ActiScan

MSP Operations

Recurring Revenue Is Already the MSSP Story of 2026 — Email Security Should Be Riding It

September 2, 2026

Ric Hall, CRO— AI-assisted and reviewed prior to publication.

Laptop on a workbench showing a domain scan report beside client folders under desk lamp light

Every channel report published so far this year lands on the same word: recurring. MSPs that grew fastest in 2025 did not do it by chasing one-off project work. They did it by locking in monthly, contracted services that show up on the books the same way every month, and security has become the easiest sell in that category.

Email security in particular sits at an odd intersection right now. Mailbox providers are tightening authentication requirements, regulators keep raising the bar, and clients are finally asking for it unprompted. The MSPs riding recurring revenue hardest in 2026 are the ones that noticed first.

So is recurring revenue really the defining MSSP story of 2026, and should email security ride it? Yes on both counts. Security services are growing faster than the rest of the managed stack, retention tracks with demonstrated ongoing value, and mailbox providers now give MSPs a recurring reason to monitor every client domain monthly, not just at renewal.

Why Is Recurring Revenue Suddenly the Center of the MSSP Conversation?

It is not sudden so much as it is finally showing up in the numbers everyone can see. Early submissions to the 2026 MSSP Alert Top 250 survey show a clear pattern: providers are reporting recurring revenue increasing compared with prior years, and customers are continuing to commit to ongoing security services even as they scrutinize broader technology spending. That is a meaningful signal in a year when overall IT budgets are under more pressure, not less.

The pressure shows up in growth projections too. ScalePad's 2026 MSP Trends Report, built from a survey of more than 1,100 MSP professionals across North America, found that overall growth projections for 2026 are less aggressive than 2025, with flat and loss projections up a few percentage points while the highest growth tier shrank. In other words, the easy growth is gone. What is left is retention, expansion within existing accounts, and services clients renew without a second thought, which is exactly the profile of a well-run security offering.

Kaseya's 2026 State of the MSP Report adds the operational half of the story. Nearly half of surveyed providers now see a specific capability as the deciding factor for scaling profitably: 48% of MSPs rank AI as the number one client need, with shrinking deal sizes and a widening talent gap making efficiency essential to protecting margins. Smaller deals mean fewer big projects to chase. That pushes MSPs back toward recurring lines they can deliver profitably at scale, and email security is one of the few categories where automation genuinely reduces the labor per client.

What the 2026 Numbers Actually Show

The market-level data backs up what individual providers are reporting anecdotally. Analyst firm Omdia's research, cited in Acronis's 2026 MSP trends analysis, found that the global managed security market is set to grow from $93 billion in 2025 to $106 billion in 2026, a 14.4% growth rate. That is faster growth than most other managed services categories are seeing this year, and it is happening while general IT spending growth cools.

Data pointSource
Managed security market growing $93B to $106B (14.4%) in 2025-2026Omdia, via Acronis
2026 MSSP Top 250 entrants report rising recurring revenueMSSP Alert / ChannelE2E
Highest growth tier of MSPs shrank versus 2025 projectionsScalePad 2026 MSP Trends Report
48% of MSPs name AI-driven efficiency as the top client needKaseya 2026 State of the MSP Report

The pattern across all four sources points the same direction. Growth is concentrating in security, and within security, in services clients pay for continuously rather than once. Email touches every employee, every day, which makes it one of the few line items a client notices immediately if it lapses. That visibility is exactly what turns a service into a renewal instead of a negotiation.

Why Is Email Security the Natural Anchor for This Kind of Revenue?

Because the requirements around it keep changing on a schedule outside any single MSP's control, which means the work never actually finishes. Domain authentication is not a project with an end date. SPF, DKIM, and DMARC records need monitoring as clients add marketing platforms, CRM tools, and helpdesk software, each one a new sender that can break alignment if nobody is watching.

