ActiScan

MSP Operations

The Easiest Sale You're Not Making: Cross-Selling Email Security to Current Clients

September 9, 2026

Ric Hall, CRO— AI-assisted and reviewed prior to publication.

Laptop displaying a domain scan report on a technician's desk beside a client roster binder

Every MSP has a list of clients they already bill monthly, already hold credentials for, and already understand the domain footprint of. Few of those MSPs have checked whether those same clients have a working DMARC policy. That gap between what's already known and what's already sold is where the fastest, lowest-friction revenue in the business is sitting untouched.

Why Is Cross-Selling Email Security the Easiest Sale an MSP Isn't Making?

Because the buyer relationship, billing infrastructure, and technical access already exist, so there is no acquisition cost, no procurement cycle, and no cold pitch. The only missing step is running the scan and showing the client their own exposure. Acquiring a new customer typically costs several times more than retaining or expanding one already on the books, according to widely cited Harvard Business Review research summarized by Invesp, which puts the multiple as high as five to twenty-five times.

That math changes the entire calculus of where an MSP should be spending sales energy this quarter. A brand-new logo requires discovery calls, competitive bake-offs, and a trust curve that takes months to build. An existing client already trusts the MSP enough to let it manage their infrastructure, which means the sales cycle for an adjacent service collapses to a conversation and a report.

What the Data Says About the Exposure Sitting in Every Client Base

Most client domains are unprotected against spoofing, and the businesses that own them do not know it. The EasyDMARC 2025 DMARC Adoption Report found that global DMARC adoption among top domains rose from 27.2% to 47.7% between 2023 and 2025, but that still leaves the majority of tracked domains without enforcement. A broader domain sample analyzed by Red Sift paints an even starker picture: as of December 2025, only about 14.9% of domains in a 73.3 million domain sample had implemented even a baseline DMARC policy of p=none, according to Red Sift's global DMARC adoption guide.

That gap is not theoretical. It shows up in fraud losses that regulators and law enforcement now track publicly. The FBI's Internet Crime Complaint Center reported more than $16 billion in total losses for 2024, a 33% increase over the prior year, with phishing and spoofing the single most common complaint type, according to the 2024 IC3 Annual Report. Business email compromise remains one of the costliest categories inside that total, which means every unprotected client domain is a live liability, not a hypothetical one.

The following gap is what makes the sale easy to open. It also happens to answer, unprompted, the question every client eventually asks when a scan turns something up: how did nobody catch this before?

SignalWhat it reveals to the client
No DMARC recordAnyone can spoof the domain in phishing sent to customers or partners
DMARC at p=noneReports are collected but nothing is blocked
Missing SPF/DKIM alignmentLegitimate mail may fail delivery to major providers
No BIMI recordBrand logo and verified sender trust signals are unused

Why the Timing Has Never Been Better

Mailbox providers have turned email authentication from a best practice into a delivery requirement, which gives every MSP a natural, non-salesy reason to reopen the conversation with existing clients. Google's own guidance is explicit that bulk senders must have SPF and DKIM in place, and that alignment failures can result in messages being rejected outright, as detailed in the Google Workspace email sender guidelines. Yahoo adopted parallel requirements on the same timeline, meaning any client sending marketing or transactional email at volume is already exposed to bounced mail if authentication is missing.

Government policy reinforces the same direction. CISA's Binding Operational Directive 18-01 required federal civilian agencies to publish DMARC records and move to an enforcement policy, and CISA has since published follow-on guidance encouraging non-federal organizations to adopt the same baseline, according to the agency's own Enhanced Email and Web Security resource. When a federal standards body and the two largest inbox providers on earth are pointing at the same control, that is not a hard sell. It is a compliance and deliverability story that tells itself.

MSPs are also operating in a market where security has become the primary growth lever rather than a side offering. Huntress research on the MSP channel found that a large share of MSPs experienced at least one cybersecurity incident affecting a client in the past year, underscoring why security add-ons have become central to renewal conversations rather than optional upsells, as noted in the Huntress MSP statistics report. That shift means clients are primed to hear this pitch, even if they have not asked for it directly.

Building the Conversation Around a Scan, Not a Pitch

The mechanics of the cross-sell matter as much as the timing. Leading with a live scan of the client's own domain turns an abstract security concept into a concrete, named finding they can see in front of them.

  • Run a domain scan against every current client, not just the ones flagged as high risk, since misconfigurations show up in mature environments as often as new ones.
  • Present findings in plain language tied to business outcomes: deliverability, brand impersonation risk, and fraud exposure, rather than protocol jargon.
  • Attach a fixed monthly line item to the remediation and ongoing monitoring, so the client sees a bounded cost rather than an open-ended project.

Framing matters because most business owners have never heard of SPF, DKIM, or DMARC and do not need to. What they need is a specific answer to "is someone impersonating my company to defraud our customers right now," and a scan report answers that question better than any slide deck.

Turning a One-Time Fix into Recurring Revenue

DMARC and broader email authentication are not a set-and-forget project, which is exactly why they belong on a recurring contract instead of a one-off invoice. Policies need monitoring as clients add new marketing platforms, CRM tools, and outbound vendors that send mail on their behalf. The EasyDMARC 2026 adoption report found that operational complexity from multiple SaaS platforms and third-party senders is a major reason organizations stall at monitoring-only policies instead of reaching full enforcement, which is precisely the ongoing work an MSP is positioned to own.

That ongoing need is what makes email security a durable line item rather than a one-time win. Every new sender a client adopts is a potential authentication gap, and every gap is a reason the monitoring contract renews. Positioning the service this way, with a clear pricing structure, tends to convert better than positioning it as a security audit that ends once the report is delivered.

Making the First Scan Effortless

The lowest-friction way to start this motion is to scan the entire client roster before pitching anything. A getting-started guide that walks a technician through bulk-scanning existing domains means the first client conversation can happen this week, not next quarter after a sales process is designed from scratch. Once the findings exist, the pitch writes itself around specific, named exposures rather than generic security talking points.

For MSPs that have not yet built this into their renewal or QBR process, the fastest path forward is to get accounts scanning now rather than waiting for a client to ask. Setting up an account through signup takes less time than a single new-client discovery call, and the resulting findings are what actually open the cross-sell conversation. The clients are already on the books. The only question is whether their current MSP gets there before a competitor's report does.

← Back to all posts