Authwright vs Palisade in 2026
Both platforms let an AI assistant do email authentication work. They differ on who holds the keys to your DNS, how many providers that reaches, and whether the job ends at setup or keeps running.
Our verdict: Pick Palisade if the DMARC work is the job and you would rather not hand a vendor your registrar keys. Pick Authwright if you manage a domain portfolio on one of its five supported registrars and want certificates, renewals and purchases in the same MCP session.
15-day full-product trial. Nothing is charged until it ends.


Palisade's IT-team plans start at $19 a month, sized by email volume. Start with a 15-day full-product trial; nothing is charged until it ends.
Which one is right for you?
Best for Agencies with portfolios on five supported registrars
Best for MSPs and IT teams responsible for multiple domains
- Your domains sit on GoDaddy, Namecheap, Cloudflare, Porkbun or Route 53, the five registrars its adapters reach.
- You want one MCP session to also renew SSL certificates, buy defensive domains, and flip WHOIS privacy, which Palisade does not do.
- Storing registrar API credentials at a vendor is a trade your security review accepts.
- You want the DMARC work carried from report to verified fix, not a one-shot setup run.
- You would rather authorise a scoped, revocable connection in your own DNS provider's window than store registrar API keys at a vendor.
- Your domains are spread across providers: automatic configuration covers 64 of them.
- You need DMARC aggregate reports turned into prioritised tickets with provider-specific fix instructions, plus webhooks and ongoing monitoring.
IT-team plans start at $19 a month, sized by email volume. Start with a 15-day full-product trial; nothing is charged until it ends.
Where the day-to-day work actually differs
| Feature | Authwright | Palisade |
|---|---|---|
| DNS and credentials | ||
| Publishes approved records into your own DNS without holding your credentialsWhether approved DNS records can be published without storing registrar credentials.Authwright: registrar API key and secret stored in its workspace Source (2026-08-20) | Stores registrar credentials | Provider-window authorization |
| Assistant can write the corrected records, not just recommend themWhether an assistant can publish corrected DNS records after approval.Both; Authwright writes at the registrar, Palisade through the connection you authorise | Registrar record writes | Approved zone writes |
| Automatic configuration across 64 DNS providersWhether automatic DNS configuration reaches providers across a domain portfolio.Authwright: five registrars (GoDaddy, Namecheap, Cloudflare, Porkbun, Route 53) Source (2026-08-20) | Five registrar adapters | Automatic provider configuration |
| Hosted records served on redundant managed DNS, so nothing is written at your registrar at allWhether email-authentication records can be hosted outside the registrar.Authwright hosts the MTA-STS policy file; other records are written into your zone Source (2026-08-20) | MTA-STS policy only | Redundant managed DNS |
| Ongoing operation | ||
| DMARC aggregate reports become prioritised tickets with provider-specific fix instructionsWhether DMARC reports become prioritised, provider-specific work items.Authwright ingests reports and summarises them for the assistant to read Source (2026-08-20) | No prioritised tickets | Provider-specific work tickets |
| DMARC aggregate report ingestionWhether a product receives DMARC aggregate reports for review.Both; Authwright includes it on every tier | Included on every tier | Agent analyzes reports |
| SPF flattening kept under the 10-lookup limitWhether SPF lookup chains are kept within DNS lookup limits.Both; Authwright bundles it on every tier, and Palisade serves a hosted flattened include whose live lookup budget the assistant can read through get_spf | Included on every tier | One-lookup hosted SPF |
| Webhook endpoints for your own systemsWhether a product can send event data to other systems through webhooks.Source (2026-08-20) | Not advertised | Webhook endpoints |
| Native ConnectWise, HaloPSA and Autotask integrationsWhether a platform connects directly with the named PSA systems.Source (2026-08-20) | Not advertised | Native PSA integrations |
| Connecting an assistant | ||
| Listed in the official MCP registryWhether a server can be discovered in the official MCP registry.Zero results for authwright on registry.modelcontextprotocol.io Source (2026-08-20) | Not listed | Official registry listing |
