schedule 12-min read

DMARC Reporting Cadence for Client QBRs

DMARC AI editorial team · Last updated

What MSPs actually show clients in a Quarterly Business Review on DMARC — trend graphs, narrative, what to do when the report is “boring” (good).

01

Introduction

The Quarterly Business Review is the moment when the MSP's recurring DMARC work becomes visible to the client. Done well, it justifies the line item and renews the engagement without anyone having to ask. Done badly, it's three slides of XML aggregated into a bar chart, and the client wonders what they're paying for. This article is the playbook for the well-done version — what to include, what to leave out, how to talk about a quarter where nothing happened (which is the goal), and how to talk about a quarter where something went wrong.

It's the companion to the DMARC for MSPs pillar and the third leg of the operational triad alongside scoping the engagement and pricing it.

02

Why this topic matters

Most MSP service lines have a built-in visibility loop. The help-desk service line generates tickets every time someone has a problem; the client sees the activity. The endpoint-management service line surfaces alerts when an endpoint goes down. DMARC is the opposite — it works invisibly when it's working, and the absence of incidents is the success metric. That makes the QBR uniquely important: it's the only moment when the work becomes visible to the client.

Practices that don't get the QBR right end up either churning recurring clients ("we never see them doing anything, do we need this?") or being forced to manufacture visibility through inflated activity reports that don't survive scrutiny. The right cadence is honest: here's what happened, here's what we did about it, here's what we expect next quarter.

03

The reporting cadence stack

A multi-layer reporting cadence holds up best across practice sizes:

Weekly (internal). The MSP team reviews the portfolio internally — new senders across all clients, policy-state changes, alerts that came in. Operational quality control. Never client-facing.

Monthly (client-facing, low-touch). A short report per client: aggregate stats, anything notable, next-month focus. One page, autogenerated from the platform with minor analyst polish. Delivered by email or through the client portal.

Quarterly (client-facing, high-touch). The QBR. A real conversation with the client about the quarter, the trend across quarters, and what's coming next. Slides, narrative, recommendations. Usually 30-60 minutes of analyst preparation time + 30 minutes of meeting time.

Annually (client-facing, strategic). A year-in-review at the end of each engagement year. Trend graphs across the year, policy progression across the portfolio (for multi-domain clients), recommendations for the year ahead. Doubles as the renewal conversation.

The monthly and quarterly cadences are non-negotiable for any client paying for Tier 3 monitoring. The weekly and annual are nice-to-haves that become non-negotiable above certain client tiers.

04

What to put in the monthly report

The monthly is mostly auto-generated. The shape that holds up:

  • Headline number. "94% of mail from your domain passed DMARC this month" or "Your DMARC policy is at p=reject across all monitored domains." One sentence the client reads first.
  • Aggregate pass-rate graph. A simple line graph of daily pass-rate over the month. Trends matter more than absolute numbers.
  • New senders detected. The list of senders that appeared this month that weren't there last month. Most months this is empty; that's good.
  • Action items. Anything the analyst is working on or has done. Most months this is "nothing significant"; that's also good.
  • Next month focus. Anything queued for the coming month — DKIM rotation due, policy escalation gate approaching, a known scheduled change.

One page, twenty-four months of pattern recognition. The monthly is the proof-of-life that the recurring work is happening.

05

What to put in the QBR

The QBR is the conversation. The shape that holds up:

1. The quarter in one sentence

Open with the headline: "Your DMARC posture is stable; the team handled three new sender additions and one policy progression." If the quarter went well, the headline says so. If it didn't, the headline acknowledges what happened.

2. The trend across quarters

Show the last 4-6 quarters of headline numbers on one slide. Pass-rate trend, policy state across the portfolio, new-sender cadence. The client sees their own trajectory, not just a snapshot.

3. What happened this quarter

The narrative slide. Two or three concrete things the team did: "We onboarded the new acquisition's three domains and brought them to p=quarantine inside 8 weeks." "We resolved the SPF lookup overrun on the marketing tool stack by flattening the include chain." "We identified a phishing campaign impersonating your brand and reported it through standard channels." Real work, real outcomes.

