Blog
Email security, straight talk.
Commentary for MSPs, from the team behind ActiScan.

Industry News
What DigiCert's Acquisition of Valimail Tells Us About Where Email Security Is Headed
A certificate authority just bought one of the biggest names in DMARC. For MSPs managing dozens of client domains, that says more about the next few years of email security than any product roadmap slide could.
Randy Hall, CEO
September 28, 2026

DMARC
Finding Every Legitimate Sender Before DMARC Enforcement Finds Them First
Every MSP that has pushed a client toward p=reject has learned the same lesson the hard way: the invoicing tool nobody remembered, the CRM that sends on the client's behalf, the marketing platform that was set up two account managers ago. This is the operational discipline for finding them first.
Rodney Hall, COO
September 28, 2026

Email Security Strategy
The Real Cost of Skipping Email Security: What the FBI's Latest Numbers Mean for MSPs
A fresh look at the FBI's newest cybercrime numbers shows email fraud is not slowing down, and MSPs who treat authentication as optional are the ones absorbing the fallout. Here is what the data actually says about the exposure sitting in client domains.
Randy Hall, CEO
September 25, 2026

DMARC
The Operational Reality of Running DMARC Across Every Client Domain You Own
Publishing a DMARC record is a five-minute task. Keeping hundreds of client domains correctly authenticated, aligned, and moving toward enforcement is a permanent operational commitment that most MSPs underestimate until it breaks something.
Rodney Hall, COO
September 25, 2026

Industry News
AI vs. AI: What the 2026 Email Threat Data Actually Means for Security Strategy
The 2026 threat reports are in, and the headline is not that AI writes better phishing emails. It is that the fundamentals MSPs have underfunded for years are now the difference between a contained incident and a headline.
Randy Hall, CEO
September 24, 2026

DMARC
Automating DNS Fixes Without Breaking Mail Flow: A Field Guide
Scripted DNS changes can fix SPF, DKIM, and DMARC problems across dozens of client domains in minutes, or they can knock out mail flow just as fast. This field guide walks through the guardrails that keep automation from becoming the outage.
Rodney Hall, COO
September 24, 2026

DMARC
Rolling Out DMARC Enforcement Without Breaking Client Mail Flow
Client domains do not fail DMARC because the standard is unclear. They fail because someone flips the policy to reject before every legitimate sender has been found and fixed. Here is the operational sequence that avoids that outcome, updated for the newly finalized DMARC standard.
Rodney Hall, COO
September 23, 2026

DMARC
BIMI in 2026: What It Actually Takes to Get a Client's Logo Into the Inbox
Client logos in Gmail and Apple Mail don't come from a DNS record alone. This is the operational checklist MSPs need before promising BIMI results, from DMARC enforcement to certificate math.
Rodney Hall, COO
September 23, 2026

Email Security
Email Security Just Became a Line Item, Not an Upsell
Insurance applications, mailbox provider rules, and client expectations have quietly moved email authentication from optional add-on to required baseline. Here is what changed and how MSPs should adjust pricing before a competitor does it first.
Randy Hall, CEO
September 21, 2026

DMARC
DMARC Just Became Internet Law — And That Changes the Math for Every MSP
Four separate mandates converged in the same eighteen months, turning a once-optional DNS record into a baseline requirement for anyone who sends business email. Here is what changed, why it matters for client contracts, and where MSPs stand to gain or lose the most.
Randy Hall, CEO
September 19, 2026

Industry News
From Optional to Mandatory: What Google and Yahoo's Bulk-Sender Rules Really Signal
Two years after Google and Yahoo announced bulk-sender authentication rules, enforcement has finally arrived, and Microsoft followed with its own version. This is a look at what the shift from soft warnings to hard rejections means for how MSPs price and deliver email security.
Randy Hall, CEO
September 17, 2026

MSP Operations
Why Email Authentication Is Becoming a Standard Line Item in MSP Contracts
Mailbox providers, insurers, and regulators have quietly turned SPF, DKIM, and DMARC from optional add-ons into baseline expectations. MSPs that still bundle authentication into "email support" instead of pricing it separately are leaving money and leverage on the table.
Randy Hall, CEO
September 17, 2026

Industry News
What Two September Acquisitions Tell Us About Where Email Security Is Headed
Two deals closed within two weeks of each other point at the same conclusion from opposite directions: authentication and AI detection are converging into a single problem that platforms, not point tools, are being built to solve.
Randy Hall, CEO
September 17, 2026

Email Security & Compliance
Email Authentication Is Now an Insurance Line Item — MSPs Should Treat It Like One
Underwriters have stopped taking an applicant's word for it on email security. They're running their own DNS lookups, and a domain sitting at p=none is starting to look like an unfixed vulnerability on a scan report.
Randy Hall, CEO
September 17, 2026

Industry News
AI Has Changed the Math on Email Threats — and on Defending Against Them
Generative AI has quietly stripped away the tells that used to make phishing easy to spot, and the click-through numbers prove it. Here is what the data says about the shift, and the specific controls that still hold up against it.
Randy Hall, CEO
September 17, 2026

