Skip to Main Content
Authwright alternative

Authwright vs Palisade in 2026

Both platforms let an AI assistant do email authentication work. They differ on who holds the keys to your DNS, how many providers that reaches, and whether the job ends at setup or keeps running.

Our verdict: Pick Palisade if the DMARC work is the job and you would rather not hand a vendor your registrar keys. Pick Authwright if you manage a domain portfolio on one of its five supported registrars and want certificates, renewals and purchases in the same MCP session.

Samuel ChenardSamuel Chenard · CEO & Co-Founder, PalisadeSource checks through 2026-08-20

15-day full-product trial. Nothing is charged until it ends.

Authwright
Authwright's public domain-check page: a single domain field and Audit domain button, above a note that the free check probes 8 DKIM selectors while the MCP server's email_auth_wizard runs 20+ checks
Palisade
Palisade domains dashboard with email activity chart and DMARC compliance report
Authwright
AI assistant for email authentication
Palisade rubric score
76/100
Palisade rubric: tied rank #11 of 69 verified providers
Score calculation: 61 ÷ 80 × 100 = 76.25, rounded to 76/100
Palisade’s 8-dimension rubric
Starts at
Not published
Best fit
Agencies with portfolios on five supported registrars
In one line
Authwright suits teams managing a domain portfolio on its five supported registrars that want certificates, renewals and purchases in one MCP session.
Palisade
Agentic DMARC platform
Palisade rubric score
91/100
Palisade rubric: rank #1 of 69 verified providers
Score calculation: 73 ÷ 80 × 100 = 91.25, rounded to 91/100
Palisade’s 8-dimension rubric
Starts at
IT plans from $19/mo by email volume; 15-day trial
Best fit
MSPs and IT teams responsible for multiple domains
In one line
Palisade is agentic DMARC software for IT teams and MSPs. Find every sender, fix SPF and DKIM, and reach p=reject with human-approved changes.

Palisade's IT-team plans start at $19 a month, sized by email volume. Start with a 15-day full-product trial; nothing is charged until it ends.

The decision

Which one is right for you?

Pick Authwright if…
Pick Palisade if…

Best for Agencies with portfolios on five supported registrars

Best for MSPs and IT teams responsible for multiple domains

  • Your domains sit on GoDaddy, Namecheap, Cloudflare, Porkbun or Route 53, the five registrars its adapters reach.
  • You want one MCP session to also renew SSL certificates, buy defensive domains, and flip WHOIS privacy, which Palisade does not do.
  • Storing registrar API credentials at a vendor is a trade your security review accepts.
  • You want the DMARC work carried from report to verified fix, not a one-shot setup run.
  • You would rather authorise a scoped, revocable connection in your own DNS provider's window than store registrar API keys at a vendor.
  • Your domains are spread across providers: automatic configuration covers 64 of them.
  • You need DMARC aggregate reports turned into prioritised tickets with provider-specific fix instructions, plus webhooks and ongoing monitoring.
Starts at
Not published
Starts at
IT plans from $19/mo by email volume; 15-day trial

IT-team plans start at $19 a month, sized by email volume. Start with a 15-day full-product trial; nothing is charged until it ends.

