MSP Operations
The Free Domain Scan: Turning a DMARC Gap Into a Sales Conversation
August 26, 2026
Ric Hall, CRO— AI-assisted and reviewed prior to publication.

Every MSP sales rep has sat across from a prospect who insists their email is "fine" because nothing bad has happened yet. A free domain scan ends that conversation in about ninety seconds. It pulls the prospect's own DNS records, shows whether DMARC is missing, misconfigured, or sitting at a policy that does nothing, and hands the rep a concrete, unarguable fact to build a proposal around.
Does a free domain scan actually help close email-security deals? Yes, because it replaces a hypothetical threat with a documented gap in the prospect's own DNS, visible on their own domain, in their own words when they read the record back. That shift from abstract risk to observable fact is what moves a lead from "call me next quarter" to a signed statement of work.
Why Does a Missing DMARC Record Make Such a Strong Opening Line?
A DMARC gap is persuasive because it is binary and self-evident. Either the record exists and enforces a policy, or it doesn't, and a prospect can verify that themselves with a single DNS lookup.
Unlike a phishing simulation result or a vulnerability score, there is no interpretation required. The domain owner can see the same TXT record the rep is describing, which removes the "vendor scare tactic" objection before it forms.
This matters more now than it did two years ago. Google and Yahoo began enforcing bulk sender requirements in February 2024, and Microsoft followed with enforcement of its own bulk sender rules starting May 5, 2025, according to guidance tracked by dmarcian. Any prospect sending marketing email, invoices, or newsletters at volume is already inside the blast radius of those requirements whether they know it or not.
What Does the Data Say About How Many Prospects Actually Have This Gap?
Most of them. Independent measurement consistently shows that a majority of domains either have no DMARC record at all or have one that only monitors traffic without blocking anything. That gap is exactly what a free scan is built to surface.
Red Sift's global tracking found that only 14.9% of domains in a sample of 73.3 million had even started their DMARC journey with a policy of at least p=none as of December 2025, per its DMARC adoption guide. The same research noted that 2.3 million domains adopted DMARC in the wake of the Google, Microsoft, and Yahoo bulk sender mandates, which shows the mandates are working but also how far the baseline still had to travel.
Publishing a record is only step one. Fortra's analysis of the top 10 million internet domains found that only 22.9% of domains managing their own DMARC reporting had reached a reject policy, compared to 72.8% of domains whose records pointed to a managed third-party provider, a gap Fortra's researchers attribute directly to specialized third-party support. That single statistic is the entire business case for an MSP-delivered DMARC service in one sentence: prospects who try to do this alone stall at p=none, and prospects who get help reach enforcement.
The following breakdown is what a scan report typically hands a rep to walk a prospect through:
| Policy found | What it means | What it tells the prospect |
|---|---|---|
| No record | Anyone can spoof the domain in phishing emails | Zero visibility, zero protection |
| p=none | Reports are collected but nothing is blocked | Monitoring only, spoofed mail still lands in inboxes |
| p=quarantine | Failing mail is routed to spam | Partial protection, still not full enforcement |
| p=reject | Failing mail is blocked outright | Full enforcement, the target state |
Turning the Finding Into a Paid Engagement
The scan itself should never be the product. It is the diagnostic that earns the right to propose the actual work: SPF and DKIM cleanup, DMARC policy staging, BIMI logo enablement, and ongoing report monitoring. Framing the free scan as lead generation rather than a favor keeps the sales motion honest and repeatable.
A rep walking a prospect through a scan report has a natural three-part script. First, show the record (or its absence) directly from the prospect's own DNS. Second, connect it to a deadline they already know about, such as Microsoft's May 2025 enforcement date or the Google and Yahoo requirements that Google documents in its own email sender guidelines, since a compliance deadline creates urgency a generic "you might get hacked" pitch cannot. Third, propose the phased path from p=none to p=reject, since jumping straight to reject without a monitoring period is how legitimate mail gets dropped and how MSPs lose client trust fast.
This pattern is not new. The federal government proved the same phased approach at scale years ago. CISA's Binding Operational Directive 18-01 required agencies to publish a DMARC record with a p=none policy within 90 days and reach full enforcement at p=reject within one year, a staged rollout that has become the de facto industry template, as described in CISA's own directive. MSPs that mirror that same 90-day-to-one-year cadence with clients are following a model that already survived a decade of real-world enforcement.
A few objections come up often enough that reps should have answers ready before the meeting:
- "We already have SPF." SPF alone does nothing for DMARC alignment or reporting visibility, and Google's guidelines make clear that bulk senders need both SPF and DKIM aligned, not just one record in place.
- "Our email provider handles this." Most mailbox providers authenticate outbound mail but do not publish or manage the domain owner's DMARC policy, which remains the domain owner's responsibility.
- "We're too small to be a target." Spoofing targets the domain's reputation and the recipients who trust it, not the size of the company sending mail, which is why enforcement gaps at small businesses get exploited just as often as at large ones.
Why This Pitch Is Worth Building a Practice Around
Email security carries better unit economics than most reactive IT work, and the market is expanding fast enough to reward MSPs who move early. The managed security services market is projected to grow from $38.31 billion in 2025 to $69.16 billion by 2030, with cybersecurity cited as the fastest-growing segment of managed services overall, according to reporting compiled by The Hacker News. DMARC-driven email security is one of the more turnkey slices of that opportunity because the diagnostic step (the scan) doubles as the sales tool.
Getting this running does not require building scanning infrastructure from scratch. A platform built specifically for MSPs handles the DNS lookups, tracks client domains over time, and packages findings into a report a non-technical prospect can understand without a glossary. Reps who follow a structured rollout, starting with the getting-started guide for configuring their first batch of client and prospect domains, typically have a working pipeline of qualified conversations within a week rather than spending that time building spreadsheets by hand.
The economics scale with the client base, not against it. Firms evaluating the cost of running scans across a growing prospect list should look at the pricing page before assuming this requires an enterprise-grade budget, since most MSP-focused platforms price around volume of domains scanned rather than flat enterprise licensing. For a firm ready to test the workflow against its own prospect list before a client call, the fastest path is to open a free account and run a batch of scans this week.
None of this replaces a security team's judgment or guarantees a specific compliance outcome for any given client. What it does is turn an invisible DNS gap into a visible, defensible reason for a conversation, and in a market where most domains still have not reached enforcement, that conversation is available to any MSP willing to have it first.