| OAuth sign-in to connect an assistantWhether an assistant connects through an OAuth sign-in flow.Both; Authwright documents OAuth 2.1 with PKCE via Microsoft Entra ID, plus a portal-issued bridge token for editor clients Source (2026-08-20) Source 2 (2026-08-20) | OAuth with PKCE | OAuth sign-in |
| MCP access included on the entry tierWhether MCP access is available on the lowest-priced tier.Both; Authwright's free workspace covers one account Source (2026-08-20) | One-account free workspace | Included on every plan |
| Registrar portfolio work | ||
| SSL/TLS certificate lifecycle across a portfolioWhether SSL/TLS certificates can be managed across a domain portfolio.Authwright: 7 tools. Outside Palisade's scope | Seven certificate tools | Outside Palisade's scope |
| Domain purchasing, renewals and defensive registrationWhether a tool handles domain purchases, renewals, and defensive registrations.Authwright: 9 portfolio tools. Outside Palisade's scope | Nine portfolio tools | Outside Palisade's scope |
| WHOIS privacy and DNSSEC auditing at portfolio scaleWhether a portfolio tool manages WHOIS privacy and audits DNSSEC.Outside Palisade's scope | Supported | Outside Palisade's scope |
| Commercial terms | ||
| Published rates you can read before contacting anyoneWhether a buyer can see prices before requesting a quote.Authwright names Free, Agency Plus and Enterprise without publishing numeric rates on its public homepage. Source (2026-08-20) | Rates not published | Published IT pricing |
| AI and automation access | ||
| Documented REST or GraphQL API for domain dataWhether customers can build against a published REST or GraphQL reference instead of using only the product's MCP tools.Authwright does not advertise a documented REST or GraphQL API on its public homepage or capabilities page. It describes its published programmatic interface as a Model Context Protocol server (checked 2026-08-27). Source (2026-08-27) Source 2 (2026-08-27) | No public API listed | REST API published |
| MCP server for connecting AI assistants to domain dataWhether an AI assistant can reach the product's domain-management tools directly.Both; Authwright publishes a 42-tool Model Context Protocol server over streamable HTTP with OAuth 2.1 and PKCE, for use from MCP-compatible clients (checked 2026-08-27). Source (2026-08-27) | MCP server published | MCP server published |
| AI assistant can run an email-authentication workflowWhether the vendor advertises an AI-driven workflow for email-authentication work and states what it does.Both; Authwright advertises its email_auth_wizard MCP tool as an LLM-driven workflow that reads the current state, diagnoses gaps, writes approved records, hosts MTA-STS, verifies propagation, and ingests DMARC reports (checked 2026-08-27). Source (2026-08-27) | LLM runs Email EasyPass | Agent drafts fixes |
| Portfolio data export without opening a dashboardWhether domain-portfolio data can leave the product through a published programmatic interface.Authwright lists export_portfolio in its MCP tool surface and describes a quarterly compliance audit export as a CSV. It does not advertise webhooks on that capabilities page (checked 2026-08-27). Source (2026-08-27) | MCP portfolio export | REST API published |
Want to compare the workflow yourself? Start a 15-day full-product trial of Palisade.
Palisade 91 vs Authwright 76, and why
Both products are scored on the same eight dimensions the comparison hub uses, so the figures here are the figures there. Four are derived from vendor facts that each carry a source and a checked date. Four are editorial, marked as such below, and each states its reasoning and its source.
Each dimension is out of 10 and the total is the raw sum out of 80, rescaled to 100 — the raw figure is printed beside it so the conversion is checkable rather than a black box. Scored on what each vendor publishes, not on how the product feels in use. Editorial dimensions last reviewed 2026-09-02.
How reachable the product is from your own software and AI tools. 10 = a documented API on every plan plus a published MCP server. 6 = an API, gated to a tier or to a sales conversation. 3 = no programmatic access advertised.
Authwright publishes a streamable HTTP MCP server with OAuth 2.1 and PKCE and includes MCP access on the Free plan; a separate public API reference is not published. Source (2026-08-29)
Palisade publishes a REST API and a remote MCP server on every plan, making the same domain data and remediation workflows available to connected software. Source (2026-08-30)
How much of the report analysis is done for you. 10 = the platform turns raw report data into a prioritised, actionable queue on its own.
