Email Security
Email Security Just Became a Line Item, Not an Upsell
September 21, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

For years, MSPs pitched email security the way electricians pitch surge protectors: nice to have, easy to skip if the budget got tight. That era is closing. Insurance underwriters now ask about it on applications, Google and Yahoo enforce it as a condition of inbox delivery, and clients are starting to ask for it by name instead of waiting for a technician to suggest it. The upsell has become table stakes.
What actually changed to make email security a line item?
Email security became a line item because three forces converged at once. Mailbox providers began rejecting unauthenticated bulk mail outright, cyber insurers started pricing policies around authentication posture, and clients grew more aware of business email compromise after years of costly headlines. None of these forces is optional, and none is reversible.
The clearest signal came from the mailbox providers themselves. Google's own guidance states that starting February 1, 2024, senders who deliver 5,000 or more messages a day to Gmail accounts must authenticate with SPF and DKIM, and Google has since moved to full DMARC quarantine enforcement for messages that spoof its domains. Yahoo followed the same threshold and timeline, and by mid-2025 Microsoft joined Gmail, Yahoo, and Apple Mail in requiring DMARC for large senders on its consumer email services. A domain that cannot pass those checks does not get flagged for review anymore. It simply stops landing in the inbox.
Why do cyber insurers care about DMARC?
Insurers now treat email authentication as a proxy for how well a business defends against phishing and impersonation fraud, one of the costliest breach categories they underwrite. A weak or missing DMARC record signals higher risk of business email compromise claims, which increasingly shapes both eligibility and premium pricing. Coalition, one of the larger cyber insurance carriers, publishes guidance specifically on authenticating email with SPF, DKIM, and DMARC as part of the risk factors it evaluates. That is not a marketing document. It is underwriting language showing up in front of policyholders.
This did not start with private insurers. The federal government set the precedent nearly a decade ago. The Department of Homeland Security's Binding Operational Directive 18-01, issued in 2017, required all federal civilian executive branch agencies to implement DMARC, moving from a monitoring policy to full enforcement within a set timeline. CISA still maintains and references that directive today as the baseline model for non-federal organizations that want to reduce their own exposure. When a federal mandate becomes the template an insurance industry borrows from a few years later, that is a durable trend, not a passing compliance fad.
The dollar figure that makes this a board-level conversation
Business email compromise is not a niche threat anymore. The FBI's Internet Crime Complaint Center has tracked it as one of the most expensive categories of cybercrime for years, and its most recent public service announcement puts a striking number on it. IC3 found that BEC and email account compromise schemes accounted for roughly $55 billion in exposed losses reported to the bureau between October 2013 and December 2023. That figure covers reported losses across a decade, but the trend line inside it keeps climbing year over year, which is exactly the kind of statistic that shows up in a boardroom slide before it shows up in an MSP's renewal conversation.
Clients are absorbing this message faster than many MSPs expect. Independent survey data collected by Vanson Bourne and published in ConnectWise's State of SMB Cybersecurity report found that 57% of small and midsize businesses now call cybersecurity their top organizational priority in 2025, up from 43% the year before. That shift in client posture means the conversation about email authentication is arriving at the sales table already half-won, which changes how an MSP should present it.
How this reshapes the MSP conversation with clients
The pitch no longer needs to start from scratch convincing a client that phishing is a real threat. It starts from a compliance and deliverability problem the client may have already noticed, such as marketing emails landing in spam or a cyber insurance renewal that suddenly asks pointed questions about SPF and DMARC records. That reframes email security from a discretionary add-on into infrastructure the client cannot function without, similar to backup or endpoint protection.
Here is roughly how that conversation splits across the stack:
- Deliverability risk: unauthenticated domains increasingly get throttled or rejected outright by major providers, which threatens ordinary business communication, not just marketing campaigns.
- Insurance risk: missing or misconfigured DMARC, SPF, and DKIM records can affect underwriting decisions and claims outcomes on cyber policies.
- Fraud risk: domain spoofing and lookalike domains remain a primary vector for the wire-fraud and invoice-fraud schemes that IC3 tracks under the BEC umbrella.
None of those three risks is solved by a single control, and none of them is fully eliminated even with strong authentication in place. Domain spoofing can still occur through display-name tricks and lookalike domains that DMARC alone does not catch, and no amount of email authentication substitutes for user training or a dedicated security team reviewing alerts. But together, deliverability, insurance, and fraud exposure give an MSP a factual, defensible reason to put email authentication on every client's baseline scope rather than treating it as a premium tier reserved for clients who ask.
What this means for how MSPs price and scope the work
Line items need to be measurable, and email authentication is one of the more measurable security controls an MSP can offer. A domain either publishes a valid DMARC record at enforcement or it does not, and that status can be checked, tracked, and reported the same way patch compliance or backup success rates are reported today.
That measurability is exactly what makes it defensible as a recurring line item rather than a one-time project fee. Clients renewing cyber insurance want documentation showing authentication is in place and monitored, not a memory of a project completed two years ago. Regular scanning across a client base, the kind built into ActiScan's platform, turns that documentation into something an MSP can hand over on demand instead of scrambling to rebuild it at renewal time.
For MSPs still pricing email security as an occasional add-on, the practical next step is straightforward. Review current client domains against the enforcement thresholds Google and Yahoo already apply, check where DMARC policies sit relative to CISA's federal benchmark, and use that baseline to justify moving the control into standard scope. ActiScan's getting-started guide walks through exactly that kind of baseline domain scan, and MSPs deciding how to structure the offering across their client base can compare tiers on the pricing page before rolling it out.
The bottom line for MSPs
Mailbox providers, insurers, and clients have independently arrived at the same conclusion from three different directions: email authentication is not optional infrastructure, it is baseline infrastructure. MSPs that keep pricing it as an upsell are negotiating against a market that has already decided the answer. Those that move it into standard scope now, backed by measurable scanning and reporting rather than a one-time setup, are the ones positioned to keep that line item on every invoice instead of losing it to a competitor who got there first. Getting a domain portfolio scanned and baselined takes less time than most MSPs assume, and ActiScan's signup page is built to get that first scan running the same day.