For UK organisations that used NCSC Web Check or Mail Check

Web Check and Mail Check have gone. This is the next step.

The NCSC retired Web Check and Mail Check on 31 March 2026. If you used them to watch your website or email authentication, those findings have stopped.

That is not a scandal. The NCSC said the commercial market can now do that job, and pointed organisations at an EASM buyer’s guide. They also still offer a free snapshot, Check Your Cyber Security. Run that first. It is government-backed, takes minutes, and needs no account.

MyDomainRisk is the self-serve next step after that snapshot: a wider set of external checks, scheduled monitoring, a score you can track, and a PDF you can hand to a board or an auditor. Pro is £19 a month. It is not an NCSC product, and it is not a substitute for NCSC advice.

Scan a domain in 60 seconds, no card

What actually stopped on 31 March

Web Check watched public websites for common issues: certificates, TLS, headers, some software and configuration problems. Mail Check watched email authentication: whether SPF, DKIM and DMARC were in place so someone else could not send mail in your name.

From 31 March 2026, users no longer receive findings from those two services. That is the NCSC’s own wording, on their retirement post.

Two things did not stop:

  • Check Your Cyber Security. Still live. Website and IP, email security (anti-spoofing and privacy in transit), and a web browser check. Free, remote, no software to install.
  • Early Warning and DNS Check. If you already get those through MyNCSC, the NCSC says those findings continue.

If you have not run Check Your Cyber Security since the retirement, do that today: checkcybersecurity.service.ncsc.gov.uk. Then come back here for the watching that a snapshot cannot do.

What most organisations do next, and why it is a poor fit for a small estate

The NCSC is right that you should not rely on a one-off check. The usual commercial answers are Hexiosec, Intruder and Red Sift. They are proper EASM or email-security platforms, built for security teams, often sold with a conversation, and priced like it. Hexiosec ASM Premium, for example, is £329 a month, or £299 on an annual contract. (Hexiosec’s published prices, excluding sales tax, checked 30 August 2026.)

That is the right buy for some estates. It is a lot of money if you used Web Check because it was free, you have a handful of domains, and you want someone watching them without a procurement exercise.

MyDomainRisk is the £19 self-serve rung: scan in about 60 seconds, no card on the free plan, two apps behind one login — security posture, meaning how well a domain is defended, and authenticity, meaning whether a domain is what it claims to be. Upgrade when you want scheduled scans, PDFs and a portfolio. MSP is £99 a month if you run this for clients.

What MyDomainRisk actually checks

Every scan is external and non-intrusive. Nothing is installed, no credentials are used, and we do not log into your systems. The same class of public signals a careful person would look at, run in parallel, in under a minute.

On the security side that includes, among other things:

  • Email authentication: SPF, DKIM, DMARC, MTA-STS, BIMI, TLSRPT, CAA, DNSSEC
  • TLS and certificates, including expiry and weak configuration
  • Security headers
  • Exposed services, cloud storage buckets, dangling subdomains
  • Lookalike domains
  • Browser-safety, breach and infostealer context from public feeds

On the authenticity side: is this supplier domain, invoice domain or suspicious link what it claims to be? Same account. No second subscription.

Pro adds weekly or monthly full scans, bulk work, richer evidence and a branded PDF. MSP adds daily security monitoring, client grouping, a read-only portal and report bundles. Details live on the MSP page.

A sensible order of work

  1. Run the NCSC’s Check Your Cyber Security tools. Treat that as the government-backed snapshot.
  2. Run a free MyDomainRisk scan of the same domain. No account needed for the instant check. No card for the free plan.
  3. Fix the highest-priority findings from both. Start with email that can be forged, certificates about to expire, and anything publicly exposed that does not need to be.
  4. Keep the NCSC guidance bookmarked. Put the domain on MyDomainRisk Free (5 domains) so you have a baseline. Upgrade to Pro at £19 a month when you want the watch and the PDF.

If the snapshot is all you need, use it. If you want the gaps between snapshots watched, that is what this is for.

NCSC Check Your Cyber Security vs MyDomainRisk

NCSC pages do not call the remaining tool “Basic Check”. The table uses the official name. “Basic check” is how a lot of people search after they have run it.