The published wizard reads the current authentication posture, diagnoses gaps, proposes and applies authorized record changes, and ingests aggregate reports for ongoing summaries. Source (2026-08-29)
Report data is analysed into a prioritised list of sender, SPF, DKIM and DMARC issues, so nobody reads raw XML. Source (2026-08-30)
How much of the work the vendor's own software does. 10 = it identifies the sending sources, drafts the SPF and DKIM fixes each one needs, and proposes the next policy step. 6 = it applies the records for you, but a person decides what to fix and when to advance. 3 = it reports, and every change is yours to make. A vendor whose team does the work rather than its software scores here on the software alone.
The vendor describes LLM-callable MCP workflows that compose diagnostics, DNS changeset previews, authorized writes, propagation checks, and portfolio-scale actions. Source (2026-08-29)
The agent investigates each sender, drafts the SPF and DKIM changes it needs, and proposes the next policy step; a human approves before deployment. Source (2026-08-30)
10 = full pricing published. 6 = some tiers published, rest quote-gated. 3 = quote only.
Free, Pro, Team, Agency, and Agency Plus prices are published; Enterprise is contact-sales. Source (2026-08-29)
10 = hosts the records for you. 6 = partial or add-on. 3 = you manage your own DNS.
Authwright publishes hosted MTA-STS policies and SPF flattening; its public material does not describe it hosting DMARC, DKIM, or BIMI records. Source (2026-08-29)
10 = a genuine free plan. 6 = time-limited trial only. 3 = no free access.
The Free plan includes one domain, one registrar, public audits, MCP server access, and seven-day snapshots. Source (2026-08-29)
No free plan: a 15-day full-product trial; nothing is charged until the trial ends Source (2026-08-30)
10 = a real MSP program with multi-tenant management. 6 = partial. 3 = none.
Agency and Agency Plus plans provide multi-tenant workspaces for domain portfolios; published partner-program terms are not listed. Source (2026-08-29)
How much work it takes to get a domain from p=none to p=reject. 10 = the platform (or the vendor's team) gets you there without manual DNS edits.
Email EasyPass diagnoses email-authentication gaps, proposes the corrected records, writes them after authorization, and verifies propagation across supported registrars. Source (2026-08-29)
The DMARC Agent detects when a domain's authentication and alignment are ready for the next policy stage and proposes the move, but a human still approves and applies it, so it is not fully hands-off. Source (2026-08-30)
Where Palisade and Authwright actually differ
Each argument keeps the product screens, sourced comparison points, and supporting analysis together.
Credential storage vs provider authorization
Who holds the keys to your DNS
This is the real decision between the two, and it is worth getting past the marketing on both sides. Authwright writes DNS records for you, and the way it reaches your zone is by holding your registrar's API credentials. Its onboarding is explicit about it: step three asks you to paste a GoDaddy API key and secret, or a Cloudflare API token, into the portal. Its FAQ says those credentials are encrypted at rest in Azure Key Vault, scoped per domain where the registrar API supports it, and never logged, and it recommends creating a dedicated API user for Authwright on each registrar.Source 1, Source 2
Authwright
A relevant product screenshot was not available in the reviewed evidence.
Palisade
A relevant product screenshot was not available in the reviewed evidence.
- Publishes approved records into your own DNS without holding your credentials: Provider-window authorization
- Assistant can write the corrected records, not just recommend them: Approved zone writes
- Automatic configuration across 64 DNS providers: Automatic provider configuration
That is a reasonable design, handled with more care than most, and it still means a vendor holds keys that can act on your registrar account. A registrar API key is rarely scoped to email authentication alone; on several registrars the same credential can move nameservers, edit unrelated records, or touch billing.
Palisade reaches your DNS a different way. The provider is detected from the domain's live nameservers, and you authorise the connection in that provider's own window. No credentials are shared with Palisade, the access granted is scoped to email-authentication records, and you can revoke it from the provider whenever you want. Records you approve in Palisade are then written into your own zone through that connection. Palisade is not asking for a key it has to store, which is why there is no key to leak.