4. What we found

Trend insights from the quarter's aggregate reports. Where the unauthorized sending is coming from, how attack volume against the client's brand has trended, anything in the threat landscape relevant to the client's industry. This is the part that justifies the strategic value of the service, not just the operational value.

5. Recommendations

Three to five concrete recommendations for next quarter. Some flow from the work this quarter (escalate the new acquisition's domains to p=reject); some are forward-looking (the M&A activity may add domains, here's the change-order template ready). Recommendations should be actionable, not vague.

6. The "boring quarter" slide

This is the slide that matters most for QBRs where nothing went wrong. Title: "A quiet quarter is a working quarter." Brief explanation: enforcement is steady, policy is at the target state, the operational work continues invisibly. This frames non-incident quarters as success, not as "what did you do all quarter?"

06

How to talk about a quiet quarter

The most important QBR skill is selling a quiet quarter. The narrative that holds up:

> "This quarter was operationally quiet, which is what we want. Your DMARC posture stayed at the target state across all domains. We processed three platform updates from Microsoft and Google that affected DKIM signing — none required client action because we handled them in the background. Aggregate reports continue to show ~99% DMARC pass rate, with the remaining failures attributable to forwarded mail (expected) and one persistent low-volume spoof campaign that we monitor. The recurring value is the absence of incidents."

The key reframes: "operationally quiet = working as intended", "we handled it in the background = the service is doing exactly what it should", "absence of incidents = the value proposition delivered". Practice this narrative until it sounds natural; it's the most-used narrative in the entire QBR cadence.

07

How to talk about a bad quarter

A bad quarter is one where something went wrong — a misconfiguration caused legitimate mail to be quarantined, an analyst missed an alert, a client-side change introduced a problem that wasn't caught quickly enough. The narrative that holds up:

Lead with the incident. Don't bury it. The client knows something went wrong (otherwise they wouldn't be tense about the meeting); leading with it builds trust.

Walk through the timeline. What was detected, when it was detected, what was done. The timeline tells the client where the response process worked and where it didn't.

Identify the failure mode. Was it a process failure, a tooling failure, a communication failure? Most incidents are process failures; saying so honestly is the right answer.

Describe the fix. What's been done to prevent recurrence — change to operational process, change to alerting configuration, change to the runbook.

Acknowledge the client impact and accept it. If legitimate mail was lost or delayed, acknowledge it directly. Don't minimize. Don't litigate the technical details to deflect blame.

Move forward. The next-quarter recommendations matter more than the past-quarter postmortem. Show the path forward.

Clients renew engagements after bad quarters more often than they renew after quarters where the MSP under-communicated. The honest-but-corrective narrative is the one that holds the relationship.

08

What to leave out

The reverse of the playbook above:

  • Raw XML or screenshots of aggregate reports. The platform's view is for analysts, not clients. Translate, don't display.
  • Activity-as-success theater. "We monitored 47,000 reports this quarter!" is meaningless to the client. Outcomes matter; activity counts don't.
  • Generic security industry trend slides. A client doesn't need a generic threat-landscape briefing in their DMARC QBR; they need their own posture explained.
  • Open-ended "questions for the client" slides. Bring decisions, not interview questions.
  • Comparisons to "industry averages." The aggregate stats vary so widely that any "average" is misleading; better to compare the client to themselves over time.
  • Sales material for upsells. The QBR is a service review, not a sales meeting. Upsells happen in separate conversations.
09

Delivery format

The format depends on client preference:

Slides via screen share. Most common, works for both technical and non-technical client contacts. 10-15 slides for the quarterly; can run in 30 minutes.

Branded PDF export. For clients who don't want a meeting. The same content as the slides, delivered as a downloadable artefact. Less interaction, but some clients prefer the asynchronous mode.

Live dashboard walkthrough. For technical clients who want to see the platform. Less common; works well for security-team buyers but feels intimidating for non-technical executives.

White-label is non-negotiable across all three formats. The QBR is the MSP's deliverable, not the platform's; the client sees the MSP's brand, not the underlying platform's.