DMARC
DMARCbis, p=reject, and the Next Phase of Email Authentication Enforcement
DMARC just moved from a decade-old informational spec to a real IETF standard, and mailbox providers are no longer treating p=none as good enough. Here is what changed, who is forcing the issue, and how MSPs should sequence client domains toward enforcement.
Randy Hall, CEO
September 17, 2026

DMARC
Gmail's Enforcement Wave Is Here — And the Federal Government Already Showed Us What Comes Next
Google stopped warning and started rejecting mail in November 2025. Federal agencies lived through this exact playbook under a 2017 directive, and their eight-year record offers a blunt preview of what happens when a deadline passes and the DNS records still aren't right.
Randy Hall, CEO
September 17, 2026

Email Security
Why Email Security Just Became a Standard Line Item, Not an Upsell
Mailbox providers, regulators, and cyber insurers have quietly rewritten the rules of the inbox. For MSPs still pitching DMARC as a premium add-on, the market has already moved the goalposts.
Randy Hall, CEO
September 17, 2026

DMARC
Rolling Out DMARC Enforcement Without Breaking Client Mail Flow
Pushing a client straight to p=reject is how helpdesk tickets happen. Here's the staged, evidence-driven path MSPs use to reach full DMARC enforcement without dropping invoices, password resets, or a CEO's newsletter mid-migration.
Rodney Hall, COO
September 17, 2026

Industry News
Four Deals, One Signal: Email Authentication Is Consolidating Into the Platform Players
DigiCert, Proofpoint, KnowBe4, and Cloudflare have all folded standalone email authentication companies into bigger platforms in the last few years. For MSPs, that shift changes how DMARC gets bought, priced, and supported.
Randy Hall, CEO
September 17, 2026

MSP Operations
The Business Case for Adding Email Security Monitoring to Your MSP Stack
Regulators, mailbox providers, and criminals have all moved on email authentication faster than most client contracts have. This is the operational and financial argument for MSPs to close that gap now, not at the next renewal cycle.
Randy Hall, CEO
September 17, 2026

Industry News
AI Is Now Fighting AI in the Inbox — Here's What That Means for MSPs
Phishing generation and phishing detection are both running on large language models now. For MSPs, the practical question isn't who wins the arms race, it's which layers of defense still hold when the words in an email stop giving attackers away.
Randy Hall, CEO
September 17, 2026

Industry News
From Mailbox Rules to Law: Where Email Authentication Mandates Are Headed Next
DMARC started life as a voluntary anti-spoofing header. It is now showing up in payment card audits, federal procurement rules, and IETF standards documents. Here is how MSPs should read that shift.
Randy Hall, CEO
September 17, 2026

DMARC
DMARC Just Became a Standard — What That Comes to Mean Beyond Google and Yahoo
For over a decade DMARC ran the internet's email trust layer as a widely-adopted convention with no formal standing. That changed this year, and the shift reaches far past the mailbox providers who made it famous.
Randy Hall, CEO
September 17, 2026

MSP Operations
Why Email Authentication Is Turning Into Table Stakes in MSP Contracts
Mailbox providers, card networks, and insurance underwriters have quietly converged on the same three protocols. For MSPs, that convergence is turning SPF, DKIM, and DMARC from a nice-to-have upsell into a baseline clients will start asking for by name.
Randy Hall, CEO
September 17, 2026

Industry News
The Great Email-Security Roll-Up: What Proofpoint's $1.8B Hornetsecurity Deal Signals for MSPs
A $1.8 billion acquisition rarely changes how an MSP runs its Tuesday, but this one might. Here's what the Proofpoint-Hornetsecurity deal actually rewires for the technicians managing client mailboxes.
Randy Hall, CEO
September 17, 2026

MSP Operations
The Business Case for Adding Email Security Monitoring to Your MSP Stack
Clients keep asking why their inbox still lets phishing through despite antivirus and firewalls. The answer, and the revenue opportunity it creates for MSPs, comes down to a layer most stacks still treat as an afterthought.
Randy Hall, CEO
September 17, 2026

Email Security Strategy
AI Is Rewriting Both Sides of the Email Threat Equation
Generative AI has quietly become the biggest force multiplier in email fraud since the invention of the macro virus. This piece looks at what the newest attacker data actually shows, and why domain authentication remains the one lever that still works regardless of who is writing the message.
Randy Hall, CEO
September 17, 2026

DMARC
From Guidelines to Standards Track: Where Email Authentication Pressure Goes Next
DMARC just left its eleven-year run as an informal community convention and entered the IETF Standards Track. For MSPs, that shift changes the conversation with clients from "best practice" to "documented protocol requirement."
Randy Hall, CEO
September 17, 2026

MSP Operations
The First 24 Hours: Running Incident Response When a Client Domain Gets Spoofed
A client calls in a panic because their domain is showing up in phishing emails nobody in the office sent. Here is the hour-by-hour playbook MSPs need before touching a single DNS record, and why the instinct to jump straight to p=reject can make things worse.
Rodney Hall, COO
September 17, 2026

