MSP Operations
The Free Domain Scan Is a Qualification Tool, Not a Giveaway
October 2, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

Every MSP website seems to have one now: a box where a prospect types in a domain and gets back a score. The instinct behind it is sound. The execution, in most cases, is not. Too many providers treat the free scan as a piece of marketing furniture, something that sits on a landing page to look modern, rather than as the diagnostic instrument it actually is.
That distinction matters because of what the scan measures. A free domain scan checks whether a domain has a valid SPF record, a DKIM selector, and a DMARC policy, and what that policy actually does when authentication fails. In under a minute, it answers a real question: is this prospect currently exposed to spoofing, and are they on the wrong side of the authentication rules that Google, Yahoo, and Microsoft now enforce. That answer is the qualification data, not the giveaway.
Why Are So Many Domains Still Failing Basic Authentication?
Because DMARC has existed since 2012 but enforcement has lagged adoption for over a decade, and most domain owners still do not know their current status. Research from Red Sift analyzing 73.3 million domains found that as of December 2025, 83.9% of domains had no visible DMARC record at all, and only 2.5% enforced the strictest p=reject policy. Separate analysis from Validity of domains and subdomains used in email "From" addresses found an even starker gap, with 84 percent lacking a published DMARC record entirely, and among the smaller share that do publish one, roughly 7.6% contain invalid syntax that renders the record useless.
This is not a niche problem confined to small, neglected domains. Even domains under direct regulatory mandate show real gaps. A September 2025 survey cited in industry benchmarking found that a large share of U.S. .gov domains had SPF errors, missing records, or syntax problems that silently broke DMARC despite the federal mandate requiring enforcement. If domains obligated by directive still fail basic checks, the average SMB client an MSP manages is almost certainly further behind.
What Does a Free Scan Actually Qualify For?
It qualifies a prospect against a specific, dated set of external requirements, not against a vague notion of "best practice." Since February 2024, Google has required that any sender pushing 5,000 or more messages a day to personal Gmail accounts authenticate with SPF and DKIM and publish a DMARC record, with enforcement tightening through November 2025 to include temporary and permanent rejections for non-compliant traffic. Yahoo adopted parallel requirements on the same timeline, and Microsoft followed with its own enforcement in 2025.
On the public sector side, the Department of Homeland Security's Binding Operational Directive 18-01 has required federal civilian agencies to publish SPF and DMARC records within 90 days of the directive and reach a p=reject policy within one year, a standard CISA continues to enforce today and one that has influenced private-sector procurement requirements for vendors who touch federal data. A scan result that comes back p=none or blank is not an abstract finding. It maps directly onto whether that prospect can legally keep sending bulk mail to Gmail and Yahoo users, or whether they can pass a vendor security questionnaire that references DMARC.
That mapping is what separates a qualification tool from a giveaway. A giveaway produces a number with no consequence attached. A qualification tool produces a number that predicts a near-term problem the prospect did not know they had.
Reading the Policy Level Correctly
Not every DMARC record means the same thing, and this is where MSPs most often undersell their own scan results. The policy value in the record determines whether the domain is actually protected or merely watching from the sidelines.
| Policy | What it does | Sales implication |
|---|---|---|
| No record | Domain is entirely unauthenticated | Immediate risk, urgent conversation |
| p=none | Reports on failures but delivers spoofed mail anyway | False sense of security, needs remediation plan |
| p=quarantine | Suspicious mail routed to spam | Partial protection, migration path exists |
| p=reject | Unauthenticated mail is blocked outright | Target state, worth showing as the goal |
A prospect sitting at p=none often believes they are covered because a record exists in DNS. Explaining that this setting still allows impersonated mail to reach recipients, per the way the dmarcian implementation guide describes the required policy for Google and Yahoo's minimum bar, is frequently the moment a scan conversation turns into a signed engagement.
Turning the Scan Into a Conversation, Not a Report
A number on a screen does not close business by itself. The scan result needs a human follow-up within a defined window, ideally same day, where the finding is translated into consequence: deliverability risk, spoofing exposure, or failure against a client's own compliance obligations. MSPs that let the scan output sit in an inbox unopened are wasting the exact signal they built the tool to capture.
A well-run qualification flow around a free scan generally includes:
- A scored, dated report the prospect can forward internally to a decision-maker
- A short, plain-language explanation of what the specific policy gap means for their mail flow
- A recommended next step tied to a real deadline, such as an upcoming bulk sender enforcement date or a vendor audit
- A clear path to a paid engagement that fixes the finding, not just documents it
That last point is where a lot of tools fall short. A scanner that reports a problem but offers no structured way to solve it just generates anxiety. Pairing the scan with a defined onboarding path, the kind laid out in ActiScan's own getting-started guide, gives the sales conversation somewhere to go immediately after the finding lands.
Why This Matters More for MSPs Than for Direct Marketers
A marketing team running a scanner wants email addresses. An MSP running one wants qualified engagements, and the difference shows up in what happens next. The MSP's book of business is domains, often dozens or hundreds of them across clients, each with its own drift in DNS configuration, forwarding service, and third-party sender. A free scan that only checks the MSP's own marketing site proves nothing. A free scan built to be run repeatedly against a prospect's actual client portfolio, and then again on a schedule after onboarding, is a monitoring product wearing a lead-generation hat.
This is also where regulatory momentum keeps expanding the addressable case for the tool. CISA's newer Binding Operational Directive 25-01 extends secure configuration baselines, including DMARC enforcement expectations, into Microsoft 365 and Google Workspace tenants beyond the federal government itself, a signal that authentication scrutiny is not staying confined to .gov domains. MSPs who can show a prospect exactly where they stand against that trajectory, using their own domain as evidence, are selling from data instead of from fear.
Structuring the Offer So It Converts
None of this works if the free scan and the paid remediation live in different mental categories for the prospect. The scan should feel like the first billable-quality deliverable of the relationship, not a disconnected freebie. That means the report needs the MSP's branding, a specific recommendation, and a visible connection to what comes next on the pricing page, where the remediation and ongoing monitoring tiers are laid out plainly enough that a prospect can self-select before the first call even happens.
The mechanics of running this well are not complicated, but they require intention. A scanner embedded on a website with no follow-up sequence, no scoring rubric, and no defined handoff from marketing to sales is a giveaway, regardless of what the landing page copy calls it. The same tool, wired into a qualification and follow-up process, becomes one of the highest-leverage instruments an MSP has for turning a DNS lookup into a signed statement of work. Setting one up correctly takes less time than most providers assume, and starting the process is as simple as visiting the signup page and connecting the first batch of client domains.
The technical check behind a free domain scan has not changed in years. SPF, DKIM, and DMARC records are still public DNS information anyone can query. What has changed is the cost of getting the follow-up wrong: enforcement dates have passed, regulatory scope has widened, and the domains still sitting at p=none or with no record at all are running out of runway to fix it quietly.