For MSPs & IT agencies

Your whole client book,
walked to p=reject.

When a client's domain gets spoofed, it's your ticket either way. Canny Pigeons turns DMARC into a service you can run at scale: every client domain on one dashboard, hosted DMARC so policy changes stop being DNS change requests, and daily drift alerts across the lot.

Start free with one domain Talk agency pricing

Free tier is permanent — trial the workflow on one client before you commit the book.

Why now

DMARC stopped being optional. Your clients just haven't noticed yet.

The mailbox providers mandated it

Google and Yahoo require DMARC from bulk senders since early 2024, and Microsoft followed for Outlook in 2025. Clients who "never had a deliverability problem" are starting to have one — and the fix lands on whoever runs their IT.

Insurers and auditors ask for it

Cyber-insurance questionnaires and security frameworks increasingly ask about email authentication outright. "We have SPF" doesn't tick the box; a monitored DMARC policy at enforcement does.

Spoofed invoices already cost them

Business email compromise starts with a domain that anyone can send as. Without DMARC at p=reject, a client's own name is an open tool for invoice fraud against their customers — and the cleanup call comes to you.

The workflow at N domains

One repeatable onboarding. Zero recurring DNS tickets.

The hard part of client DMARC isn't the standard — it's that client DNS lives across a dozen registrars with half-lost logins. Hosted DMARC means you touch each client's DNS exactly once.

1 Minutes per client

Add client domains

Each domain gets its own dashboard, its own report address, its own policy state. Your view is the whole book; each client's view can be just theirs.

client-a.com · client-b.com.au · …
2 One record, once

One CNAME in each client's DNS

Point _dmarc at us and we serve the policy. Every later change — p=, pct=, sp= — is a button in your dashboard, not a change window with the client's web agency.

_dmarc CNAME → verified ✓
3 Each at its own pace

Walk every domain to p=reject

Reports fill each dashboard, senders get identified by name, and you tighten each client's policy when their senders are aligned — the same playbook, repeated. The onboarding playbook →

p=none → p=reject
Built for the book, not the domain

The parts that break at thirty domains, handled.

Per-domain dashboards

Every client domain has its own senders, its own policy state, its own history — clean enough to screen-share in the client's quarterly review.

Unlimited seats, every plan

Your whole bench gets logins — admins who change policy, members who read reports. Seats are never a line item, so headcount never argues with margin.

Daily drift watch, across the lot

Client web agencies edit SPF. Migrations drop DKIM keys. We re-check every domain's records daily and email you the before/after diff — you find out in a day, not at renewal. Why records drift →

Threat intel on every source

Every IP in every client's reports arrives enriched — geolocation, network owner, attacker/abuser flags — so "who is this sender?" answers itself before the client asks you.

One custom plan, not a matrix

More than 5 domains means the Agency plan: sized to your client base, per-domain dashboards for client reporting, priority support. One email, one price, no add-on decoding.

A service you can sell

DMARC monitoring is recurring by nature — records drift, senders change, reports never stop. That's a monthly line item on your invoice, not a one-off project. How MSPs package it →

MSP questions, answered plainly

How does pricing work across many client domains?

Free covers one domain forever and Pro ($19/mo) covers up to 5 — enough to trial the workflow on real clients. Past that, the Agency plan is custom: priced to your client base rather than a per-domain rate card. Email support@cannypigeons.com with roughly how many domains you manage and you'll hear back from the founder within a day.

Can my clients see their own dashboard?

Yes — seats are unlimited on every plan, and members can read reports without being able to change policy. Invite a client as a member and they see the monitoring you run for them; keep policy changes with your team.

Do you white-label?

Not today — dashboards and alert emails say Canny Pigeons. Most MSPs present the monitoring under their own service name and use the dashboard as the working tool behind it. If white-labelling is the thing standing between you and rolling this out, tell us — agency-plan conversations are exactly where that call gets made.

What happens when a client leaves?

Remove the domain and point their _dmarc record wherever they're going next (or hand them a TXT equivalent of their current policy so nothing breaks in the handover). Domains aren't locked in — DMARC is DNS, and the DNS stays theirs.

We already do this by hand with a shared mailbox. Why switch?

Reading raw aggregate XML for one domain is a chore; for thirty it's a full-time job nobody actually does — which means nobody is really watching. The honest comparison isn't "tool vs. tool", it's "monitored vs. silently unmonitored". What managing DMARC across a client book actually involves →

Start free Contact us

One client domain free, no card. See pricing →