A DMARC Platform Built for UK MSPs
Most DMARC tooling is built for the organisation that owns one domain. An MSP owns a portfolio: forty clients, ninety domains, a dozen half-forgotten brand registrations, and a service desk that needs to know which of them is safe to move to enforcement this month.
DMARC AI treats the portfolio as the primary object. Domains are added individually rather than licensed per seat, reporting is built to be handed to a client rather than interpreted by the engineer who configured it, and the pricing model gets better as the book grows instead of worse.
Per-seat licensing punishes exactly the clients where DMARC matters most.
DMARC operates at the domain level. A client with 400 mailboxes on one domain is the same amount of DMARC work as a client with 12 mailboxes on one domain — the same record, the same sender inventory, the same policy decision. Per-seat pricing does not reflect that, and gateway suites that bundle DMARC as one feature among many are licensed against a single tenant because that is who they were designed for.
The consequences show up in the sales conversation. A per-seat model makes your smallest clients unprofitable to protect and your largest clients expensive to quote, so the service line ends up applied selectively — which defeats the point, because the domain most likely to be spoofed in a supply-chain invoice fraud is rarely the biggest one on the book.
The second problem is operational rather than commercial. Single-tenant tooling means a separate login, a separate report and a separate configuration per client. At five clients that is annoying. At sixty it is a person, and that person is not billable.
The per-seat shape
- removeCost scales with headcount, which has nothing to do with DMARC effort.
- removeOne tenant per licence, so a portfolio means a stack of separate accounts.
- removeLegacy brand domains that send no mail still cost you something to watch.
- removeQuoting requires a per-client calculation before you can name a price.
The per-domain shape
- check_circleCost tracks the unit of work — one domain, one record, one inventory.
- check_circleOne account, every client inside it, separated by tenant.
- check_circleFrom just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.
- check_circleYou can quote the service line on the first call without a pricing cycle.
One account. Every client. Properly separated.
Multi-tenancy is not a dashboard filter bolted onto a single-tenant product. It changes what an engineer can see, what a client can see, and how long it takes to answer the question "which of our domains is at risk this week".
Portfolio view first
Open the platform and see every client domain, its current policy, its pass rate and whether anything moved since last week. Sort by risk rather than alphabetically, so the domain that just picked up an unrecognised sender surfaces without anyone going looking for it.
Tenant separation
Each client sits in its own tenant with its own data and its own reporting. You can hand a single tenant to a colleague, or to the client, without exposing the rest of the book — which matters when two clients on your portfolio are competitors.
Add a domain in minutes
Adding a domain is publishing a record and pointing rua= at the platform. There is no per-client deployment, no agent and no tenant-to-tenant integration work, so bringing a new client onto the service line is a DNS change rather than a project.
The report is the product the client actually buys.
Clients do not experience DMARC. They cannot see the record, they do not read the reports, and if the rollout goes well nothing visible happens to them at all. What they experience is the monthly report — which means the report is the thing that renews the contract.
Reporting that needs an engineer to translate it costs you twice: once in unbillable time, and again in the credibility gap when a client asks a question the report should have answered. DMARC AI produces output designed to go to a client without a rewrite: current policy, which senders are legitimate, what failed and why, what changed this month, and what happens next.
For UK public sector clients the reporting carries extra weight. Since Mail Check was retired on 31 March 2026 there is no free government-run findings service, so an organisation that needs to evidence its anti-spoofing position to an assurance route now has to produce that evidence itself — usually via its MSP. GOV.UK's Securing government email guidance still requires public sector organisations to have DMARC, DKIM and SPF records in place; the obligation did not retire with the tool.
One thing worth stating plainly to clients, because it gets oversold elsewhere: DMARC is not a Cyber Essentials control. Cyber Essentials v3.3 covers firewalls, secure configuration, security update management, user access control and malware protection — email authentication is not among them. Sell DMARC on spoofing risk and deliverability, which are real, rather than on a certification requirement that does not exist.
Findings, not XML.
Aggregate reports are machine-readable summaries that receivers send daily to the address in your rua= tag. Reading them by hand for one domain is tolerable. Across ninety domains the useful signal — a new sender appearing, a pass rate slipping — is invisible to the naked eye.
Every source, named
The platform resolves sending IPs into recognisable sources — Microsoft 365, the CRM, the ticketing system, the payroll provider, the fundraising platform the charity signed up for without telling anyone. That list is the artefact that justifies the engagement to the client, and it is usually longer than the client expects.
Alignment failures explained
A failing sender is reported in terms of the fix: the missing SPF include, the DKIM selector that needs a custom signing domain rather than the provider's generic signature, the subdomain sending outside the parent policy. Guidance an engineer can act on without first learning to read the report format.
New senders surface fast
The most common way an enforced domain breaks is a department signing up for a SaaS tool that sends on the domain's behalf. Continuous monitoring catches the new source in the reports, which turns a potential outage into a change request. Detail on the UK monitoring page.
