The email-security platform built for MSPs
Every client's email.Protected, fixed, proven.
ActiScan watches SPF, DMARC, DKIM and more across your whole client base, publishes the fix to each client's DNS for you, and proves the result in a report under your brand.
No sales call. Cancel any time during the trial.
Client domains
148
across 31 clients
Average grade
A−
up from B last month
DMARC compliance
97.8%
2.1M messages, 30 days
Needs you
3
failing checks
Mail sent as your clients, by DMARC result
30 days
Top problems
- Mailchimp is failing DKIM for brightsmile-dental.comFix ready
- MTA-STS missing on 4 domains at Harbor & Pine LawApply to 4
- northfield-cpa.com is ready for p=rejectStep up
36
free tools, no signup
6
DNS hosts with one-click publish
4
PSA and CRM integrations
$3
per domain, no volume cap
One platform
See it, fix it, enforce it, prove it
Other tools tell you what's wrong. ActiScan takes it all the way to done, for every client at once.
See
Every sender for every client, named: Microsoft 365, HubSpot, a spoofer on a cloud host. Charts, not report files.
Fix
ActiScan writes the exact record and publishes it to the client's DNS host in one click. Not a to-do list.
Enforce
A guided ladder to p=reject, one safe step at a time, with an autopilot that steps back before mail is lost.
Prove
Branded monthly reports, audit evidence packs and SIEM export, so every client sees what they pay for.
DMARC analytics
Know every sender, by name
ActiScan reads each client's DMARC reports and names the service behind every IP address, so a failing Mailchimp account or a spoofer on a cloud host stands out at a glance.
- Volume and compliance over time
- Senders grouped by service, not IP
- "Look here first" when something breaks
| Service | Messages | DMARC pass |
|---|---|---|
| Microsoft 365Mailbox provider | 18,420 | 100% |
| HubSpotEmail sending service | 6,102 | 100% |
| MailchimpEmail sending service | 2,877 | 41% |
| Unrecognised (DigitalOcean)Authorise it or investigate | 312 | 0% |
One-click fixes
Fix it, don't just flag it
Every finding comes with the exact record, checked before it's published. Connect the client's DNS host once and ActiScan publishes the fix, keeps every other record, and confirms it's live.
- Cloudflare, GoDaddy, Route 53, Azure, Namecheap, DNSimple
- Risky changes held for review
- Optional two-person approval
MTA-STS
Mail sent to this domain can be intercepted in transit. ActiScan wrote the record; one click publishes it at the domain's DNS host.
Enforcement autopilot
Get to p=reject without losing mail
A guided ladder moves each domain from monitoring to full rejection one step at a time, only when its own reports show every legitimate sender passing.
- Readiness judged from real mail
- Every step is your call
- Automatic step back if mail starts failing
Monitor
Done
Quarantine 25%
Done
Quarantine
Now
Reject
Next
Ready for Reject. Every recognised sender has passed for 14 days across 48,210 messages.Autopilot steps back on its own if legitimate mail starts failing.
Client reporting
Prove your work, every month
A report under your brand lands in each client's inbox on the 1st: grades that improved, spoofing that was blocked, fixes made and response targets met.
- Your logo, colours and support link
- Built only from what the data shows
- Shareable links and PDF too
Your MSP
Email security report · September
Brightsmile Dental
This month
- 2 domains improved their security grade.
- 1,204 spoofed messages impersonating you were blocked.
- Every response target was met (6 targets).
brightsmile-dental.com
Grade C → A · DMARC p=none → p=reject
Built for how MSPs work
Sell it as a managed service
The pieces an MSP needs to run email security for dozens of clients, and to charge for it.
Service tiers
Your packages decide what ActiScan automates for each client.
Two-person approvals
Technicians propose, a second person approves, every step logged.
Response targets
Acknowledge and resolve targets per tier, with breach alerts.
Client margins
What each client pays against what it costs you to serve.
SIEM export
Webhook, Splunk, Microsoft Sentinel or CEF syslog.
Audit evidence
PDF or CSV packs for SOC 2, HIPAA and insurers.
White-label
Your logo and colours on the dashboard, reports and share links.
PSA & CRM tickets
Findings land in ConnectWise, Autotask, HaloPSA or HubSpot.
Check any domain now, free
The same checks ActiScan runs for your clients. No signup.
Integrations
Works with the tools you already run
PSA & CRM
DNS hosts (one-click publish)
SIEM & alerts
ActiScan vs EasyDMARC
More for MSPs, for less
| ActiScan | EasyDMARC | |
|---|---|---|
| Price | $90/mo for 30 domains | Premium: $71.99/mo for 4 domains |
| More domains | $3 each, in 5-domain packs | Contact sales |
| Email volume cap | None | 100,000 a month |
| Fixes | The exact record, published for you | No exact fix record; DNS publishing tier not confirmed |
| Built for MSPs | Tiers, approvals, margins, white-label | Enterprise-first, demo required |
| Engineer help | Serafy, an AI engineer, included | People, on top tiers only |
EasyDMARC figures from its public pricing page. Full comparison
Put every client on ActiScan this month
$90 a month covers your first 30 domains. Try it free for 30 days, with no sales call.
From the blog
All posts →What DigiCert's Acquisition of Valimail Tells Us About Where Email Security Is Headed
A certificate authority just bought one of the biggest names in DMARC. For MSPs managing dozens of client domains, that says more about the next few years of email security than any product roadmap slide could.
Finding Every Legitimate Sender Before DMARC Enforcement Finds Them First
Every MSP that has pushed a client toward p=reject has learned the same lesson the hard way: the invoicing tool nobody remembered, the CRM that sends on the client's behalf, the marketing platform that was set up two account managers ago. This is the operational discipline for finding them first.
The Real Cost of Skipping Email Security: What the FBI's Latest Numbers Mean for MSPs
A fresh look at the FBI's newest cybercrime numbers shows email fraud is not slowing down, and MSPs who treat authentication as optional are the ones absorbing the fallout. Here is what the data actually says about the exposure sitting in client domains.