDMARC trial today and stay protected.

PUBLISHED BY

Red Sift

26 Feb. 2025

SHARE ARTICLE:

Categories

Recent Posts

VIEW ALL
AI

Enhanced logo detection with AI: A hybrid approach

Phong Nguyen

Logo detection is crucial for brand protection, helping identify logo misuse in lookalike domains and fraudulent activities. Detecting true logo appearance while minimizing false positives is equally essential – false positives waste resources, trigger unnecessary enforcement actions, and obscure genuine threats. At Red Sift, our Brand Trust product combats brand abuse, fraud, and lookalike…

Read more
DMARC

Prepare for the Mail Check deadline

Red Sift

The National Cyber Security Centre (NCSC) is modifying Mail Check services to discontinue certain features, such as DMARC aggregate reporting, while continuing others. These changes aim to expand Mail Check’s accessibility to all UK-based organisations and manage service complexity and costs. Public sector organisations relying on Mail Check for DMARC aggregate reporting should seek…

Read more
Cybersecurity

Post-quantum cryptography for Internet and WebPKI: Where are we now and how…

Bhushan Lokhande

Recent advancements in quantum computing pose a substantial threat to the cryptographic algorithms that secure internet communications, particularly public key cryptography. As quantum computers evolve, they could eventually compromise these cryptographic protections, putting all internet communication at risk.  While cryptographically relevant quantum computers (CRQCs) are not expected imminently, the transition to quantum-safe cryptography is…

Read more
Cybersecurity

Collaborative cybersecurity: The building blocks to a safer internet

Rahul Powar

Ciaran Martin, former CEO of the UK National Cyber Security Centre, and Rahul Powar, CEO of Red Sift The internet’s foundational promise is one of connection, opportunity, and innovation. But as technological innovation grows, so do the risks. The challenge is clear: how do we create a fundamentally safer internet while empowering organisations of…

Read more