That ongoing complexity is precisely what enterprise mailbox providers have been building policy around. Google's own guidance for large-scale senders now recommends full alignment, not partial coverage, stating that Google recommends all senders fully align DMARC to both SPF and DKIM, noting it is likely that dual alignment will eventually become a sender requirement. That kind of guidance is not a one-time fix. It requires a provider checking client domains on a recurring basis, since alignment can break the moment a client adds a new marketing tool or helpdesk platform that sends mail on the domain's behalf.

Government policy set the precedent for this years ago and keeps reinforcing it. The Department of Homeland Security's Binding Operational Directive 18-01, still in force, orders federal agencies to enhance their email and web security programs through domain-based authentication built on the DMARC standard defined by the IETF. The federal mandate never applied to private-sector clients directly, but it established the template every mailbox provider policy since has followed: authenticate, monitor, then enforce.

How Much of the Client Base Is Actually Exposed Right Now?

Most of it, based on the latest independent measurement. EasyDMARC's 2026 DMARC Adoption and Enforcement Report analyzed policies across 1.8 million domains worldwide and found that even where adoption is climbing, most organizations still are not protected. The report notes that Fortune 500 companies lead in maturity with 95% adoption and over 80% enforcement of DMARC policies, which means the gap sits almost entirely with the small and midsize businesses that make up the typical MSP client roster.

Large enterprises solved this problem years ago. Everyone else is the addressable market.

That gap is the recurring-revenue opportunity in plain terms. A client with no DMARC policy, or one stuck at a passive monitoring setting, is not a one-time fix-it ticket. It is an ongoing monitoring relationship, because:

  • New SaaS tools and marketing platforms send mail on the client's behalf constantly, and each one needs to be authenticated or excluded
  • Policy enforcement has to be raised gradually, from monitoring to quarantine to reject, with reporting checked at every step
  • Mailbox provider rules keep shifting, so a configuration that passed review last year may not pass this year's

How Do MSPs Turn That Exposure Into a Contracted Line Item?

The path runs through visibility and packaging, not through one-time remediation. A provider that can show a client, in plain terms, which domains are unauthenticated, which senders are failing alignment, and what the exposure looks like month over month has a report worth paying for on a schedule. That is a different conversation than "let's fix your SPF record" once and move on.

Turning that into recurring revenue starts with a tool that can run across every client domain without adding headcount, since the margin math on manual per-domain review does not work at MSP scale. Providers evaluating that kind of platform can compare tiers on the ActiScan pricing page before committing, since the right plan depends on how many client domains need continuous scanning versus periodic checks. Most MSPs that make the switch describe the same rollout pattern: start with a baseline scan across the client base, package the findings into a standing report, then upsell active enforcement work once the client sees the gaps in writing.

For teams building this line of business for the first time, the getting-started guide walks through the initial domain scan and report setup end to end, which shortens the time between signing a client and generating the first billable deliverable. That first report is often what converts a monitoring-only client into one paying for managed enforcement, because it turns an abstract compliance requirement into a specific, visible list of open exposures with the client's own domain name attached to each one.

Getting the Motion Started This Quarter

None of this requires a new practice built from scratch. Most MSPs already have the client relationships, the trust, and the billing infrastructure. What is missing in a lot of shops is simply the recurring mechanism, the report that goes out every month whether or not a ticket gets opened, and the packaging that turns domain authentication from a line in a security audit into its own contracted service.

The MSSP Alert data on rising recurring revenue, the Omdia market growth numbers, and the widening gap between Fortune 500 enforcement and everyone else all point at the same opening. Email domains are one of the few assets every client has, every mailbox provider is watching, and almost none of the smaller ones have fully locked down. Providers that want to test the fit before committing budget can start from the signup page and run a scan across a handful of client domains to see what the exposure actually looks like before building the packaging around it.

Recurring revenue is not a trend MSPs need to wait out. The reporting from ScalePad, Kaseya, and MSSP Alert all describes the same shift already underway, and the DMARC enforcement data shows exactly which service category has the most room to grow inside it. Email security was already a natural fit for monthly billing. In 2026, the mailbox providers are making sure it stays that way.

← Back to all posts