ActiScan

MSP Operations

The Cross-Sell Sitting in Your Existing Client Base: Email Authentication

September 1, 2026

Ric Hall, CRO— AI-assisted and reviewed prior to publication.

A sealed envelope caught halfway through a brass mail slot in an empty hallway

Every MSP has a list of clients whose domains are one bad DNS record away from a deliverability problem, a spoofing incident, or a failed vendor security questionnaire. That list is not a prospecting exercise. It is the existing client roster, and the service that fixes it, email authentication, is one of the few line items an MSP can sell without a new logo, a new tool stack, or a long sales cycle.

The core opportunity is simple: nearly every client domain an MSP already manages needs SPF, DKIM, and DMARC configured correctly, most don't have it done right, and mailbox providers have spent the last two years turning that gap into a business problem the client will pay to solve. The pitch already exists inside their inbox.

Why Is Email Authentication Suddenly a Sales Conversation?

Because the mailbox providers made it one. For a decade, SPF and DKIM were background hygiene that only deliverability specialists cared about. That changed when Google and Yahoo jointly announced that bulk senders would need authentication in place, with enforcement that has kept tightening since.

Google's own guidance is unambiguous about who this touches. All senders, including Google Workspace users, must meet the requirements in the Email sender guidelines when sending messages to personal Gmail accounts, and enforcement for bulk senders who fall short is gradual and progressive, arriving as error codes on failed messages rather than a single cutoff date. Microsoft followed with its own deadline, confirming in its official announcement that domains sending over 5,000 emails a day would need to comply with SPF, DKIM, and DMARC, with non-compliant messages routed to junk before outright rejection. That means every one of the three largest consumer mailbox ecosystems now conditions inbox placement on authentication that a large share of SMBs never configured.

What Cross-Sell Opportunity Already Exists in Your Client List?

It exists in the gap between "has a DMARC record" and "has a DMARC record that does anything." Most domains that publish DMARC sit at a monitoring-only policy, which means they are visible to reporting but not actually blocking spoofed mail. The EasyDMARC 2025 Adoption Report, built from an analysis of 1.8 million domains alongside a survey of 980 IT professionals, found that global DMARC adoption rose sharply but with enforcement policies growing at a slower pace than adoption itself, leaving a large population of domains that have technically complied without technically protecting anything.

That gap is the cross-sell. A client who set p=none to stop Gmail bounces two years ago and never touched the record again is not protected today. They are sitting at the exact stage where a phishing email spoofing their own domain sails through untouched, and where the fix is a policy change an MSP can make in an afternoon.

How the Big Mailbox Providers Rewrote the Business Case

Each provider set its own threshold and timeline, but the pattern is consistent enough to build a single conversation around.

ProviderThresholdEnforcement startMinimum requirement
Google & Yahoo5,000+ msgs/dayFebruary 2024DMARC record, SPF or DKIM alignment
Microsoft (Outlook.com, Hotmail, Live)5,000+ msgs/dayMay 5, 2025DMARC p=none minimum, SPF and DKIM aligned
US federal agencies (BOD 18-01)All second-level domains90 days / 1 yearDMARC p=reject within one year

The federal directive is worth knowing even for MSPs with no government clients, because it set the template everyone else copied. CISA's own directive language required agencies to move from a baseline DMARC record within 90 days to a full reject policy for all second-level domains and mail-sending hosts within one year. That two-stage structure, monitor first, enforce later, is precisely the sales narrative an MSP can walk a client through today: get visibility this month, get protection by next quarter.

The underlying protocol has not changed to support any of this urgency. DMARC itself has worked the same way since 2015, when the IETF published the mechanism by which a mail-originating organization can express domain-level policies and preferences for message validation, disposition, and reporting that a mail-receiving organization can use to improve mail handling, as defined in RFC 7489. What changed is not the standard. What changed is that Gmail, Yahoo, and Outlook decided to actually check for it.

Where MSPs Are Leaving Money on the Table

Security services are already the fastest-growing line on most MSP service menus, but the growth is concentrated in flashier categories than authentication. Kaseya's Datto Global State of the MSP Report, based on a survey of 1,800 MSPs worldwide, found that the top three managed security services currently offered are email security, followed by security framework and compliance auditing, and identity access management. Email security tools like spam filtering and phishing simulation sit near the top of that list. DMARC monitoring and enforcement, the piece that actually stops a spoofed message from being sent in the client's name in the first place, is frequently absent or bundled invisibly into a broader security stack where nobody itemizes it.

That absence is the opening. A few reasons DMARC monitoring tends to under-sell relative to its urgency:

  • It requires no new agent, endpoint, or hardware, so it does not show up in the same sales motion as EDR or backup renewals.
  • The value is invisible until a client asks why their invoices are being spoofed, at which point the MSP is fixing a fire instead of billing a retainer.
  • DNS changes feel low-effort to a technician, which makes techs undersell the ongoing monitoring and alignment work to a client who has no idea the record exists.

None of that reflects the actual difficulty or value of the service. Getting a client domain from a bare DMARC record to a safe p=reject policy without breaking legitimate mail flows through every third-party sender, marketing platform, and CRM integration takes real analysis of aggregate reports over weeks, not a five-minute DNS edit.

How Do You Turn DMARC Into a Recurring Line Item?

Start with an audit, not a pitch. Running a scan across the existing client book surfaces exactly which domains have no DMARC record, which are stuck at monitoring-only, and which are already misconfigured in ways that hurt deliverability today. That audit becomes the sales conversation on its own, because it turns an abstract risk into a specific list of client domains with a specific gap.

From there, the packaging matters more than the technology. Some MSPs fold authentication monitoring into an existing security tier. Others break it out as its own recurring item, priced against the actual work of report analysis and staged policy rollout rather than the appearance of a one-time DNS task. A provider evaluating how to structure that offer can compare tiers designed for exactly this motion on the pricing page, which lays out what a scan-and-monitor engagement looks like at different client volumes.

Once the packaging is set, the technical rollout should follow the same staged approach the mailbox providers themselves modeled: publish, monitor, then enforce. The getting-started guide walks through that sequence for teams running their first client domains through a scan, from initial record discovery to interpreting aggregate reports before flipping a policy to quarantine or reject. Teams ready to run that audit against their own client list can move straight to a signup and start pulling domain-level results the same day.

The Underlying Argument for Clients

The sales conversation does not need to lean on fear. It can lean on math the client already understands: mailbox providers now gate inbox placement on authentication, most SMB domains are only partially compliant, and the fix is a service the MSP is already positioned to deliver without new headcount or new tooling. Framing the offer as protection against a specific mailbox provider deadline, rather than an abstract security upsell, tends to close faster because the client can verify the deadline themselves.

None of this promises a specific compliance outcome or replaces a client's need for a broader security program. What it does is close a gap that is measurable, billable, and already sitting in domains an MSP has DNS access to today. The mailbox providers built the urgency. The audit builds the pitch. The recurring engagement is the part most MSPs still haven't priced.

← Back to all posts
Email Authentication: The MSP Cross-Sell You're Missing — ActiScan Blog