Email Security
Why Email Security Just Became a Standard Line Item, Not an Upsell
September 17, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

A domain without SPF, DKIM, and DMARC used to be a sales opportunity. An MSP could point to a prospect's exposed inbox, describe what a spoofed invoice could cost, and close a premium add-on. That pitch still works in a slide deck, but the underlying assumption behind it has quietly stopped being true. Email authentication is no longer a differentiator an MSP sells into. It is a condition the mailbox providers, the card networks, and the insurance underwriters now require just to keep mail moving and claims payable.
The shift is structural, not seasonal. Bulk sending thresholds, breach-cost data, and audit language have converged on the same conclusion: unauthenticated mail is now treated as a compliance and delivery failure, not a nice-to-have improvement, which means email security has moved from the optional line item on an MSP quote to the baseline every client contract now assumes is already covered.
What Changed to Make Email Authentication Non-Negotiable?
Three of the largest inbox providers on earth built enforcement into the plumbing of email itself. Google's own guidance states that a bulk sender is any domain sending close to 5,000 or more messages to personal Gmail accounts within 24 hours, and that domain must now meet Google's email sender guidelines or risk rejection rather than a spam-folder landing. Microsoft followed on the same logic for Outlook.com, Hotmail, and Live.com addresses, confirming in its own announcement that as of May 5, 2025 it would begin rejecting messages that fail SPF, DKIM, and DMARC checks outright rather than routing them to junk.
That is not a marketing suggestion buried in a best-practices PDF. It is a protocol-level gate that every domain sending meaningful volume now has to clear, and it applies whether the sender is a Fortune 500 marketing team or a twelve-person accounting firm using its domain to send monthly statements.
| Provider | Bulk sender threshold | Enforcement start | Failure result |
|---|---|---|---|
| Google (Gmail) | ~5,000 msgs/day | February 2024 | Temporary or permanent rejection |
| Yahoo/AOL | Not fixed volume | February 2024 | Bounce or spam placement |
| Microsoft (Outlook.com) | 5,000 msgs/day | May 5, 2025 | SMTP 550 rejection |
How Are Regulators and Insurers Raising the Floor Further?
Mailbox providers set the delivery bar, but compliance frameworks and insurers now set the coverage bar, and both point to the same three protocols. The Payment Card Industry Security Standards Council folded anti-phishing controls into PCI DSS v4.0.1 Requirement 5.4.1, which became mandatory on March 31, 2025, and its own guidance names DMARC, SPF, and DKIM as the anti-spoofing controls entities are encouraged to deploy, explicitly noting the requirement is not satisfied by security awareness training alone.
The federal government moved even earlier. CISA's Binding Operational Directive 18-01, in effect since 2017, still requires federal executive branch agencies to enforce a DMARC policy of p=reject, and CISA's own directive page frames this as reducing the ease with which email fraudulently uses a federal domain. Cyber insurers have absorbed the same logic into underwriting. Gallagher's 2025 Cyber Insurance Market Conditions Outlook, produced by one of the world's largest insurance brokerages, documents that carriers are now evaluating security posture "more granularly," with email authentication named alongside MFA, EDR, and backup practices as a specific factor in pricing and coverage decisions.
The financial backdrop makes the underwriting logic easy to follow. The FBI's Internet Crime Complaint Center reported that 2024 losses reached a record $16.6 billion across all categories, and business email compromise alone accounted for roughly $2.77 billion in reported losses that year. When a control costs a few hours of DNS work and the loss category it prevents runs into the billions annually, underwriters have every incentive to ask about it by name on the application.
Why Are MSPs Feeling the Squeeze First?
MSPs sit at the exact point where all three pressures land at once. A client's domain has to pass mailbox-provider authentication checks to keep client newsletters and invoices arriving, has to satisfy PCI or insurer questionnaires if the client touches payment data or wants coverage, and has to survive the reputational hit of a spoofed executive email regardless of whether either compliance box was ever checked.
This is why the framing of email security as a premium tier no longer holds up commercially. A client whose domain gets flagged by Gmail's compliance dashboard or bounced by Outlook does not experience that as an unmet upsell opportunity. They experience it as the MSP failing to keep basic infrastructure working, which is a much harder conversation than the one about whether DMARC was ever pitched as an add-on. For an MSP managing dozens of client domains, verifying that every one of them still has aligned SPF, valid DKIM selectors, and a DMARC policy above p=none is no longer a project. It is baseline hygiene that belongs in the same tier as patching and backup verification.
What This Means for How MSPs Price and Package Email Security
Bundling authentication monitoring into the standard managed services agreement, rather than quoting it separately, reflects where the market has already landed. A few practical shifts follow from that:
- Domain authentication status (SPF, DKIM, DMARC alignment, and policy strength) should be checked on the same cadence as patch compliance, not treated as a one-time setup task.
- Client onboarding should include a baseline authentication audit before the first invoice goes out, since a client already failing bulk sender requirements is already leaking deliverability and reputation.
- Reporting to clients should translate DMARC aggregate data into the language of risk and compliance, not raw XML, since that is the language insurers and auditors are now asking clients to speak.
None of this requires reinventing an MSP's service catalog. It requires moving a control that used to sit in the "security upsell" column into the row every managed services agreement already covers, the same way MFA enforcement and endpoint patching moved from optional to assumed over the last five years. MSPs evaluating how to structure that shift can walk through the mechanics in the getting-started guide, which covers what a baseline domain scan should check before a technician ever touches DNS.
The pricing conversation follows naturally once the scope is right. Authentication monitoring, bulk-sender compliance tracking, and DMARC reporting scale differently than endpoint counts, and MSPs comparing how that fits into existing per-seat or per-domain billing can review current pricing tiers to see how a scanning layer sits alongside the rest of a security stack rather than beside it as a separate quote line.
The Standard Just Moved, Not the Threat
Email-based fraud did not suddenly become more dangerous this year. What changed is that the parties who used to tolerate unauthenticated mail, the mailbox providers, the card networks, the insurers, stopped doing so at roughly the same time. That convergence is what turned a security nicety into infrastructure, and it means the MSPs who treated DMARC as a premium line item are now the ones explaining to a client why a Gmail rejection wasn't caught sooner.
Domains that have not been audited for SPF alignment, DKIM signing, and DMARC policy strength recently are a bigger liability today than they were eighteen months ago, not because the attack changed but because the tolerance for the gap disappeared. MSPs that want to see where their client domains stand against the current bulk-sender and authentication baselines can run that check directly by creating an account through the sign-up page and reviewing the results against the thresholds outlined above.