ActiScan

MSP Operations

"We Already Have a Free DMARC Tool" -- How to Actually Answer That Objection

September 7, 2026

Ric Hall, CRO— AI-assisted and reviewed prior to publication.

An open, unattended wooden mailbox beside a locked metal one in tall grass at dusk

A prospect leans back and says it: "We already have a free DMARC tool." The instinct is to argue tool features. That is the wrong fight. The real gap is almost never the tool. It is that a record was published once, at p=none, and nobody has touched it since.

The direct answer to the objection is this: a free DMARC tool can show a client what is happening in their mail flow, but it rarely gets them to an enforced policy, and it almost never scales across a client's full domain portfolio, subdomains, and parked domains. Visibility without enforcement leaves the spoofing problem exactly where it started, just better documented.

What Does "We Already Have a Free DMARC Tool" Actually Mean?

In practice, it usually means someone added a DMARC TXT record with p=none a year or two ago and has not looked at the reports since. The record satisfies the letter of a compliance checklist. It does nothing to stop spoofed mail because a monitoring-only policy takes no action on failures by design.

That distinction matters more now than it did even two years ago. Google and Yahoo's bulk sender rules, which took effect in February 2024, require a published DMARC policy of at least p=none for any domain sending close to 5,000 or more messages a day to personal Gmail or Yahoo accounts. Microsoft followed with its own enforcement window in 2025. A domain with a stale p=none record technically clears the bar these providers set, while remaining fully spoofable to everyone else on the internet.

Why the Objection Sounds Reasonable but Rarely Holds Up

Free tools are genuinely useful for the discovery phase: publishing a first record, confirming reports are flowing, and spotting obvious unauthorized senders. Independent comparisons of these tools are blunt about where that usefulness ends, noting that free tiers are designed for the discovery phase and are not built for ongoing enforcement monitoring at scale, compliance evidence, or multi-domain management.

The underlying data format is part of the problem. Aggregate reports arrive as gzip-compressed XML, one file per receiving mailbox provider per domain per day, and Microsoft's own documentation for Defender for Office 365 is candid that the information in the aggregate report can be vast and difficult to parse, suggesting PowerShell or Power BI automation to make sense of it. A client running five domains and a handful of subdomains can generate dozens of these files a day. Reading them by hand, or pasting them one at a time into a free upload box, is not a sustainable operating model, a point Valimail's own free analyzer page acknowledges directly, noting that monitoring authentication posture across multiple domains by hand isn't really sustainable.

The scale of the underlying gap backs this up. The most recent global tracking from Red Sift puts overall DMARC adoption at roughly 15% of domains with any policy at all, and only about 2.5% enforcing the strictest reject setting, out of a sample of more than 73 million domains. Separate analysis of the top 1.8 million domains found that more than 70% of DMARC-enabled domains lack reporting tags entirely, leaving organizations without visibility into who sends on their behalf. A free tool did not create that gap. But a free tool, used once and abandoned, is exactly how a domain ends up inside it.

Where the Free Tool Actually Falls Short

The practical limits show up in a handful of predictable places once a client has more than one domain or wants to move past monitoring:

  • Domain and subdomain ceilings. Most free tiers cap out at one or two domains and often skip subdomains and parked domains, which are common spoofing targets precisely because nobody is watching them.
  • No path to enforcement. Free tools show what is failing. Getting from p=none to p=quarantine to p=reject without breaking legitimate mail requires someone tracking every sending source over weeks, not a dashboard someone glances at occasionally.
  • No forensic or trend data. Aggregate reports show volume and pass/fail counts. Investigating a specific spoofing incident or tracking drift over months needs retained history and, in some cases, forensic reporting that free tiers rarely include.
  • No multi-client operating model. A tool built for one person checking one domain does not translate into a workflow for a technician managing forty client domains across different DNS providers.

How Should an MSP Reframe the Conversation?

Reframe it around outcome, not feature list. Ask what policy the record is actually set to, who is authorized to send as that domain, and what happens the next time a client's domain gets spoofed in a vendor-invoice scam. Those three questions usually surface the gap without a single mention of the word "tool."

This lines up with how the channel already talks about DMARC as a service line. Industry guidance for MSPs frames the sales conversation around business outcomes, noting that the conversation should center on protecting brand reputation, meeting inbox provider requirements, and preventing financial losses from domain spoofing, not on DNS record syntax, which matters to the implementation team and not the buyer. The client already has a record. What they are missing is the operational discipline of watching it, and someone accountable when it needs to change.

It also helps to name the regulatory backdrop plainly. The federal government mandated this exact posture back in 2017, when the Department of Homeland Security issued a directive requiring all federal executive branch agencies to implement DMARC with a minimum policy of p=reject within one year. That was not a monitoring requirement. It was an enforcement requirement, and it set a precedent that inbox providers have since echoed with their own bulk sender rules.

Positioning ActiScan Against the Free Tool, Not Instead of It

The honest pitch is not "replace what you have." It is "the free tool got you to visibility, this gets you and your clients to enforcement, and it does it across every domain in the book, not one at a time." That framing respects the work already done and focuses the conversation on what happens next.

For an MSP evaluating whether this is worth adding to the stack, the fastest way to see the difference is to run a handful of client domains through the platform rather than debate it in the abstract. The getting-started guide walks through connecting a first batch of domains and shows what a multi-domain enforcement dashboard actually surfaces that a single-domain free tool cannot.

Pricing conversations tend to resolve quickly once the enforcement gap is visible, since the cost of a missed spoofing incident dwarfs a monthly subscription. The pricing page breaks down tiers by domain count, which matters here because the objection almost always comes from someone thinking in terms of one domain instead of a full client portfolio. From there, the easiest next step is to open an account and connect the first client domain directly, so the enforcement gap becomes something the prospect can see rather than something they have to take on faith.

None of this requires disparaging what a prospect already has in place. It requires asking the one question free tools were never built to answer: not "can you see the reports," but "who is actually walking this domain to reject, and what happens to the ones nobody is watching."

Further Reading

← Back to all posts
Answering "We Already Have a Free DMARC Tool" — ActiScan Blog