MSP Operations
The Proof-of-Value Gap Is Widening -- and Recurring Security Reports Close It
Clients only see the invoice, never the attack that never happened. Ric Hall breaks down why domain-security reporting cadence, not scan quality alone, is what actually saves renewals.
Ric Hall, CRO
September 16, 2026

MSP Operations
The Easiest Sale You're Not Making: Cross-Selling Email Security to Current Clients
Most MSPs are still treating email authentication as a project instead of a product line. Here's why the client list already sitting in the PSA is the fastest path to new recurring revenue.
Ric Hall, CRO
September 9, 2026

DMARC
The Hidden Ceiling: What Actually Breaks When You Manage Email Authentication Across Dozens of Client Domains
A single client domain with SPF, DKIM, and DMARC configured looks solved. Multiply that by forty clients, each adding vendors on its own schedule, and the same three protocols start failing in ways no single-domain checklist ever anticipated.
Rodney Hall, COO
September 4, 2026

MSP Operations
Recurring Revenue Is Already the MSSP Story of 2026 — Email Security Should Be Riding It
Channel data from ScalePad, Kaseya, and MSSP Alert all point the same direction this year: growth is concentrating in recurring security services. Here's why domain and email authentication is the easiest line item MSPs can turn into a standing monthly contract.
Ric Hall, CRO
September 2, 2026

DMARC
Why SPF and DKIM Break Mid-Year: The Client DNS Drift MSPs Miss
A client's email authentication passes cleanly at onboarding, then fails in August after nobody touched a thing. The culprit is rarely a hack. It is DNS drift, and most MSPs have no process for catching it between reviews.
Rodney Hall, COO
September 2, 2026

DMARC
Automating DNS Record Fixes Without Breaking Client Mail Flow
Bulk DNS edits are where good DMARC intentions go to die. Rodney Hall lays out the operational guardrails MSPs need before letting any tool touch a client's SPF, DKIM, or DMARC records automatically.
Rodney Hall, COO
August 31, 2026

MSP Operations
Why "I Already Use a Free DMARC Tool" Is the Start of the Sales Conversation, Not the End of It
A prospect who mentions a free DMARC checker has already admitted the domain needs watching. The real question an MSP should ask next is who is actually moving that policy toward enforcement, and that question is where the deal gets won.
Ric Hall, CRO
August 28, 2026

DMARC
What a BIMI Rollout Actually Requires — And Where It Breaks
Brand logos in the inbox sound like a simple DNS record and a nice-to-have marketing win. In practice, BIMI sits on top of a DMARC enforcement policy, a certificate market that just lost one of its two issuers, and an SVG format most design tools can't produce correctly on the first try.
Rodney Hall, COO
August 28, 2026

MSP Operations
Four Ways MSPs Are Pricing DMARC Monitoring — And Why the Model Matters More Than the Rate
A rate on a quote is easy to copy from a competitor. The billing structure behind it is not, and it is the structure, not the number, that decides whether a DMARC engagement is still profitable after the easy domains are enforced.
Ric Hall, CRO
August 27, 2026

DMARC
The Gap Between "Has a DMARC Record" and "Actually Protected" Is Where MSPs Live
A TXT record with v=DMARC1 in it tells a client's compliance checklist that DMARC is "done." It tells an attacker almost nothing has changed. Here's why that gap is the actual job for MSPs managing email security at scale.
Rodney Hall, COO
August 27, 2026

MSP Operations
The Free Domain Scan: Turning a DMARC Gap Into a Sales Conversation
A missing DMARC record is one of the easiest security gaps to prove and one of the hardest for a prospect to argue with. Here is how top-performing MSPs use a free scan as the opening move in a paid email-security engagement.
Ric Hall, CRO
August 26, 2026

DMARC
The Safe Path From p=none to p=reject: A DMARC Enforcement Playbook
A domain sitting at p=none for months is still wide open to spoofing, yet rushing to p=reject without reading the reports first is how MSPs break client mail flow. Here is the staged, report-driven route between the two, updated for the newly published DMARC standard.
Rodney Hall, COO
August 26, 2026

MSP Operations
Stop Selling DMARC as a Project. Start Selling It as a Line Item.
Most MSPs still quote DMARC the way they quote a server migration: a fixed scope with an end date. That framing kills recurring revenue and leaves clients exposed the moment enforcement drifts. Here's why the smarter play is a monthly line on the invoice, not a closed ticket.
Ric Hall, CRO
August 25, 2026

DMARC
The SPF and DKIM Mistakes We Keep Finding in Client DNS Records
Most authentication failures MSPs troubleshoot were baked into DNS months earlier by a stale include, a duplicate TXT record, or a key nobody rotated. Here is what shows up over and over during client audits, and how to catch it before Gmail or Yahoo does.
Rodney Hall, COO
August 25, 2026