Privacy Ninja

UK Govt Releases Free Tool to Check for Email Cybersecurity Risks

UK Govt Releases Free Tool to Check for Email Cybersecurity Risks

The United Kingdom’s National Cyber Security Centre (NCSC) has announced a new email security check service to help organizations identify vulnerabilities that could allow attackers to spoof emails or lead to email privacy breaches.

The government agency, which leads the UK’s cyber security mission, says the Email Security Check tool requires no sign-ups or personal details.

This service was developed and is now provided online for free as a direct response to some UK sectors having a superficial adoption of recommended email security controls (as low as just 7% in some cases), as highlighted in NCSC’s guidance on email security and anti-spoofing.

Also Read: Computer Misuse Act Singapore: The Truth And Its Offenses

Using Email Security Check allows defenders to look up publicly available information about email domains and check for anti-spoofing and email privacy risks.

It works by checking publicly available internet DNS records to verify if anti-spoofing controls (notably the DMARC Policy) are correctly configured and the TLS configuration by initiating a server “handshake.”

“It checks that anti-spoofing standards, such as DMARC, are configured correctly to help organisations prevent cyber criminals from abusing their domain and sending out malicious emails pretending to be them,” the NCSC said.

“It also looks up whether privacy protocols, such as TLS, are in place to ensure that emails are encrypted when in transit so they cannot be accessed and remain confidential between mail servers.”

Also Read: Personal Data Websites: 3 Things That You Must Be Informed

“By following the recommended actions, organisations can help bolster their defences, demonstrate they taken security seriously, and make life harder for cyber criminals.”

Although the tool can check the security of email domains, it cannot check if individual emails or email domains are malicious. The NCSC advises those receiving suspicious emails to report them by forwarding them to [email protected].



Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection


We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.


Click one of our contacts below to chat on WhatsApp

× Chat with us