Skip to main content

Help us improve the Digital Marketplace - send your feedback

NETCRAFT LTD

DMARC Processing and Visualisation

DMARC is part of a portfolio of tools recommended by the NCSC that improves email security and can prevent your domains being spoofed. Netcraft’s DMARC service will provide the information you need to confidently move to a reject policy to prevent abuse, whilst not interfering with legitimate mail delivery.

Features

  • Processing of DMARC Forensic Reports
  • Processing of DMARC Aggregate Reports
  • Web interface that visualises the DMARC reports
  • Monitoring of the SPF and DMARC status for your domains
  • Alerts when SPF and DMARC policies are invalid
  • Alerts when new trends are identified
  • Detailed view of all your email domains

Benefits

  • Web based with 24/7 access
  • Prevent spoofing of your domains
  • Detection of phishing attacks spoofing your domains
  • Detection of phishing attacks spoofing your domains

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at rad@netcraft.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 2 0 9 3 1 3 5 6 9 7 5 8 6 5

Contact

NETCRAFT LTD Robert Duncan
Telephone: 01225 447500
Email: rad@netcraft.com

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
All modern web browsers supported.
System requirements
Web Browser

User support

Email or online ticketing support
Yes
Support response times
Support is available 24/7
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support is provided by electronic mail and telephone.
Account manager is provided for enterprise accounts.
Support available to third parties
No

Onboarding and offboarding

Getting started
Online training and documentation provided. Onboarding session is provided.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
N/A
End-of-contract process
N/A
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Web and meeting

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
None or don’t know
Accessibility standards
None or don’t know
Description of accessibility
N/A
Accessibility testing
N/A
API
Yes
What users can and can't do using the API
A full HTTP API is available, including detailed documentation. Contact us to manage user accounts and permissions and for API credentials.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The range of cybercrime attack types that are covered by both detection and countermeasures can be customised to your needs as described in the pricing document.

Scaling

Independence of resources
We scale our applications to account for load placed by all customers.

Analytics

Service usage metrics
Yes
Metrics types
Dashboards are available on usages, these are configurable by the customer.
In addition many statistical reports are also available in the portal.
Reporting types
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
We operate under a shared responsibility model with AWS for the protection of data at rest. Netcraft protects data at rest within our environments through a combination of physical safeguards and technical controls designed to prevent unauthorised access and maintain confidentiality and integrity. In addition, AWS implements security controls that meet or exceed industry standards across its data centres, providing strong protection for infrastructure and storage services used to host or process data.
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users may extract their data using the API or download capabilities in the portal.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
If the Service is unavailable continuously for 3 (three) days or unavailable for an aggregate of 120 (one hundred and twenty) hours within the Subscription Period the customer may terminate the Service and receive a pro-rata refund for the unused period.
Approach to resilience
Available on request
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
Multi-Factor Authentication (MFA)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted to authorised personnel only. We use strong authentication (including MFA) and least-privilege access to limit permissions. Administrative interfaces are protected by network controls such as firewalls, VPN access, and IP allow listing where appropriate. Access is reviewed regularly and removed promptly when no longer needed. Support systems use named accounts and identity verification before account changes or sharing sensitive information. All administrative and support activity is logged and monitored for auditability and security. These controls align with our SOC 2 Type II logical access and monitoring controls (e.g., CC6 and CC7).
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
No audit information available
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
SOC2 Type II
Cyber essentials
Information security policies and processes
Netcraft has a structured organisational model with a clear governance and reporting path, ensuring Information Security is embedded as a core backbone of the business and supported at all levels of the organisation.

Our Information Security and Compliance Departments are responsible for drafting, maintaining, and cascading all security and compliance policies across the organisation. These policies are reviewed and approved by senior stakeholders, with a clear escalation route to the Board-level Risk Committee where required.

Netcraft’s control environment is externally audited as part of our SOC 2 Type II assurance and is also self-assessed as part of Cyber Essentials. Policies are embedded into the employee onboarding process and reinforced through a structured programme of mandatory Information Security training delivered on a defined schedule.

We also maintain a Trust Centre (trust.netcraft.com), designed to provide customers and prospects with a transparent view of our Information Security and Data Protection policies, alongside supporting assurance documentation.
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We maintain configuration and change management processes to ensure service components are controlled and managed throughout their lifecycle. Components are recorded in a central inventory with defined ownership, versioning, and environment scope, and configuration baselines are maintained for production systems. All changes follow a standard workflow (request, review, approval, implementation, validation) with audit logging retained. Prior to deployment, changes are assessed for operational and security impact, including risks to confidentiality, integrity, and availability. Security sensitive changes receive additional review, testing, and, where appropriate, security sign off. Emergency changes are controlled and retrospectively reviewed.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Netcraft’s vulnerability management program identifies and remediates vulnerabilities (software flaws/misconfigurations) and threats (including insider threats) through defined controls and remediation. We assess potential threats using continuous monitoring, internal and external vulnerability scanning, and regular network and application penetration testing, supported by an in-house penetration tester and dedicated vulnerability management specialist. Findings are prioritised based on impact, likelihood, and compensating controls. Patches and mitigations are deployed according to severity and risk, with urgent issues addressed on an expedited basis. Threat intelligence is informed by scan results, penetration testing outcomes, and vendor security advisories.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Netcraft operates protective monitoring to identify potential compromises through comprehensive auditing and monitoring of authentication/authorisation activity, privileged user actions, access to sensitive/customer data, and indicators of malicious activity, with alerting enabled for events requiring immediate action. We also use technical detection measures such as regular network scanning, anti-virus and endpoint protection, and inbound email analysis. Suspected incidents are reported immediately and triaged by the Incident Response Team/Handlers, who assess severity and impact, contain the issue (e.g., isolating systems), eradicate root cause, and recover services. We respond promptly based on severity, taking immediate action where urgent risk is identified.
Incident management type
Supplier-defined controls
Incident management approach
Netcraft maintains an incident management approach with predefined processes for identifying, reporting, triaging, and responding to security and business continuity incidents. Users can report suspected incidents immediately (even if unsure) via established internal reporting channels, which are then assessed and managed by the Incident Response Team. For broader disruptive events, staff escalate initially to a senior manager, who will assess whether to notify the Business Continuity Team (BCT) to coordinate response and recovery activities. Incident reporting and communications are managed by the relevant response team, with post-event review and customer communications provided where required.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We can offer a 14 day trial of the service.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
7e4209f8-0178-4a86-99c8-71c74ff32553
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
SOC 2 Type II

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Activities to cascade good practice on fair working conditions throughout the supply chain
    • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at rad@netcraft.com. Tell them what format you need. It will help if you say what assistive technology you use.