Oxwyn Studio

Free tool

NCSC Mail Check alternative: check your SPF, DKIM and DMARC

The NCSC retired its free Mail Check and Web Check services on 31 March 2026. This is an independent replacement you can use in their place. Enter your domain and we read your live SPF, DKIM, DMARC and basic web security records, then tell you plainly what to fix.

We read the page, its headers, its certificate and its public DNS records. We do not log in, we do not probe admin paths, and we identify ourselves in your server logs as OxwynXRay.

What this tool can and cannot tell you

This is an independent tool built by Oxwyn Studio. It is not affiliated with, endorsed by, or a continuation of the NCSC, Mail Check, Web Check or any government service. We only read what your domain publishes externally in DNS and HTTP responses. We cannot see inside your mail server, your tenant configuration, your DKIM private keys or your internal routing, so we cannot confirm that signing actually works end to end or that every sending source is covered. A clean result means the public records we can read look correct at the moment of the scan. It is a strong signal, not a guarantee of security, and it is no substitute for ongoing DMARC report monitoring and proper mail administration.

What Mail Check did, and why it is gone

Mail Check was the NCSC's free service for UK organisations to monitor email anti-spoofing. It assessed whether a domain published SPF and DMARC correctly, and earlier also covered DKIM, DMARC aggregate reporting and TLS reporting. The NCSC retired Mail Check, alongside Web Check, on 31 March 2026, pointing to a mature commercial market for these checks. Users no longer receive findings from it, which leaves many organisations without the free government tool they relied on.

What this tool checks instead

Enter a domain and we read what it publishes to the public internet, the same way a receiving mail server or browser would. We resolve your SPF record and flag lookup limits and soft policies, look for DKIM selectors, and read your DMARC record to show whether your policy is none, quarantine or reject. On the web side we read your response headers for basics such as HSTS, content type options and a content security policy. You get a plain report, not a raw dump.

Why email authentication matters

SPF, DKIM and DMARC together tell the world's inboxes which servers may send email using your domain, and what to do with anything that fails. Without them, a criminal can forge messages that appear to come from you, invoicing your customers or phishing your staff, and inboxes have little reason to stop it. A published, enforced DMARC policy means forged mail is far more likely to be rejected or quarantined before it ever reaches a person. It protects your name as much as your inbox.

What to do with the result

Treat the report as a prioritised to-do list. If DMARC is missing or set to none, that is usually the first thing to address, moving carefully towards quarantine then reject once you trust your reporting. Fix SPF records that exceed the ten lookup limit or end in a weak all setting, and confirm a DKIM selector is present and signing. For the web headers, add the ones you are missing. If any of this is unfamiliar, take the report to whoever runs your DNS and mail, or ask us.

Questions

Is this the official NCSC tool?
No. This is an independent checker built by Oxwyn Studio. It is not the NCSC's Mail Check or Web Check, it is not affiliated with or endorsed by the NCSC or any government body, and it is not their official successor. The NCSC retired those services on 31 March 2026. We built this so you have something free to use in their place.
What does the scan actually read?
Your publicly published records. We resolve your SPF and DMARC records from DNS, look for a DKIM selector, and read the security headers your website returns over HTTPS. Everything we check is information your domain already exposes to any mail server or browser on the internet. We do not log in to anything or touch your internal systems.
Do I need to enter any passwords or connect my mailbox?
No. You enter a domain name, nothing more. There is no login, no mailbox connection and no access to your account. Because the tool only reads public records, it never needs and never asks for credentials.
My domain passes every check. Am I safe now?
It is a good sign, but not a guarantee. We can only see your published records, not whether DKIM signing works end to end or whether every legitimate sending service is included. Email security is ongoing. Keep a DMARC policy enforced and keep an eye on your aggregate reports over time.
Who is behind this tool?
Oxwyn Studio, a UK web studio. The same engine powers our wider site audits. A member of our team is a certified ISO 27001 Lead Auditor and ISO 42001 Auditor, which shapes how we read and explain these results. We are an independent studio, not a certification body or a government service.

This tool is one part of the full X-Ray, which measures security headers, your certificate, speed, indexability and what your site publishes about itself. Same scan, same free report.