Platform
Past the pass/fail check
DMARC monitoring is table stakes. Client groups, an AI policy advisor, threat intelligence and lead enrichment are what turn it into an MSP security practice.
Multi-client, for real
Domain Groups
Each client's domains live in their own group. Pick a client from the selector at the top of the dashboard and every scan, report and finding narrows to them. Built for an MSP running dozens of clients, not a single-company tool with a filter added on.
- One selector for the whole dashboard
- Switches the moment you pick a client
- No re-navigating page by page
Client
Brightsmile Dental
3 domains · average grade A−
AI-assisted, not AI-guessed
DMARC Policy Advisor
Moving from p=none to quarantine or reject without breaking real mail is the part most DMARC tools leave to you. Once a domain has DMARC reports on file, the Advisor reads its real mail and recommends the next safe step, instead of a generic nudge to enforce.
- A recommendation with a high, medium or low confidence level
- Names the biggest blocker, when there is one
- Concrete next steps, refreshed as more reports arrive
Recommended next step
High confidenceMove to quarantine at 25%
31,480 messages in 30 days. Every recognised sender passes DMARC except one, and it sends 0.4% of mail.
Biggest blocker
A billing service sends as the domain without DKIM.
- 1. Turn on DKIM in the billing service.
- 2. Step up to quarantine at 25% from the enforcement ladder.
Know who's spoofing your clients
Threat intelligence
DMARC reports list the IP addresses that failed. Most tools stop at the count. ActiScan checks each one against AbuseIPDB's reputation database and shows where the abuse is coming from.
- Top source countries, ranked by message volume
- Abuse score, network and volume for every failing IP
- Coloured by severity, so the worst stand out
Failing sources, by volume
| Source IP | Country | Messages | Abuse score |
|---|---|---|---|
| 185.220.xx.14Hosting provider | NL | 1,204 | 100 |
| 45.141.xx.87Cloud VPS | RU | 866 | 92 |
| 103.76.xx.201Data centre | VN | 412 | 61 |
| 91.92.xx.33Hosting provider | BG | 95 | 18 |
From scan to sales conversation
Lead enrichment and hot-lead alerts
The scan widget on your website grades every prospect's domain and scores the lead from it. One click finds IT decision-makers at that company through Apollo, and a high-risk lead alerts your team the moment it arrives.
- Up to 3 verified IT contacts with work emails, per company
- High-risk leads alert Slack or Discord instantly
- The same channels your scan alerts already use
lakeview-dental.com
Scanned from your website widget · grade D
Sent to your team's Slack
IT contacts found
Questions
Do I need to set anything up to use these?+
Domain Groups work as soon as you have more than one client. The Policy Advisor and threat intelligence need DMARC reports for the domain first, and then run from its report page. Lead enrichment and hot-lead alerts work through the website widget on the prospecting page; Slack or Discord alerts need a webhook connected once in Settings.
Is the threat view a world map?+
No, it's a ranked list of source countries. AbuseIPDB gives country-level locations, not cities or coordinates, so a ranked list is what the data can honestly support.
Does the Policy Advisor change DNS records for me?+
No. The Advisor recommends. Each enforcement step is published from the domain's enforcement ladder, by an owner or admin in one click, or by the enforcement autopilot if you've switched it on for that client.
How many contacts does "Find IT contacts" return?+
Up to 3 verified IT contacts per company (IT manager, IT director, CIO and similar titles), each with a work email found through Apollo. The cap keeps the cost of each lookup predictable.
Want the lead-capture widget itself? See the prospecting page
See it on your own clients
Add your client domains and scan them in minutes. Free for 30 days, with no sales call.