Five registrars vs broader reach
Five registrars against a wider catalogue
Custody and reach are the same decision seen twice. Because Authwright writes through registrar adapters it has built, it works where an adapter exists: GoDaddy, Namecheap, Cloudflare, Porkbun and Route 53. Its own FAQ says those five "map to the overwhelming majority of agency books" and invites you to email if yours is not covered. Palisade's automatic configuration reaches 64 DNS providers, because it connects through the provider's own authorisation rather than through a credential Palisade had to build a home for.Source 1, Source 2 +1 more
Authwright
A relevant product screenshot was not available in the reviewed evidence.
Palisade
A relevant product screenshot was not available in the reviewed evidence.
- OAuth sign-in to connect an assistant: OAuth sign-in
- MCP access included on the entry tier: Included on every plan
- Published rates you can read before contacting anyone: Published IT pricing
For a book of client domains, that gap decides how much of the book the tooling covers. Five adapters handle a portfolio consolidated at a big registrar. A mixed inheritance, which is what most agencies actually have, spreads past them.
Setup completion vs continuous operation
A setup run against an operating loop
Authwright's flagship is Email EasyPass, its email_auth_wizard tool. Its homepage sets out the sequence: read the current state, diagnose against the Gmail and Yahoo rules, write corrected records at the registrar, host the MTA-STS policy, wait for propagation, verify, then ingest DMARC reports on an ongoing basis and summarise them in plain language. The homepage transcript clocks the run at 47 seconds and moves a score from 32 to 94.Source
Authwright
A relevant product screenshot was not available in the reviewed evidence.
- DMARC aggregate reports become prioritised tickets with provider-specific fix instructions: No prioritised ticketsSource
- DMARC aggregate report ingestion: Included on every tier
- SPF flattening kept under the 10-lookup limit: Included on every tier
Palisade

- DMARC aggregate reports become prioritised tickets with provider-specific fix instructions: Provider-specific work tickets
- DMARC aggregate report ingestion: Agent analyzes reports
- SPF flattening kept under the 10-lookup limit: One-lookup hosted SPF
Getting a domain to a good configuration quickly is genuinely useful, and that sequence does it. The part that decides whether a domain stays there is what happens over the following weeks, when a marketing team adds a sender nobody told you about, or an upstream provider changes its SPF include and the lookup count creeps back over ten.
Palisade is built around that second phase. Aggregate reports feed a work queue: the agent investigates each sending source, works out whether it is legitimate, drafts the fix, and files it as a prioritised ticket with instructions specific to the provider involved. Webhooks push those events into your own systems. The agent investigates every sender, drafts every fix, and proposes each policy step, and you approve before anything ships. The output is a task with an owner rather than a report to read.
Email focus vs portfolio breadth
Where Authwright is the better tool
Authwright is not really a DMARC product with extras. Of its 42 published tools, 8 are email authentication; the other 34 handle DNS records, domain portfolio lifecycle, SSL/TLS, bulk operations and health checks. Its registrar pages make the actual pitch plainly: renewals you keep forgetting, certificates expiring on inconvenient days, WHOIS privacy that flips off after a billing failure, defensive registrations that each cost a trip through a checkout flow.
Authwright
A relevant product screenshot was not available in the reviewed evidence.
- SSL/TLS certificate lifecycle across a portfolio: Seven certificate tools
- Domain purchasing, renewals and defensive registration: Nine portfolio tools
- WHOIS privacy and DNSSEC auditing at portfolio scale: Supported
Palisade
A relevant product screenshot was not available in the reviewed evidence.
- SSL/TLS certificate lifecycle across a portfolio: Outside Palisade's scope
- Domain purchasing, renewals and defensive registration: Outside Palisade's scope
- WHOIS privacy and DNSSEC auditing at portfolio scale: Outside Palisade's scope
If that is the job in front of you, Authwright covers ground Palisade does not and is not trying to. Palisade does not renew certificates, buy domains, manage WHOIS privacy, or audit DNSSEC. An agency whose real problem is a sprawling registrar portfolio should weigh that breadth seriously, and can run both: the two overlap only on the email-authentication tools.
