ActiScan

MSP Operations

Stop Selling DMARC as a Project. Start Selling It as a Line Item.

August 25, 2026

Ric Hall, CRO— AI-assisted and reviewed prior to publication.

Technician's hands adjusting server cabling beside a laptop showing live email authentication logs

A DMARC record is not a light switch. It is a policy that has to be watched, tuned, and defended against a mail ecosystem that keeps changing the rules underneath it. Yet plenty of MSPs still sell it the way they sell a firewall replacement: scope it, install it, invoice it, move on. That framing is costing them money and quietly leaving clients exposed.

Why does treating DMARC as a project fail clients?

Because DMARC is not a finished state, it is a moving target that requires ongoing DNS hygiene, SPF flattening, new sending-service onboarding, and policy escalation from monitoring to enforcement. A project mindset closes the ticket at p=none, which is functionally the same as having no DMARC record at all for stopping spoofed mail. Clients who bought "DMARC setup" as a one-time deliverable are almost always still sitting unprotected months later.

That last point is not speculation. Independent tracking of DMARC records across the internet found that only 28.5% of domains with a published DMARC record have reached p=reject enforcement, the policy level that actually blocks spoofed mail rather than just reporting on it. The rest are parked at monitoring-only, often because whoever set the record up moved on to the next ticket before anyone pushed the policy to quarantine or reject. A record that never advances past p=none is a compliance checkbox, not a defense.

The market already priced this in, even if your contracts haven't

Mailbox providers stopped treating email authentication as optional years ago, and the deadlines have compounding effects for every domain an MSP manages. Google requires bulk senders, defined as anyone sending more than 5,000 messages a day to Gmail addresses, to authenticate with SPF, DKIM, and DMARC, a rule that has been enforced since February 2024 and now results in rejections for non-compliant traffic. Yahoo moved in lockstep with nearly identical requirements the same year. Microsoft followed with its own bulk-sender authentication mandate for Outlook.com, Hotmail, and Live.com addresses, with enforcement beginning May 5, 2025 for anyone sending over 5,000 messages a day to those domains.

PCI DSS 4.0 added another pressure point, with a March 31, 2025 deadline for organizations handling cardholder data to implement DMARC as part of their broader email security controls. Federal agencies have had a hard mandate even longer: CISA's Binding Operational Directive 18-01, issued back in 2017, required agencies to move to a DMARC policy of "reject" for all second-level domains and mail-sending hosts within one year. None of these mandates are static. They are the floor, and the floor keeps rising.

Adoption is climbing in response, but unevenly. One large-scale analysis of top domains found DMARC adoption rose from 27.2% to 47.7% between 2023 and 2025, with enforcement-level policies growing by roughly 50% over the same window, according to the EasyDMARC 2025 DMARC Adoption Report. That growth curve is exactly the kind of moving landscape a static, one-time project cannot track.

What does a client actually get if they buy DMARC as a line item instead?

They get continuous enforcement management: someone watching aggregate and forensic reports, adjusting SPF records as the client adds new SaaS tools that send mail on their behalf, and pushing the policy from none to quarantine to reject as confidence builds. That is a service, not a delivery. It belongs on the recurring line of the invoice next to patching and backup monitoring, not in the one-time setup column.

The technical reality behind DMARC makes recurring service unavoidable. The DMARC specification itself, RFC 7489, was built around a feedback loop: domain owners publish policy, receivers send back aggregate reports, and domain owners use those reports to refine the policy over time. That loop does not have a natural end date. Every new marketing platform, CRM, or helpdesk tool a client connects to their domain is a new sender that has to be authenticated or the policy breaks silently.

This is precisely the operational reality that makes DMARC monitoring a natural recurring-revenue category rather than a one-off SKU. Bundling ongoing cybersecurity services into predictable monthly pricing is already a proven pattern for MSPs building recurring revenue, and DMARC fits that model better than almost anything else in the security stack because the reporting infrastructure is built to generate a steady stream of actionable signal, not a single pass/fail result.

Reframing the sales conversation

The pitch changes once DMARC is positioned as an ongoing service rather than a deliverable. Instead of "we'll get your DMARC record set up," the conversation becomes "we monitor your domain's authentication posture every month and tighten enforcement as your sending sources stabilize." That is a subscription pitch, not a project quote, and it maps cleanly onto the way MSPs already sell managed detection, patch management, and backup verification.

A simple comparison shows why the framing matters for how the client experiences risk:

ApproachWhat client buysWhat happens after go-live
ProjectA configured DMARC record at p=noneNothing, until the next audit or breach forces a revisit
Line itemOngoing monitoring, alerting, and policy escalationContinuous tightening toward p=reject as sources are verified

Framing DMARC as a line item also changes how an MSP scopes new client onboarding. A getting-started guide that walks a technician through initial record discovery, SPF consolidation, and the first 30 days of aggregate report review sets the expectation from day one that this is a managed service with a cadence, not a checkbox on a project plan.

Making the economics work

Pricing this correctly requires unbundling DMARC monitoring from generic "email security" packages so its value is visible on its own line. A few practical moves make that easier:

  • Quote enforcement progression (none to quarantine to reject) as a defined service phase with its own milestones, not a single flat fee for "DMARC setup."
  • Price per-domain monitoring monthly, scaled by the number of client domains and subdomains that need authentication, since every unmonitored subdomain is a potential spoofing vector.
  • Attach DMARC status to quarterly business reviews so clients see enforcement progress the same way they see patch compliance or backup success rates.

A published pricing page that separates initial configuration from ongoing monitoring makes this distinction concrete for prospects comparing quotes, rather than burying the recurring value inside a bundled number they will question at renewal.

The competitive edge is in the renewal, not the install

MSPs that still sell DMARC as a project are competing on install price, which is a race to the bottom against anyone who can copy a DNS record. MSPs that sell it as a line item are competing on outcomes, specifically the percentage of client domains sitting at enforcement versus stuck at monitoring-only, a distinction that maps directly to real phishing exposure given how few domains globally have actually reached reject.

That distinction is also what turns a single DMARC engagement into a durable account. Every new client domain, every new marketing tool the client adopts, every mailbox provider that tightens its bulk-sender rules is another reason the monitoring relationship needs to continue. Getting a client from a free trial into that ongoing posture starts with a straightforward path, and a clear sign-up flow that leads into monitoring, rather than a one-time scan, is what actually converts a technical fix into recurring revenue.

DMARC was never designed to be installed once and forgotten. The RFC bakes in a reporting loop precisely because domain owners are expected to keep adjusting. MSPs who build their service catalog and their contracts around that reality will find the renewal conversation is already won before it starts, because the client has been seeing the value delivered every month rather than remembering a single invoice from a year ago.

← Back to all posts