Selling DMARC as a managed service
For fifteen years, selling DMARC meant explaining what spoofing was, why the client should care, and why a protocol from 2012 deserved budget. Then Google and Yahoo made authentication mandatory for bulk senders, Microsoft followed, and the conversation inverted: now it is a compliance line item with a deadline attached. If you run an MSP, DMARC management is currently the easiest security service to add to your stack. Here is how the MSPs doing it well actually package, pitch, and operate it.
Why this sells now
Since early 2024, Google and Yahoo require bulk senders to publish SPF, DKIM, and DMARC, keep spam complaints low, and support one-click unsubscribe; Microsoft added its own requirements for high-volume senders in 2025. The enforcement is not theoretical: mail from non-compliant domains gets rejected or lands in spam. Your clients have felt this, usually as a mystery: invoices bouncing, quotes never arriving, a marketing send that suddenly underperforms.
That gives the service a hook no security pitch usually has: it is not insurance against a hypothetical attack, it is the fix for a delivery problem the client has already experienced, plus compliance with rules the biggest mailbox providers now enforce.
What the service actually is
The deliverable is a journey with a visible end state: every client domain at an enforcing DMARC policy, with someone watching the reports afterward. Concretely that means a first-month setup phase (publish DMARC in monitor mode, inventory who legitimately sends as the domain, authorize them in SPF and DKIM), a progression phase (tighten the policy as the data proves it safe), and then steady state: watching for new senders, catching breakage when a client adopts a new tool, and reporting monthly that protection held.
The number that sells renewals is enforcement coverage: "eleven of your twelve domains reject spoofed mail outright" is a sentence a business owner understands. Parked domains are the fast win here: domains that send nothing can go straight to a locked-down posture, which moves the coverage number in week one.
Packaging and pricing
The MSPs doing this well sell it per domain per month, either as a named line item or folded into a security bundle. Per-domain pricing matches how the work scales, and it makes the quote trivial: count the client's domains. Retail rates vary widely; what matters is that the wholesale side is a small fraction of any defensible retail price, so the margin survives even aggressive bundling. Monitor-only and parked domains cost you little or nothing to run, which is worth mirroring in your own packaging: charging full rate for a domain that sends nothing invites the client to prune the list instead of protecting it.
The pitch that works
Show, don't explain. A prospect's own domain, checked live in front of them, does more than any deck: no DMARC record, an SPF catch-all left open, reports going nowhere. If your tooling can scan a prospect list ahead of a call or embed a checker on your own site, the pitch opens with their data instead of your claims, and the close is "we fix exactly this, per domain, here is the price."
The three objections, answered
"We already have SPF."
SPF alone neither stops spoofing nor satisfies the mandates. Without DMARC, a receiver has no instruction to reject mail that fails, and no report ever tells anyone it happened. SPF is one of the two signals; DMARC is the policy and the feedback loop.
"We're too small to be spoofed."
Spoofing is automated and indiscriminate: attackers impersonate small businesses precisely because their customers trust invoices from them. The first month of reports usually settles this argument with data; unknown sources sending as the client's domain are the norm, not the exception.
"Our IT person can set this up."
Publishing a record is an afternoon. The service is what follows: reading receiver reports, classifying senders, progressing the policy without breaking payroll email, and noticing when something changes eight months from now. That is ongoing skilled attention, which is exactly what a managed service is for. For the client who wants the self-hosted route taken seriously, walk them through the parsedmarc comparison honestly; it usually makes the case for you.
Operating it without drowning
The economics only work if steady state is quiet, so run it exception-driven: one view over every client sorted by open problems, alerts only when something genuinely needs a human, and reporting generated, not written. A book of a hundred domains should be minutes a day of real attention, spent on the two clients whose posture changed, not on reading a hundred clean dashboards. That is the bar to hold any tooling to, ours included; the MSP page shows how we build for exactly this shape of work.
Keep reading
DMARC monitoring vs. self-hosted parsedmarc
For the client who says their IT person can build it.
White-label DMARC: what it covers
Putting your brand on the deliverable.
Turning on p=reject: what actually happens
The enforcement journey you are selling.
Protecting parked domains
The easiest first win in any client's portfolio.
Was this page helpful?
Free for one domain. Set up in five minutes. We parse the reports; you read plain-English summaries.