10

Common QBR pitfalls

  • Treating the QBR as a sales meeting. Damages trust. Use a separate cadence for sales conversations.
  • Drowning the client in data. Three numbers, one trend graph, three recommendations. More than that loses the audience.
  • Hiding bad news. Clients notice when QBRs only contain good news. The credibility recovers slowly.
  • Generic templates that don't reference the client's situation. A QBR that could be anyone's is a QBR no one values.
  • Skipping the QBR when nothing happened. This is the worst possible move. The quiet quarter QBR is what justifies the recurring engagement.
  • Misaligned cadence with the client's own QBR cycle. If the client runs QBRs in fiscal quarters that don't match calendar quarters, align with theirs.
11

Step-by-step approach

  1. Build a template per service tier. Tier 1 monitoring clients get a lighter QBR than Tier 3 hardened clients; both get one.
  2. Automate the data pull. The platform should produce the trend graphs and headline numbers; the analyst writes the narrative.
  3. Block calendar time for QBR preparation. 45-60 minutes per client at Tier 3 is realistic. Less for Tier 1.
  4. Schedule QBRs in standing series. Same week of each quarter, same client contact, same format. Predictability builds the cadence into both sides.
  5. Save the narrative slides. The "what happened this quarter" slides accumulate into a year-in-review artefact at engagement-year end.
  6. Review your QBR delivery quarterly internally. What worked, what didn't, what to change. The cadence is itself a deliverable that needs operational ownership.
12

Best practices

  • Lead with the headline. First sentence summarizes the quarter.
  • Show the trend, not just the snapshot. Quarter-over-quarter graphs.
  • Translate, don't display. Raw platform data is for analysts; QBRs are narrative.
  • Sell the boring quarter. Operationally quiet = service working as intended.
  • Don't skip QBRs. Even quiet ones. Especially quiet ones.
  • Three concrete recommendations. Not more, not vague.
  • Align with client's own QBR cycle if it exists.
13

If you're delivering monthly reports but not QBRs, add the QBR cadence to your standard Tier 3 service. The marginal cost is low (45 minutes per client per quarter) and the renewal-rate impact is meaningful. If you're already delivering QBRs but they're data-heavy, rebuild around the narrative-first model — the conversation matters more than the dashboard.

14

FAQ

How long should a QBR meeting actually be?

30 minutes for most clients. Tier 1 clients can be 15-20 minutes. Enterprise clients sometimes need 60 if there's a deep agenda or multiple stakeholders.

Should I include peer/industry benchmarks?

Sparingly. "Most clients in your sector are at p=reject within 4 months" can be useful if it's true. "Industry benchmarks for DMARC adoption" usually isn't. Comparing the client to themselves over time is the better default.

What if the client doesn't want a QBR?

Some don't. Offer a written-only quarterly summary as the alternative — same content, asynchronous delivery. Most clients who decline the meeting still want the written artefact.

How do I handle QBRs for clients still in rollout?

Convert the QBR into a rollout review for the first 2-3 quarters of the engagement. The format is the same; the narrative is "where we are in the rollout, what's coming next, what we're watching."

Should the same person who does the operational work also deliver the QBR?

Ideally yes, especially at smaller practices. The analyst who handles the operations has the most credible narrative. At larger practices, the account manager may lead the meeting with the analyst on-call for technical questions.

How do I handle a client who consistently shows no incidents but starts questioning the value?

Lean into the absence-of-incidents narrative; show the trend across quarters; reference specific things you did in the background. If the conversation persists, demo the alternative scenario: what would have happened if we'd let the new sender go undetected for 90 days. The hypothetical is the close.

15

Final thoughts

The QBR is what makes the recurring engagement visible to the client. Done well, it justifies the service line every quarter without anyone having to ask. Done badly, it's three slides of data with no narrative and the client wonders why they're paying.

Build the cadence early. Refine it across the first year. The QBR is the deliverable that compounds — every quarter it gets a little sharper, the client gets a little more confident, the engagement gets a little stickier.

Related articles

Related tools

Ready to Implement?

Get authenticated mail moving in minutes — start free, book a guided demo, or talk to the team about your stack.