Two smaller things worth knowing before you commit. Authwright is not listed in the official MCP registry, checked on 20 August 2026, so an assistant that discovers servers through the registry will not find it. And its /docs and /pricing URLs both returned 404 that day, which for a product sold on its MCP surface is worth a question before you connect it.
What each side charges
Three points on each published range: the cheapest plan, one in the middle, and the top of what the vendor publishes. Every plan on both sides is in the pricing section further down.
- FreeNot published
One account end to end, no card. Sign in with Google, Microsoft or a magic link
- Agency PlusNot published
Named on the homepage anchor and in the white-label FAQ answer; no rate or limits given
- EnterpriseNot published
Contact is a founder email rather than a sales form; no rate or limits given
- IT teams: up to 100,000 emails/mo$19/mo ($15/mo billed annually)
2 set-up domains (adding is unlimited), unlimited retention, every core feature
- IT teams: up to 1,000,000 emails/mo$99/mo ($79/mo billed annually)
Same product: 10 set-up domains, pick the tier that matches your sending
- Enterprise (more than 2.5M / month)Custom
Custom volume, retention, and terms
Dashboard access vs programmatic access
Authwright's 42-tool MCP surface, with no public REST or GraphQL API
Authwright advertises a Model Context Protocol server rather than a dashboard or a documented REST or GraphQL API. Its capabilities page lists 42 tools across email authentication, DNS, domain portfolios, SSL/TLS, bulk operations, and health diagnostics. That surface includes export_portfolio and a quarterly compliance audit export in CSV form. On its homepage, Authwright says an LLM can call email_auth_wizard to read the current state, diagnose gaps, write approved records, host MTA-STS, verify propagation, and ingest DMARC reports. The public pages cited do not advertise a REST or GraphQL reference (checked 2026-08-27). Source (2026-08-27) Source 2 (2026-08-27)
Authwright
A relevant product screenshot was not available in the reviewed evidence.
Palisade

- Documented REST or GraphQL API for domain data: REST API published
- MCP server for connecting AI assistants to domain data: MCP server published
- AI assistant can run an email-authentication workflow: Agent drafts fixes
Palisade publishes an MCP server at /mcp. Its agent investigates senders, drafts SPF and DKIM fixes, and proposes each policy step. A human approves before anything ships.
Reachable from your own AI tools
Palisade's MCP server exposes 42 tools over OAuth, so the assistant your team already uses can read domains, pull the exact records to publish and work the task queue. These are the clients the connection guide walks through.
- ChatGPT
- Claude
- Codex
- Cursor
- Windsurf
- Any MCP client
Still deciding between Authwright and Palisade? See what changes with Palisade.
15-day full-product trial. Nothing is charged until it ends.
The agent does the heavy lifting
Sources identified, SPF and DKIM fixes drafted, each policy step proposed. You approve; nothing ships on its own.
Connect your AI with MCP
42 tools over MCP, so your assistant reads your domains and works the queue.
Connect your DNS manager directly
Approved records go into your own zone at your own provider, across 64. No credentials reach us.
“We evaluated many DMARC providers before choosing Palisade. The quality of their product, the responsiveness and friendliness of their team and their rapid progress on their product roadmap made it a no-brainer for us to move forward.”
Authwright pricing explained (and how Palisade compares)
Authwright prices per agency rather than per seat, and names three tiers. It does not publish rates for any of them. On 20 August 2026 the /pricing URL returned 404 and the tier copy sat on a homepage anchor instead, so this table records the tier names and what the site says every tier includes:
What you'd actually pay
The same five buyer sizes on every comparison, so a shape carries from one page to the next.
1 domain, up to 1,000 emails a month
Free: 1 domain and 1 registrar; no email-volume limit is published
2 set-up domains, up to 100K emails a month
Pro: 5 domains and 1 registrar; no 2-domain tier or email-volume limit is published
10 set-up domains, up to 1M emails a month
Team: 25 domains and 5 registrars; no 10-domain tier or email-volume limit is published
20 set-up domains, up to 2.5M emails a month
Team: 25 domains and 5 registrars; no 20-domain tier or email-volume limit is published
Client domains under management, any volume
Agency: 100 domains, 15 registrars, and multi-tenant workspaces; no email-volume limit is published
Palisade’s figures are derived from its published tiers. Authwright figures read from their pricing page on 2026-08-28. Plans and prices may have changed since.
