Protecting parked domains for the UK public sector
Non-email sending (parked) domains can be used to generate spam email, but they're easy to protect.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Non-email sending (parked) domains can be used to generate spam email, but they're easy to protect.

| This content was last reviewed on 05/03/2025 |
As I mentioned in my previous blog, it's just as important that you implement DMARC on your non-email sending domains as it is on those that do send email.
Unprotected, non-email sending domains can just as easily be used for email spoofing and phishing, allowing fraud and thus damaging trust in your organisation.
Even if you have defensively registered a domain, this doesn’t mean it's protected. Your registration may even have the undesired effect of convincing your partners and customers that email from this domain is genuine.
So, it makes sense to secure your parked, non-email sending domains at the same time as you apply protections to your email-sending domains. In fact, here's a top tip: Protect your parked domains first. They are easier to deal with, and once protected, require no maintenance.
If you are a domain owner who is responsible for some parked domains and you don't want your customers and partners to be spoofed, please follow the steps laid out below. And if you need it, this paper on the M3AAWG website has more information on parked domains.
These 4 actions will inform recipients that no emails should be originating from your parked domains and that if any do, they should be discarded. You should implement these measures in order.
Create an SPF record with no permitted senders, which indicates that no IP is authorised to send email for your parked domain.
parkeddomain.gov.uk TXT “v=spf1 -all”
Including our RUA will allow you to receive aggregate reports and give you visibility of potential abuse.
_dmarc.parkeddomain.gov.uk TXT
“v=DMARC1;p=reject;rua=mailto:[email protected];”
If you have an A record on your domain, but no MX records, you should create a null MX record to immediately fail any email to that domain. Otherwise, a sender server may try to send email to your A record which could be a public facing web server outside your control.
Create a record of type MX, with a priority of 0 (highest priority) and a host name of .
parkeddomain.gov.uk MX “0 .”
A null DKIM record isn’t absolutely required, as email will probably be treated similarly as if it had no record at all.
However, this approach is helpful as some recipients may treat a null DKIM record with extra caution, and it explicitly revokes any keys that may be cached. The below record indicates no email is signed for your parked domain.
*._domainkey.parkeddomain.gov.uk TXT “v=DKIM1; p=”
These four actions will prevent your domain from being spoofed. They will also give your customers and partners a clear indication that the domain is not used for sending email.
Once implemented, you can use Mail Check to verify and monitor your configurations, if you have an account.
With these measures protecting your non-email sending domains, and our guidance for your email-sending domains in place, you'll have all the bases covered. This will make a serious dent in the total amount of spoof email and phishing attempts the UK has to deal with.
Liam G
Product Manager, Mail Check


