Learn · For MSPs

Selling DMARC monitoring as a service

Here's the uncomfortable arithmetic of being an MSP without a DMARC service line: when a client's domain gets spoofed, the emergency is yours anyway — the calls, the cleanup, the "how did this happen" meeting — but the revenue for preventing it went uncollected. Managing DMARC across a client book is real recurring work with a real market rate. This article is about packaging it, pricing it, and pitching it without a single slide.

Why it sells now (when it didn't in 2020)

DMARC used to be a hard sell to small businesses because the pain was hypothetical. It isn't anymore:

The pitch that works is a demo, not a deck

The single most effective DMARC pitch takes ninety seconds and happens inside an existing review meeting: put the client's domain into a DMARC checker on the shared screen. One of two things appears, and both close:

No fear-mongering required — the client's own DNS makes the argument. The close is equally plain: "We'll get every legitimate sender aligned, tighten the policy until spoofing bounces, and then watch it permanently. It's a monthly line item."

Packaging: bundle or line item

Two models dominate, and both work:

ModelHow it looksBest when
Security-bundle inclusionDMARC monitoring folded into your managed-security tier, raising that tier's priceYou're moving all clients up-stack anyway and want one fewer per-item negotiation
Standalone line item"Email authentication & anti-spoofing monitoring" per domain per monthClients scrutinize invoices; a visible item they understand renews better than a bigger bundle

Either way, the deliverable has two phases worth naming separately in your proposal: a rollout (the 6–12 week walk to enforcement — genuine project work, chargeable as such) and the ongoing monitoring (the permanent part: reading reports, catching drift, quarterly reporting). Clients accept recurring fees far more readily when they can see what "ongoing" actually means — records drift, senders change, and reports never stop arriving.

Pricing and the margin math

MSPs commonly charge somewhere between $30 and $100 per domain per month for monitored DMARC, with the rollout phase either front-loaded as a setup fee or amortized into a 12-month term. Where a client sits in that range tracks their sending complexity — a five-person firm on Google Workspace is not a company with four ESPs and a payroll provider.

Your input cost is the tooling plus the touch time. The tooling side is deliberately boring here: Canny Pigeons' Agency plan is one custom price sized to your client base — not a per-domain rate card that eats your margin as you grow, and seats are unlimited so your whole bench can work in it. The touch time, once a domain reaches enforcement, is a short per-client review cycle — the platform does the parsing, identification and drift-watching that used to be the labor.

Honest version of the economics: the rollout phase is where the real hours go — chasing DNS access, aligning the client's ESPs, judging the odd senders that reports surface. Price the setup accordingly and let the monitoring fee be what it is: high-margin because it's genuinely automated, defensible because it's genuinely necessary.

Objections you will actually hear

The renewal is the report

Monitoring services die at renewal when they're invisible. The fix costs you five minutes a quarter: open the client's per-domain dashboard in the review meeting and read it aloud — every service that sent as their domain, the spoof attempts that enforcement bounced, the drift alerts that were caught and closed. A client who has seen the blocked-spoofing number does not ask whether the line item is worth it.

The tooling side, solved for one custom price

Per-domain dashboards you can screen-share, hosted DMARC, daily drift alerts and unlimited seats — sized to your client base, not per-domain.

Canny Pigeons for MSPs