Learn · For MSPs
Selling DMARC monitoring as a service
Here's the uncomfortable arithmetic of being an MSP without a DMARC service line: when a client's domain gets spoofed, the emergency is yours anyway — the calls, the cleanup, the "how did this happen" meeting — but the revenue for preventing it went uncollected. Managing DMARC across a client book is real recurring work with a real market rate. This article is about packaging it, pricing it, and pitching it without a single slide.
Why it sells now (when it didn't in 2020)
DMARC used to be a hard sell to small businesses because the pain was hypothetical. It isn't anymore:
- The compliance push: Google and Yahoo require DMARC from bulk senders (since 2024), Microsoft followed for Outlook (2025), and cyber-insurance questionnaires ask about email authentication by name. Clients now have external parties telling them to do the thing you're selling.
- The deliverability push: when a client's quotes and newsletters start landing in spam, they experience a revenue problem, not a security abstraction. DMARC done properly is part of the fix — and the monitoring proves it stays fixed.
- The fraud push: invoice fraud against the client's own customers, sent from the client's own domain name, is the story every business owner has now heard from a peer.
p=rejectis the control that ends that specific story.
The pitch that works is a demo, not a deck
The single most effective DMARC pitch takes ninety seconds and happens inside an existing review meeting: put the client's domain into a DMARC checker on the shared screen. One of two things appears, and both close:
- They have no DMARC record (most SMBs): "Right now, anyone on the internet can send email as yourcompany.com and nothing tells the receiving mailbox to stop it. Here's the report showing that. We can close it."
- They have
p=nonesomeone set years ago: "This record says 'monitor only' — and the reports it generates are going to a mailbox nobody reads. Spoofed mail is still being delivered. Monitoring is the missing half."
No fear-mongering required — the client's own DNS makes the argument. The close is equally plain: "We'll get every legitimate sender aligned, tighten the policy until spoofing bounces, and then watch it permanently. It's a monthly line item."
Packaging: bundle or line item
Two models dominate, and both work:
| Model | How it looks | Best when |
|---|---|---|
| Security-bundle inclusion | DMARC monitoring folded into your managed-security tier, raising that tier's price | You're moving all clients up-stack anyway and want one fewer per-item negotiation |
| Standalone line item | "Email authentication & anti-spoofing monitoring" per domain per month | Clients scrutinize invoices; a visible item they understand renews better than a bigger bundle |
Either way, the deliverable has two phases worth naming separately in your proposal: a rollout (the 6–12 week walk to enforcement — genuine project work, chargeable as such) and the ongoing monitoring (the permanent part: reading reports, catching drift, quarterly reporting). Clients accept recurring fees far more readily when they can see what "ongoing" actually means — records drift, senders change, and reports never stop arriving.
Pricing and the margin math
MSPs commonly charge somewhere between $30 and $100 per domain per month for monitored DMARC, with the rollout phase either front-loaded as a setup fee or amortized into a 12-month term. Where a client sits in that range tracks their sending complexity — a five-person firm on Google Workspace is not a company with four ESPs and a payroll provider.
Your input cost is the tooling plus the touch time. The tooling side is deliberately boring here: Canny Pigeons' Agency plan is one custom price sized to your client base — not a per-domain rate card that eats your margin as you grow, and seats are unlimited so your whole bench can work in it. The touch time, once a domain reaches enforcement, is a short per-client review cycle — the platform does the parsing, identification and drift-watching that used to be the labor.
Honest version of the economics: the rollout phase is where the real hours go — chasing DNS access, aligning the client's ESPs, judging the odd senders that reports surface. Price the setup accordingly and let the monitoring fee be what it is: high-margin because it's genuinely automated, defensible because it's genuinely necessary.
Objections you will actually hear
- "We already have SPF." SPF alone neither stops spoofing (the From header isn't covered) nor tells anyone when it breaks. DMARC is the layer that enforces and reports. The checker demo usually settles this one visually — SPF's limits in one paragraph.
- "We're too small to be a target." Spoofing isn't targeted at them — it's targeted through them, at their customers, using their name. Size is irrelevant to a script that spoofs every domain without a reject policy.
- "Microsoft/Google handles this for us." Their mailbox provider filters what arrives in their inbox. It does nothing about mail sent as their domain to everyone else. That's exactly the gap DMARC closes.
- "Can't we just set p=reject today and skip the monitoring?" Enforcing before aligning every legitimate sender bounces the client's own mail — payroll, invoices, the lot. The staged walk exists because the blast radius of getting it wrong is the client's revenue. (The safe path, step by step.)
The renewal is the report
Monitoring services die at renewal when they're invisible. The fix costs you five minutes a quarter: open the client's per-domain dashboard in the review meeting and read it aloud — every service that sent as their domain, the spoof attempts that enforcement bounced, the drift alerts that were caught and closed. A client who has seen the blocked-spoofing number does not ask whether the line item is worth it.