ActiScan

MSP Operations

Stop Pricing DMARC Monitoring Like a Tool. Start Pricing It Like an Outcome.

September 4, 2026

Ric Hall, CRO— AI-assisted and reviewed prior to publication.

Open brass padlock beside a bundle of envelopes on a workbench, symbolizing unlocked email trust

Walk through most MSP service catalogs and DMARC monitoring shows up in the same place every time: a checkbox line item bundled under "email security add-ons," priced somewhere between a spam filter and a password manager. That placement is a pricing decision, and it is the wrong one. It treats a governance and brand-protection function as if it were a utility, and it caps what an MSP can charge for work that actually prevents six and seven-figure fraud losses.

The core argument here is simple. DMARC monitoring should be priced against the outcome it produces, not the software that runs it. That outcome is measurable: fewer spoofed emails reaching inboxes, better sender reputation with Gmail and Microsoft, and a documented path from passive visibility to active enforcement. Clients will pay for that story. Few will pay extra for a dashboard.

Why Is DMARC Monitoring Still Sold Like a Commodity?

Because it started life as a technical afterthought bolted onto RMM and email gateway stacks, and pricing habits from that era never got revisited. A DMARC record is just a DNS TXT entry, and the temptation is to price it like one: cheap, automated, low-touch.

That framing ignores what the record actually does once it is enforced. Under the specification, a domain owner publishing a policy of reject is asking receiving mail servers to block messages that fail authentication and alignment, while quarantine routes them to spam and none does nothing but generate reports, as laid out in the original DMARC specification. Selling "we'll monitor your DMARC record" undersells the fact that the real product is walking a client from that passive none state to an enforced policy that actually stops impersonation.

What Outcome Are Clients Actually Buying?

They are buying protection against having their own domain used to defraud their customers, vendors, and employees. The FBI's Internet Crime Complaint Center recorded a staggering $16.6 billion in reported cybercrime losses for 2024, with business email compromise remaining one of the costliest categories tracked in that report, at close to $2.8 billion in reported losses for the year alone, according to the 2024 IC3 Annual Report.

That figure only counts complaints that reached IC3, and BEC schemes specifically rely on a spoofed or compromised sender identity to trick someone into a wire transfer, an invoice change, or a credential handoff. A DMARC record at enforcement is one of the few controls that directly closes the exact-domain-spoofing version of that attack. That is the outcome. It is not "a DNS record exists." It is "our domain can no longer be weaponized against the people who trust our name in their inbox."

The Enforcement Gap Is Where the Sales Conversation Lives

Most domains that have DMARC still are not protected by it. EasyDMARC's 2026 adoption research, built from an analysis of 1.8 million domains alongside the Fortune 500 and Inc. 5000, found valid DMARC adoption climbing to 937,931 domains, yet 525,996 of those domains remained parked at a monitor-only policy with no active blocking in place, according to the 2026 DMARC Adoption Report. Adoption has become widespread largely because mailbox providers forced the issue, not because organizations chased enforcement on their own.

That forcing function is real and dated. Google and Yahoo began requiring bulk senders (5,000 or more messages a day) to authenticate mail with DMARC starting in February 2024, and Microsoft followed with its own bulk sender rejection policy that took effect on May 5, 2025, as documented in guidance on Gmail and Yahoo DMARC requirements. Google's own sender guidelines FAQ confirms that bulk senders are expected to align DMARC with SPF or DKIM, and that non-compliant mail can face escalating delivery penalties, per Google's Email sender guidelines FAQ.

That combination, mandates that only require a published policy plus a market that mostly stops at p=none, is exactly where an MSP's value gets created. Anyone can help a client publish a record that satisfies a mailbox provider's minimum bar. Getting that client to reject without breaking legitimate mail flows is a project, not a checkbox, and it deserves project-level pricing.

How Should MSPs Structure Outcome-Based Pricing?

Structure it around the maturity stage a domain is moving through, not around per-domain or per-seat counts. Each stage has a different labor profile, a different risk profile for the client, and a different amount of ongoing value delivered, which is the same logic behind value-based pricing gaining traction across the broader managed services market. Industry analysis from TSIA notes that value-based and consumption-based pricing models are increasingly associated with stronger growth outcomes for MSPs compared to legacy cost-plus billing, according to TSIA's research on MSP pricing models.

A simple three-tier structure maps cleanly onto that logic:

StageWhat the MSP deliversClient-facing outcome
VisibilityRecord published, aggregate reports parsed, senders inventoriedFull picture of who is sending as the domain
AlignmentSPF/DKIM corrected, shadow IT senders fixed, policy moved to quarantineSpoofed mail starts landing in spam, not the inbox
EnforcementPolicy moved to reject, ongoing monitoring for new sendersDomain can no longer be spoofed for BEC or phishing

Each stage justifies a different price point because each stage removes a different amount of business risk. Charging the same flat fee across all three treats a client who just published their first record the same as one whose domain is fully locked down, which leaves real money on the table for the harder, higher-value work.

Packaging the Journey Instead of the Feature

Clients rarely understand DNS policy tags, and they should not have to. What they understand is a plain sentence: "your domain currently cannot stop someone from sending fake invoices as you." That sentence sells the alignment and enforcement tiers far better than a spec sheet ever will.

This is also where onboarding mechanics matter for margin. A structured rollout, using a getting-started guide that walks a new client from initial scan through policy changes, keeps the labor predictable enough to price it as a fixed-fee engagement rather than open-ended hourly work. MSPs that skip that structure tend to either underprice the enforcement stage because they cannot estimate the hours, or they avoid selling it at all and leave clients stuck at p=none indefinitely.

Pricing pages should reflect the same tiering. A pricing structure built around visibility, alignment, and enforcement tiers gives sales conversations a natural upsell path instead of a single take-it-or-leave-it monitoring fee. When a prospect is ready to move, routing them through a straightforward sign-up flow turns that pricing conversation into an active engagement instead of a stalled quote.

Making the Business Case Land With Clients

Two numbers do most of the persuading. First, the billions in BEC losses reported to IC3 establish that the threat is not hypothetical. Second, the enforcement gap in EasyDMARC's data establishes that most of the client's peers have not solved this, which reframes enforcement as a competitive posture rather than a compliance chore.

Neither number requires a guarantee. Nobody selling DMARC services should promise a specific compliance outcome or claim the service replaces a security team, and none of that framing is necessary anyway. The honest pitch is narrower and stronger: enforcement closes a specific, well-documented attack path, most domains have not closed it yet, and getting there is a scoped project worth paying for in stages rather than a line item worth arguing over every renewal.

That is the entire case for pricing DMARC monitoring like an outcome. The record is cheap to publish. Getting a domain to a state where spoofed mail actually gets blocked is the work clients are paying for, and it is worth pricing like the risk reduction it delivers.

← Back to all posts