ActiScan

MSP Operations

Retention Isn't Won at Renewal — It's Won in the Reports You Send All Year

September 8, 2026

Ric Hall, CRO— AI-assisted and reviewed prior to publication.

An open mailbox with envelopes arriving steadily, symbolizing consistent client reporting over time

Renewal season has a habit of concentrating an MSP's attention on exactly the wrong moment. Account managers polish a deck, pull twelve months of ticket data into a single slide, and walk into a room hoping the client remembers why they signed in the first place. By then the outcome is largely already decided, and it was decided months earlier, in the emails the client did or didn't open.

The core answer is simple: retention is not a negotiation that happens at contract renewal, it is a cumulative impression built from every status update, scan result, and QBR sent throughout the year. Clients who can see risk being found and fixed on a recurring basis rarely need convincing to renew. Clients who can't see anything are the ones quietly getting a second quote.

Why Do MSPs Lose Clients They Thought Were Happy?

Because silence gets misread as safety, and safety gets misread as low value. Research on customer disengagement has repeatedly found that dissatisfied clients rarely complain before they leave, they simply stop expecting things to improve and start planning their exit quietly. An MSP with a clean ticket queue and no visible reporting cadence looks, from the client's chair, indistinguishable from an MSP doing nothing at all.

The industry's own data backs this up. ScalePad's 2025 MSP Business Trends Report found that MSPs with the strongest retention numbers, above 76 percent, share a specific habit: they track service-level metrics proactively and use them to demonstrate progress, while lower-performing peers tend to review those same numbers only internally, if at all. Retention, in other words, tracks with visibility, not with how much work actually got done behind the scenes.

That gap matters more in security services than almost anywhere else in the stack. A client can watch a helpdesk ticket close in real time. They cannot watch a spoofed sender get blocked, a DMARC policy tighten from monitoring to enforcement, or a lookalike domain get flagged before it's weaponized. If that work isn't translated into something the client reads, it functionally didn't happen from their point of view.

What Should a Monthly Security Report Actually Contain?

It should answer three questions a non-technical buyer actually has: what changed, what's still exposed, and what happens next if nothing is done. A report that lists raw scan output or protocol jargon fails all three, no matter how technically accurate it is.

For email-security specifically, that means translating authentication posture into plain language rather than pasting in a DMARC aggregate report. Most DMARC data arrives as XML meant for machines, and Google's own sender guidelines require any domain sending more than 5,000 messages a day to Gmail addresses to have SPF, DKIM, and DMARC configured, which means most clients already have a policy in place that nobody has ever explained to them. Translating that record into "here's what's authenticated, here's what isn't, here's what a spoofed invoice from your domain would look like to a customer right now" turns a compliance checkbox into a story the client can retell to their own board.

A useful monthly or quarterly report for a managed domain typically includes:

  • Current DMARC policy state (none, quarantine, or reject) and what it means for spoofing risk
  • New or expiring SPF, DKIM, and DMARC records discovered since the last scan
  • Lookalike or newly registered domains that resemble the client's brand
  • Blocked or flagged spoofing attempts tied back to the client's own domain
  • A plain-language summary of what changed and what's recommended next

None of this requires inventing new work. It requires packaging existing scan data so a CFO, not a sysadmin, can understand it in ninety seconds.

The Compliance Backdrop Makes This Reporting Non-Optional

Regulators and mailbox providers have quietly turned domain authentication reporting from a nice-to-have into infrastructure. CISA's Binding Operational Directive 18-01 required federal agencies to authenticate outbound email and set a DMARC policy of reject, establishing the template that private-sector compliance frameworks and mailbox providers later borrowed. Google and Yahoo followed with bulk sender rules that made DMARC a prerequisite for reliable inbox delivery, not an optional hardening step.

Yet most domains still aren't watching their own mail. EasyDMARC's 2025 DMARC Adoption Report, based on more than 1.8 million domains, found that over 80 percent still have no DMARC record at all or sit at a non-enforcing policy, and more than 70 percent of the domains that do have DMARC lack the reporting tag that would actually surface spoofing attempts. That's the gap an MSP is uniquely positioned to close, and reporting on it monthly is what turns a one-time DNS fix into a recurring, visible service line.

This is also where reporting stops being a retention tactic and starts being a sales one. A client who receives a monthly summary showing three blocked spoofing attempts and a tightened DMARC policy is a client primed to ask what else is exposed, which is the natural opening for a conversation about a higher service tier, one that a clear pricing page can turn into a fast yes rather than a renegotiation.

Renewal-Only Reporting vs. Continuous Reporting

Renewal-only reportingContinuous monthly reporting
Client's mental model at renewal"What have they been doing all year?""I already know what they've been doing"
Visibility into blocked threatsCompressed into one slide, easy to disputeDocumented as it happens, hard to dispute
Upsell timingForced, feels like a pitchOrganic, feels like advice
Perceived risk exposureLearned about for the first time at renewalTracked and trending over months

The right column is not more expensive to produce than the left. It's the same scan data, delivered on a schedule instead of stockpiled for one high-stakes meeting.

Building This Into Day-to-Day Operations

An MSP does not need a new department to run continuous reporting, it needs a workflow that turns scheduled domain scans into client-ready output without manual formatting every month. Most technicians already have the raw material sitting in whatever tool checks SPF, DKIM, and DMARC records across the client base. The gap is almost always in the last step: converting that raw data into something a client will actually read.

Teams that are setting this up for the first time typically start by baselining every managed domain, then layering a recurring report on top rather than treating each scan as a one-off audit. The getting-started guide walks through that sequence for MSPs building a scanning cadence from scratch, and most find the report itself becomes the easiest part once the underlying data is standardized across every tenant.

The bigger shift is cultural rather than technical. Reporting has to move from "something we send when a client asks" to "something a client would notice if it stopped arriving." That's the actual definition of a sticky service, and it's cheaper to build than most MSPs assume. Bain & Company's long-running research on customer loyalty found that a five percent improvement in retention can lift profits by 25 to 95 percent depending on the industry, a number large enough that the reporting workflow to get there pays for itself well before the next renewal cycle even comes up.

For MSPs still deciding whether to formalize domain-security reporting as a distinct line item, the fastest way to see what a client-ready report actually looks like is to run one. A trial account through signup turns an existing client's domain into the same kind of monthly output described above, without waiting for the next QBR to find out whether it changes the conversation.

Retention was never really about the renewal call. It was about whether the client spent the preceding twelve months feeling informed or feeling ignored. The MSPs winning that argument aren't doing more security work than everyone else, they're just the only ones showing their clients the work they were already doing.

Further Reading

← Back to all posts
Win MSP Renewals Through Monthly Security Reporting — ActiScan Blog