MSP Operations
The Free Scan Play: Turning a Domain Check Into a Sales-Qualified Lead
September 11, 2026
Ric Hall, CRO— AI-assisted and reviewed prior to publication.

Every MSP sales team has run the same experiment at some point: offer a free check of a prospect's domain, hand over a report full of red and yellow flags, and wait for the phone to ring. Sometimes it works. More often the report sits in an inbox next to twenty other unread PDFs, because the scan proved a problem existed without ever connecting that problem to a decision the prospect was already under pressure to make.
The free scan converts into revenue when it stops being a generic report and becomes a specific, time-bound reason to talk. It works best when it is paired with a named business risk, a plain-language explanation of what the finding means, and a next step the prospect can take in the same call. Without that pairing, a scan is just data.
Why does a free domain scan work as a lead qualifier?
It works because it turns an abstract security conversation into a concrete, provable fact about the prospect's own infrastructure in under two minutes. Instead of asking a business owner to imagine risk, the scan shows them their actual DMARC policy, their actual SPF record, and whether their domain is currently exploitable for impersonation.
That specificity matters more than it used to. A recent analysis of 73.3 million domains found that only 14.9 percent had published any DMARC policy at all, and that just 2.5 percent enforce the strictest reject policy that actually blocks spoofed mail at the inbox. That leaves an enormous population of prospects who look protected on paper but are not, and a scan is the fastest way to show them the gap in their own DNS rather than in a generic industry statistic.
The gap is not closing on its own. A 2026 adoption report found that DMARC records have grown steadily, but that only around 9 percent of domains combine an enforcement policy with reporting, the configuration needed to both stop spoofed mail and retain visibility into who is sending on a domain's behalf. Most organizations that "have DMARC" are still sitting at p=none, collecting reports nobody reads and blocking nothing.
What should the free scan actually check?
A useful scan does not stop at "DMARC record present or absent." It needs to surface the policy level, the alignment mode, and whether the record would survive contact with a real mailbox provider's enforcement rules. The checks that map most directly to a sales conversation are the ones a prospect's own IT vendor selection criteria already touch on:
- SPF record presence, syntax validity, and proximity to the 10-DNS-lookup limit that causes silent authentication failures
- DKIM selector configuration and whether outbound mail is actually being signed
- DMARC policy tag (none, quarantine, or reject) and whether aggregate reporting is enabled
- MTA-STS and TLS-RPT status for transport-level encryption enforcement
- Basic blacklist presence across common reputation lists
Each of these ties back to a requirement the prospect may already be out of compliance with. Google's own guidance for bulk senders states plainly that mailbox providers now expect the sender's domain to align with either the SPF or DKIM organizational domain under DMARC, and that senders who fail to meet the guidelines lose access to delivery mitigation support entirely. That is a business-continuity argument, not just a security one, and it lands differently with an operations-minded buyer than a generic phishing warning does.
Turning the finding into a qualified conversation
The scan result is the opening line, not the pitch. A report that says "no DMARC record found" needs to be translated into what that means for the prospect's next board meeting, cyber insurance renewal, or vendor onboarding form. Sales teams that skip this translation step end up with a stack of scans and no meetings.
The translation is easier when it is anchored to a number the prospect's peers already recognize. The FBI's Internet Crime Complaint Center recorded business email compromise losses of just over $3 billion in 2025, a category of fraud that depends almost entirely on a spoofed or lookalike sender domain reaching an inbox unchallenged. Framing the scan result against that backdrop, rather than against abstract phishing statistics, gives a prospect's finance or operations lead a reason to forward the report internally instead of archiving it.
Federal domains have already been through this exercise. The Department of Homeland Security's Binding Operational Directive 18-01 required all federal agencies to move to a DMARC policy of p=reject on a fixed timeline, treating email authentication as a baseline control rather than an optional upgrade. That precedent is a useful reference point for MSPs selling into regulated or insurance-conscious verticals, since it shows a mandate that already worked at scale rather than a hypothetical best practice.
Where does the scan fit in the sales funnel?
The scan belongs at the top of funnel, as an unlocking mechanism for a discovery call, not as a substitute for one. It should generate a lead record the moment a domain is entered, before the prospect even sees their results, so the sales team can follow up regardless of whether the prospect books a meeting on their own.
The follow-up cadence matters more than the scan tool itself. A lead who scans a domain and finds a p=none policy or missing SPF record is telling the MSP, in effect, that nobody in their organization currently owns email authentication. That is a qualifying signal on par with a demo request, and it should be routed the same way, with a same-day or next-day outreach attempt rather than a batch email three weeks later.
| Scan finding | What it signals | Suggested next step |
|---|---|---|
| No DMARC record | No current ownership of email authentication | Same-day call, lead with BEC exposure |
| DMARC at p=none | Awareness exists, enforcement does not | Offer a phased move to quarantine/reject |
| SPF near lookup limit | Fragile setup likely to break silently | Technical audit, flag as urgent |
| Valid p=reject, DKIM aligned | Mature setup, lower urgency | Nurture for monitoring or backup services |
This kind of segmentation only works if the scan tool itself is consistent and repeatable across every prospect, which is why most MSPs standardize on one platform rather than mixing free public checkers with paid tools. Teams building this motion for the first time typically start with the getting-started guide to configure scan branding, lead capture fields, and notification routing before the first prospect ever runs a check.
Building the offer without overcommitting
The scan should never be sold as a guarantee of a specific security or compliance outcome, and the sales script needs to reflect that honestly. A scan shows current configuration at a point in time. It does not replace a security assessment, and it does not certify that a domain is safe from every form of impersonation, only that specific, checkable records are or are not in place.
That honesty is itself a sales advantage. Prospects who have been burned by vendors overselling a single free tool tend to trust the MSP that draws a clear line between "here is what we found" and "here is what a managed service would monitor going forward." The scan opens the door, the managed offering is what walks through it.
Pricing this correctly matters as much as the technical setup. Free scans that funnel into a paid monitoring tier need a pricing page that a prospect can actually reference when they ask "what happens after the free part," so the transition doesn't feel like a bait and switch. Reviewing the pricing structure before the campaign launches, rather than after the first qualified lead asks about cost, keeps that conversation credible.
Making the play repeatable
None of this scales if it depends on one salesperson remembering to follow up. The scan needs to be wired into whatever CRM or PSA the sales team already lives in, with automatic tagging based on the finding, so a p=none result routes differently than a fully enforced domain.
Once the workflow is proven on a handful of prospects, expanding it is mostly a matter of distribution: embedding the scan on a website, running it as a lead magnet in outbound campaigns, or offering it as a value-add during unrelated sales conversations about backup or endpoint protection. The mechanics of getting a domain scanner live are covered in the platform's signup flow, but the harder work is the follow-up discipline that turns a scan result into a signed services agreement.
The underlying opportunity is not shrinking. With the large majority of domains still unprotected against spoofing by any meaningful measure, the free scan will keep finding gaps for years to come. The MSPs who win the resulting business will be the ones who treat the scan as the first step in a defined process, not the whole pitch.