All-or-nothing, done safely
DMARCbis — RFC 9989, published May 2026 — removed the pct= tag, so there is no partial ramp any more. The rollout is p=none → p=quarantine → p=reject, and inventory completeness is now the safety mechanism. The platform tells you whether the inventory is stable enough to take the next step.
A recurring line with a cost base you already know.
Full breakdown on the UK pricing page, and the packaging patterns on the MSP practice guide.
Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains. There is no free tier — a free trial only. We would rather say that plainly than advertise a free plan that quietly stops being useful at the point you need it most.
The commercial case is not really about platform cost, though. It is that the work is permanent. The DNS record is published once, but new SaaS signups, brand acquisitions, subdomain delegations, DKIM key rotations and quarterly policy reviews mean there is always something to do — and the effort scales sub-linearly across a portfolio because most of it is templated. Adding the ninetieth domain costs you a fraction of what the first one did.
Most UK practices land on three tiers: monitoring (visibility, p=none, a monthly report), active management (monitoring plus authentication fixes and the move to p=quarantine), and hardened (enforcement at p=reject, plus MTA-STS and BIMI where the brand wants it). The gate between each tier protects both sides from premature enforcement.
Two things make the UK conversation easier than it was. Mail Check's retirement gives you a genuine reason to contact every client on the book, and Gmail's tightened enforcement since November 2025 means the deliverability argument is no longer hypothetical — a client who has had mail temporarily rejected already understands the problem you are selling into.
Bringing a UK client on — and handing them back cleanly.
Both ends of the relationship have a DNS component. Getting the offboarding right matters more than most practices assume, because a reporting address left pointing at your tenant means you keep receiving a former client's data.
Onboarding
- check_circleInventory the client's domains — the primary, the trading names, the lookalike registrations an agency bought years ago, and any parked domains that still resolve.
- check_circleCheck the organisational-domain boundary.
.co.ukis a public suffix, so the organisational domain forexample.co.ukisexample.co.uk— notco.uk. That determines where the record sits and how relaxed alignment is evaluated. - check_circlePublish
p=nonewith the platform reporting address on every domain, including the ones that should never send mail. - check_circleClear any legacy
pct=tag from an older rollout, and repoint anyrua=still aimed at a retired Mail Check address. - check_circleLet two to four weeks of reports accumulate before drawing conclusions. Annual and quarterly senders will not appear in week one.
Offboarding
- check_circleRewrite
rua=to the client's own reporting endpoint or their new provider's, and confirm the change has propagated before you close the ticket. - check_circleRemove any delegation or verification records the platform relied on.
- check_circleDocument the current
p=state in writing so the next owner does not roll enforcement back by accident. - check_circleHand over the sender inventory as a static document. It is the most valuable artefact of the engagement and the client is entitled to it.
- check_circleRemove the domain from the portfolio so you stop billing for it and stop receiving data you no longer have a basis to hold.
For the avoidance of doubt on public sector tenders: DMARC AI is not NCSC-approved, endorsed or certified, and the NCSC does not endorse individual DMARC products. It published a vendor-neutral buyer's guide for external attack surface management tools and left the selection to the buyer. Background on the Mail Check replacement page.
The rest of the UK cluster.
Questions UK MSPs ask us.
How is this different from running DMARC in a general email security suite? add
Gateway and email-security suites usually treat DMARC as one feature among many, and are licensed per seat against a single tenant. That shape fits an end customer, not a provider managing many customers.
An MSP-first platform inverts the model: the portfolio is the primary object, domains are added individually rather than per seat, and reporting is designed to be handed to a client rather than read by the person who configured it.
What happens when we offboard a client? add
Remove the domain from the portfolio and hand back the DNS. The practical thing to get right is the reporting address: if the client's DMARC record still points its rua= at your tenant after they leave, you keep receiving their data, which is a problem for both parties.
Offboarding should include rewriting the DMARC record to the client's own reporting endpoint, removing any delegation records, and clearing any legacy pct= tag left over from an older rollout — that tag was removed in DMARCbis (RFC 9989).
How many domains before the pricing makes sense? add
The pricing is volume-based and starts at £1 per domain per month, with the per-domain price falling as you add domains, so the economics improve rather than degrade as the portfolio grows.
The more useful question is usually margin per client rather than platform cost. Most practices bill DMARC as a monitoring-and-enforcement line with a monthly report; the platform cost per domain is typically a small fraction of what the service line bills.
Do we need to be a DNS expert to run this? add
You need to be comfortable editing DNS records, but the analysis is automated. The platform parses aggregate reports, identifies senders, and gives remediation guidance rather than leaving you to read raw XML.
The judgement calls that remain are genuinely operational: deciding when a sender inventory is complete enough to move to enforcement, and knowing which third-party senders a given client actually uses.
Can we trial it on our own domain first? add
Yes, and we would encourage it. Running your own MSP domain through the platform first means you understand the reporting before you put it in front of a client, and your own domain is usually the one your clients are most likely to see spoofed.
Put your own domain through it first.
Start a free trial, add your MSP domain, and see the reporting before you put it in front of a client. Transparent MSP pricing from just £1 per domain per month, with volume-based pricing where the per-domain price falls as you add domains.