Introduction
A new standard is one of the few genuinely good reasons to reopen a conversation with every client at once. When the IETF published DMARCbis in May 2026 — RFC 9989, RFC 9990 and RFC 9991, obsoleting the 2015 RFC 7489 — it gave managed-services providers a credible, time-bound reason to review posture, refresh deliverables and, where appropriate, expand scope. The technical changes are modest and legacy-tolerant, but that is beside the commercial point. What matters for your offering is that "the standard your domains were built on has been replaced" is a sentence clients understand, and it opens the door to a structured review you can charge for.
This article is about translating the technical transition into service packaging. It assumes you already understand the changes at a technical level and want to turn them into onboarding steps, audit line items, updated reporting and a clean service menu. The organising idea is a commercial hook worth adopting across your materials: modern DMARC compliance. Clients do not buy RFC numbers; they buy the assurance that their email authentication reflects the current standard and is being actively managed against it. For the underlying technical checklist, keep the DMARCbis readiness checklist for MSPs open alongside this.
Why DMARCbis is a commercial moment
Standards changes are rare, and they reset the baseline for what "current" means. A client who signed off on a DMARC configuration two years ago now has a configuration built on an obsoleted specification, and while it very likely still works, it is no longer demonstrably aligned with the standard in force. That gap between "still working" and "current" is the space a service offering lives in. It justifies a review, it justifies updated documentation, and for many clients it justifies moving from a one-time setup to an ongoing managed arrangement.
The framing to avoid is alarmism. Nothing broke overnight, and clients who hear otherwise will trust you less, not more. The effect on client conversations is best handled as calm, expert stewardship: the standard advanced, you have reviewed their posture against it, and here is what you recommend. That tone is what converts a technical event into recurring revenue without ever bashing the client's previous setup or a competitor's.
New and refreshed line items to add
The cleanest way to update an offering is to add specific, nameable steps that map onto work you can actually deliver and invoice. Several fit naturally into an existing MSP motion.
A DMARC standards readiness review belongs in onboarding and in a one-time refresh for existing clients. It confirms that records, tooling and documentation reflect the DMARCbis RFCs rather than the obsoleted one, and it produces a short findings report the client can keep. A domain portfolio audit widens the lens from the primary sending domain to every domain the client owns, including the parked and defensive registrations that are usually the weakest link. Both of these are readily productised because the output is a document and a set of recommendations, not an open-ended engagement.
From there, the technical work of the transition becomes billable scope. A sender inventory and enforcement roadmap reconciles what the client believes sends mail against what the aggregate reports actually show, then lays out the phased path to p=reject. Subdomain and parked-domain checks apply the new np policy for non-existent subdomains and lock down domains that should never send at all. For clients on Microsoft 365, an M365 gateway and ARC review examines the filtering and relay paths where DMARC most often fails in practice — the highest-skill, highest-margin work in the set, and a natural premium tier.
Finally, update the language in your monthly client reports. The reporting refresh is small but visible: describe failure reporting as "failure reporting" rather than the older "forensic" wording, state plainly that reports reflect what receivers choose to send rather than perfect visibility, and lead every report with interpretation rather than raw counts. Clients read the monthly report far more often than they read the initial setup document, so it is where "modern DMARC compliance" becomes something they can see they are paying for.
A tiered service menu you can sell today
The additions above resolve cleanly into a five-tier menu. Each tier is a defensible unit of work with a clear deliverable, and the tiers ladder upward from a light diagnostic to hands-on troubleshooting, so a client can enter wherever their maturity sits and move up over time.
- Basic DMARC health check. A one-time diagnostic of a client's primary domain — SPF, DKIM and DMARC records validated against the current standard — delivered as a short findings report with prioritised recommendations.
- DMARCbis readiness audit. A structured review confirming that records, subdomain policy and documentation reflect RFC 9989, 9990 and 9991, retiring legacy
pctstaging and flagging anything built on the obsoleted specification. - Managed DMARC enforcement. The hands-on engagement that takes a client from monitoring to
p=reject— sender inventory, alignment fixes, phased rollout and the rollback discipline that keeps mail flowing throughout. - Ongoing monitoring and monthly client reporting. The recurring core of the offering: continuous ingestion of aggregate reports, alerting on new or broken senders, and a monthly report written in plain language that leads with decisions rather than data.
- Premium gateway, ARC and Microsoft 365 troubleshooting. The specialist tier for clients whose mail traverses a secure gateway or complex relay path, where DMARC failures need real diagnostic skill to resolve — the highest-margin work in the menu.
Presenting the offering as a ladder rather than a single package does two useful things. It gives price-sensitive clients an affordable entry point that still generates a findings report you can upsell from, and it gives mature clients a clear reason to sit at the recurring tiers where the margin is. Most practices will find the recurring monitoring tier is where the business actually compounds, with the readiness audit and health check acting as the on-ramps that feed it.
Put the scope in the paperwork
A refreshed offering is only as durable as the agreement behind it. When you add readiness reviews, portfolio audits and enforcement roadmaps to what you deliver, the corresponding scope, responsibilities and boundaries belong in the master services agreement and statements of work rather than in an email thread. This is what protects you when a client's marketing team stands up a new sending platform without telling anyone and then asks why mail is being quarantined — the SOW should already say who owns sender inventory and how change requests are handled. The mechanics of scoping DMARC cleanly in those documents are covered in how MSPs scope DMARC in MSA and SOW templates, and DMARCbis is a natural prompt to revisit that language while you are updating everything else.
Recommended next step
Treat the standards change as a scheduled refresh of your entire DMARC line, not a scramble. Run every client domain through a readiness pass, add the readiness review to your onboarding checklist, update your monthly report template, and publish the five-tier menu so your account managers have something concrete to sell. A single portfolio-wide audit is usually enough to surface the parked domains, legacy staging and unmonitored subdomains that justify the conversation, and it gives each client a specific, non-alarmist reason to move up a tier. The DMARC for MSPs pillar connects the commercial and technical threads for a practice building this out, and the readiness checklist gives your engineers the work-through detail behind each service tier.
Modern DMARC compliance is not a product feature; it is a promise that a client's email authentication is current and actively managed. DMARCbis is the moment to make that promise explicit, price it, and put it on the menu.
Related articles
- DMARCbis readiness checklist for MSPs
- How the new DMARC standard affects client conversations
- How MSPs scope DMARC in MSA and SOW templates
- DMARC for MSPs — complete guide
Authoritative references
- RFC 9989 — core DMARC protocol
- RFC 9990 — DMARC aggregate reporting
- RFC 9991 — DMARC failure reporting
- RFC 7489 — the obsoleted 2015 specification
Author: DMARC AI editorial team Last updated: August 2026