How Authwright prices
- Every tier is described as including MTA-STS hosting, SPF flattening, DMARC aggregate report ingestion and multi-registrar support, so the tiers appear to differ on scale rather than features.
- White-label is described as on the roadmap for Agency Plus and Enterprise, not shipped.
- The /pricing and /docs URLs both returned 404 on 20 August 2026. Footer links to About and Security resolve to anchors on those same 404 pages.
How Palisade prices
- Published rates for IT teams, metered on monthly email volume, with 2 to 20 set-up domains by tier and free unlimited domain adding.
- MSPs pay per client domain, with a rate that improves as the portfolio grows and a minimum of 5 client domains. Your own MSP domain is included as a free Not-For-Resale license.
- A 15-day full-product trial. Nothing is charged until the trial ends.
- API access and MCP access on every plan.
Authwright pricing read from their public pricing page on 2026-08-20.Plans and prices may have changed since.
Start a 15-day full-product trial of Palisade. Nothing is charged until it ends.
What each one covers, and where it stops
Published facts only, read from each vendor's own material. Neither column describes a hands-on trial, because we have not run one.
Authwright is an MCP-based domain-portfolio platform for agencies on its five supported registrars: GoDaddy, Namecheap, Cloudflare, Porkbun and Route 53. Its 42 published tools span email authentication, DNS, certificates, domain lifecycle, bulk operations and health checks, so it suits teams that want registrar work and email-authentication setup from one assistant session.
Email EasyPass is its email-authentication workflow. It reads a domain's state, diagnoses gaps, writes approved records at the registrar, hosts an MTA-STS policy, verifies propagation, then ingests and summarises DMARC reports. Authwright offers Free, Agency Plus and Enterprise per-agency tiers but does not publish rates or domain limits for any of them.
Palisade is built around an agent that does the DMARC work rather than reporting on it. It identifies every sending source, drafts the SPF and DKIM changes each one needs, and proposes the next policy step when the evidence supports it.
The agent investigates every sender, drafts every fix, and proposes each policy step, you approve before anything ships.
- Provides registrar record writes for approved DNS changes
- Includes DMARC aggregate report ingestion and SPF flattening on every tier
- Provides OAuth with PKCE and MCP access in its one-account free workspace
- Provides certificate lifecycle, domain portfolio, WHOIS privacy and DNSSEC tools
- The agent investigates senders and drafts the fix, so the work arrives prepared rather than as a list of findings
- Hosted SPF, DKIM and DMARC on redundant managed DNS, so an approved change can be carried out rather than handed off
- Portfolio workflow for MSPs, with ConnectWise, HaloPSA and Autotask integrations and a free NFR domain
- An MCP server and a REST API, so the same data and workflow are reachable from the AI tools a team already uses
- Does not advertise webhook endpoints
- Does not advertise native ConnectWise, HaloPSA or Autotask integrations
- Does not advertise a documented REST or GraphQL API
- Does not publish rates for any tier
- Every policy change waits for a human approval, by design: nothing ships on the agent's own authority
- MSP pricing is quoted per client domain rather than published as a rate card, with a minimum of 5 client domains
- Plans are sized by monthly email volume, so a low-domain, high-volume sender lands on a higher tier than domain count alone suggests
- Starts at
- Not published
- Free tier
- One account, no card
- Tiers
- Free, Agency Plus, Enterprise
- Domain limit
- Not published
- Included services
- MTA-STS, SPF, DMARC reports
- Starts at
- IT plans from $19/mo by email volume; 15-day trial
- Trial
- 15 days, full product
- MSP model
- Quoted per client domain, portfolio-based; minimum of 5 client domains
What Palisade customers say
5.0 out of 5 on G2Trusted by over 10,000 domains
“Palisade made it so easy for us to get our blue verified checkmark and achieve our BIMI compliance”
Sources and further reading
Source checks run through 2026-08-20; every entry keeps its individual check date.