NCSC Check Your Cyber SecurityMyDomainRisk
What it isFree, government-backed snapshot of public-facing ITCommercial external domain monitoring and authenticity checks
Who it is forUK organisations, especially small businesses, charities, schools and sole tradersSMEs, consultants and MSPs who need a watch after the snapshot
CostFreeFree 60-second scan, no card. Pro £19/month. MSP £99/month
What it looks atWebsite and IP, email anti-spoofing and privacy, web browser50+ external checks: email authentication, TLS, headers, exposure, lookalikes, threat intel, authenticity
How oftenWhen you go and run itOn demand. Pro: weekly or monthly full scans. MSP: daily security monitoring
What you getActionable insights in minutes, no sign-upRisk rating, plain-English fixes, history and score over time. Pro: PDF reports
What it is notA continuous monitor, or a replacement for commercial EASMAn NCSC product, government advice, or a Cyber Essentials certificate
BackingNational Cyber Security CentreHuro Data Technologies Ltd, hurodata.com

Use both. The NCSC snapshot tells you where you stood when you clicked. MyDomainRisk is the day-two-onwards work: wider checks, a schedule, a PDF.

Common questions

What is a good NCSC Web Check alternative?

Web Check itself stopped on 31 March 2026. There is no official NCSC clone of it. The NCSC still offers Check Your Cyber Security for a free website and IP snapshot, and they recommend a commercial EASM product for ongoing monitoring.

MyDomainRisk is a self-serve option at £19 a month: external website, certificate, header and exposure checks, plus email authentication in the same scan, with scheduled monitoring and a PDF on Pro. It is not a government service. If you need a full attack-surface platform with a security team behind it, look at the NCSC EASM buyer’s guide and at Hexiosec, Intruder or Red Sift. Those cost more, which is the point of this page.

What should we use as a Mail Check replacement?

Mail Check also stopped on 31 March 2026. You no longer get those email-authentication findings through MyNCSC.

Do this in order. First, run the NCSC Email Security Check (part of Check Your Cyber Security). It still looks at anti-spoofing and whether mail can be intercepted in transit. Then run a MyDomainRisk scan of the same domain. We check SPF, DKIM, DMARC, MTA-STS and related DNS records, explain the finding in plain English, and on Pro keep checking on a schedule so a DNS change does not sit unnoticed.

Dedicated DMARC reporting platforms (including Red Sift OnDMARC) exist if your problem is full enforcement across a large sender list. Most organisations that used Mail Check because it was free do not need that on day one.

What should we do after the NCSC basic check?

If by “basic check” you mean Check Your Cyber Security: keep the result, fix what it flagged, and do not treat it as a monitor. It tells you about the moment you ran it. It will not email you when a certificate is a week from expiry, when a subdomain is left dangling, or when a lookalike is registered against your brand.

After the snapshot:

  1. Scan the same domain on MyDomainRisk (free, about 60 seconds, no card).
  2. Fix the overlap first: spoofable email, weak TLS, anything exposed that should not be.
  3. Leave the domain on a plan that actually re-checks. Free gives you a baseline for up to 5 domains. Pro at £19 a month adds the schedule and the PDF.

MyDomainRisk does not replace the NCSC check. It is the next step after it.

Can this help with Cyber Essentials domain checks?

Cyber Essentials is a certification scheme with five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. An external domain scan cannot award that certificate, and we do not claim it can.

What it can do is show the internet-facing evidence an assessor or a buyer will also be able to see: HTTPS and TLS, email authentication, exposed services, headers, that kind of thing. The NCSC says Check Your Cyber Security complements Cyber Essentials. We treat our own Cyber Essentials overlap the same way: supporting evidence, not a pass. Use it to tidy the public surface before you sit down with the question set, not instead of the question set.

Is MyDomainRisk an official NCSC replacement?

No. The NCSC retired two of its own services. It still offers Check Your Cyber Security, Early Warning and DNS Check, and it publishes guidance including the EASM buyer’s guide. Follow that. MyDomainRisk is a commercial product from Huro Data Technologies Ltd. We overlap with some of the public signals Web Check and Mail Check used to surface, then keep watching and turn findings into a fix list and a PDF. That is a next step, not a government replacement.

Do I need a card to try it?

No. The free plan needs an email address so we can send results. No payment details. The homepage scan itself does not even need an account.

Keep watching the domain after the NCSC snapshot

Web Check and Mail Check are not coming back. Check Your Cyber Security is still the right first run. MyDomainRisk is the £19 self-serve watch after that: wider external checks, a schedule, a PDF, two apps, one login.

  • Free scan in about 60 seconds. No card.
  • Pro £19/month: up to 50 domains, weekly or monthly full scans, PDF reports.
  • MSP £99/month: daily monitoring and client-ready bundles.

MyDomainRisk is not affiliated with the NCSC. It does not replace NCSC guidance. Advisory only: scans read public signals. They are not a security audit, not a penetration test, and not a Cyber Essentials certification.

Start free — 5 domains, no card. Run the scan