- Authwright homepage: MCP access and Email EasyPass
Checked 2026-08-27
- Authwright capabilities: 42 tools, six categories, transport
Checked 2026-08-20
- Authwright security: credential boundary and access control
Checked 2026-08-20
- Authwright free domain check
Checked 2026-08-20
- Official MCP registry search for authwright (zero results)
Checked 2026-08-20
- Authwright capabilities: 42-tool MCP surface and portfolio export
Checked 2026-08-27
Palisade vs Authwright: FAQ
What is the main difference between Authwright and Palisade?
Who holds the keys to your DNS, and how long the job lasts. Authwright writes records by storing your registrar's API credentials in its workspace. Palisade writes records too, but you authorise the connection in your own DNS provider's window, so no credentials reach Palisade and the access is scoped and revocable. Past setup, Authwright ingests DMARC reports and summarises them; Palisade turns them into prioritised tickets with provider-specific fix instructions that a person approves.
Does Authwright have OAuth?
Yes. Its capabilities page documents the MCP transport as Streamable HTTP behind OAuth 2.1 with PKCE via Microsoft Entra ID, and separately its portal issues a workspace-scoped bridge token for editor clients like Claude Code and Cursor. Its security page is more cautious, describing workspace-scoped revocable MCP tokens as planned. All three statements were checked on 20 August 2026. The difference from Palisade is not the presence of OAuth on the assistant connection, it is that Authwright also needs your registrar API credentials underneath it.
Which registrars and DNS providers does each one support?
Authwright's adapters reach five registrars: GoDaddy, Namecheap, Cloudflare, Porkbun and Route 53, checked 20 August 2026. Palisade's automatic configuration reaches 64 DNS providers. Where a provider is not covered, Palisade returns the exact records for you to publish yourself, and hosted records are a second route that needs no write access at your provider at all.
What does Authwright do that Palisade does not?
Certificate lifecycle, domain purchasing and defensive registration, WHOIS privacy management, and DNSSEC auditing across a portfolio. Those account for most of its 42 tools and sit outside what Palisade does. If managing a registrar portfolio is the job, that is a real advantage, and the two overlap only on email authentication, so running both is workable.
Is Authwright in the official MCP registry?
No, checked on 20 August 2026: a registry search for authwright returns zero results. Palisade is listed and active as email.palisade/palisade. A registry listing is a distribution choice rather than a quality judgement, but it decides whether an assistant that discovers servers through the registry can find the server at all.
What does Authwright cost?
It does not publish rates. It names three tiers, Free, Agency Plus and Enterprise, and prices per agency rather than per seat, with every tier described as including MTA-STS hosting, SPF flattening and DMARC report ingestion. On 20 August 2026 the /pricing URL returned 404 and the tier copy sat on a homepage anchor. Palisade publishes its IT-team rates, and quotes MSP portfolios per client domain at a rate that improves as the portfolio grows, with a minimum of 5 client domains.
Can I try either one without paying?
Authwright's free workspace covers one account end to end with no card, and it runs an ungated domain audit at /check with no login or email gate. Palisade offers a 15-day full-product trial, and nothing is charged until the trial ends.
How do I switch from Authwright to Palisade?
Connect your DNS provider to Palisade by authorising it in the provider's own window, then run both in parallel: DMARC reporting supports multiple recipients, so both receive the same reports while you compare. When you are satisfied, repoint the MTA-STS policy host and the rua address, and revoke the registrar API credentials you gave Authwright.
Switching from Authwright takes three steps
- 1
Connect your DNS provider instead of handing over keys
Authorise Palisade in your own provider's window. Access is scoped to email-authentication records and revocable, and you can revoke the registrar API credentials you gave Authwright once the switch is done.
- 2
Run both platforms in parallel
DMARC reporting supports multiple recipients, so Palisade and Authwright receive the same reports during the overlap window. Nothing breaks while you compare.
- 3
Move hosted records on your schedule
Repoint the MTA-STS policy host and the rua address to Palisade's hosted infrastructure (redundant managed DNS), then retire the old setup when you are satisfied.
15-day full-product trial. Nothing is charged until it ends.
Competitor information on this page was last reviewed against public sources on 2026-08-20. Spotted something out of date? Tell us and we'll fix it.
Authwright