Feature comparison

Where the day-to-day work actually differs

FeatureAuthwrightPalisade
DNS and credentials
Publishes approved records into your own DNS without holding your credentialsWhether approved DNS records can be published without storing registrar credentials.Authwright: registrar API key and secret stored in its workspace Source (2026-08-20)Stores registrar credentialsProvider-window authorization
Assistant can write the corrected records, not just recommend themWhether an assistant can publish corrected DNS records after approval.Both; Authwright writes at the registrar, Palisade through the connection you authoriseRegistrar record writesApproved zone writes
Automatic configuration across 64 DNS providersWhether automatic DNS configuration reaches providers across a domain portfolio.Authwright: five registrars (GoDaddy, Namecheap, Cloudflare, Porkbun, Route 53) Source (2026-08-20)Five registrar adaptersAutomatic provider configuration
Hosted records served on redundant managed DNS, so nothing is written at your registrar at allWhether email-authentication records can be hosted outside the registrar.Authwright hosts the MTA-STS policy file; other records are written into your zone Source (2026-08-20)MTA-STS policy onlyRedundant managed DNS
Ongoing operation
DMARC aggregate reports become prioritised tickets with provider-specific fix instructionsWhether DMARC reports become prioritised, provider-specific work items.Authwright ingests reports and summarises them for the assistant to read Source (2026-08-20)No prioritised ticketsProvider-specific work tickets
DMARC aggregate report ingestionWhether a product receives DMARC aggregate reports for review.Both; Authwright includes it on every tierIncluded on every tierAgent analyzes reports
SPF flattening kept under the 10-lookup limitWhether SPF lookup chains are kept within DNS lookup limits.Both; Authwright bundles it on every tier, and Palisade serves a hosted flattened include whose live lookup budget the assistant can read through get_spfIncluded on every tierOne-lookup hosted SPF
Webhook endpoints for your own systemsWhether a product can send event data to other systems through webhooks.Source (2026-08-20)Not advertisedWebhook endpoints
Native ConnectWise, HaloPSA and Autotask integrationsWhether a platform connects directly with the named PSA systems.Source (2026-08-20)Not advertisedNative PSA integrations
Connecting an assistant
Listed in the official MCP registryWhether a server can be discovered in the official MCP registry.Zero results for authwright on registry.modelcontextprotocol.io Source (2026-08-20)Not listedOfficial registry listing
OAuth sign-in to connect an assistantWhether an assistant connects through an OAuth sign-in flow.Both; Authwright documents OAuth 2.1 with PKCE via Microsoft Entra ID, plus a portal-issued bridge token for editor clients Source (2026-08-20) Source 2 (2026-08-20)OAuth with PKCEOAuth sign-in
MCP access included on the entry tierWhether MCP access is available on the lowest-priced tier.Both; Authwright's free workspace covers one account Source (2026-08-20)One-account free workspaceIncluded on every plan
Registrar portfolio work
SSL/TLS certificate lifecycle across a portfolioWhether SSL/TLS certificates can be managed across a domain portfolio.Authwright: 7 tools. Outside Palisade's scopeSeven certificate toolsOutside Palisade's scope
Domain purchasing, renewals and defensive registrationWhether a tool handles domain purchases, renewals, and defensive registrations.Authwright: 9 portfolio tools. Outside Palisade's scopeNine portfolio toolsOutside Palisade's scope
WHOIS privacy and DNSSEC auditing at portfolio scaleWhether a portfolio tool manages WHOIS privacy and audits DNSSEC.Outside Palisade's scopeSupportedOutside Palisade's scope
Commercial terms
Published rates you can read before contacting anyoneWhether a buyer can see prices before requesting a quote.Authwright names Free, Agency Plus and Enterprise without publishing numeric rates on its public homepage. Source (2026-08-20)Rates not publishedPublished IT pricing
AI and automation access
Documented REST or GraphQL API for domain dataWhether customers can build against a published REST or GraphQL reference instead of using only the product's MCP tools.Authwright does not advertise a documented REST or GraphQL API on its public homepage or capabilities page. It describes its published programmatic interface as a Model Context Protocol server (checked 2026-08-27). Source (2026-08-27) Source 2 (2026-08-27)No public API listedREST API published
MCP server for connecting AI assistants to domain dataWhether an AI assistant can reach the product's domain-management tools directly.Both; Authwright publishes a 42-tool Model Context Protocol server over streamable HTTP with OAuth 2.1 and PKCE, for use from MCP-compatible clients (checked 2026-08-27). Source (2026-08-27)MCP server publishedMCP server published
AI assistant can run an email-authentication workflowWhether the vendor advertises an AI-driven workflow for email-authentication work and states what it does.Both; Authwright advertises its email_auth_wizard MCP tool as an LLM-driven workflow that reads the current state, diagnoses gaps, writes approved records, hosts MTA-STS, verifies propagation, and ingests DMARC reports (checked 2026-08-27). Source (2026-08-27)LLM runs Email EasyPassAgent drafts fixes
Portfolio data export without opening a dashboardWhether domain-portfolio data can leave the product through a published programmatic interface.Authwright lists export_portfolio in its MCP tool surface and describes a quarterly compliance audit export as a CSV. It does not advertise webhooks on that capabilities page (checked 2026-08-27). Source (2026-08-27)MCP portfolio exportREST API published

Want to compare the workflow yourself? Start a 15-day full-product trial of Palisade.

The scorecard

Palisade 91 vs Authwright 76, and why

Both products are scored on the same eight dimensions the comparison hub uses, so the figures here are the figures there. Four are derived from vendor facts that each carry a source and a checked date. Four are editorial, marked as such below, and each states its reasoning and its source.

Each dimension is out of 10 and the total is the raw sum out of 80, rescaled to 100 — the raw figure is printed beside it so the conversion is checkable rather than a black box. Scored on what each vendor publishes, not on how the product feels in use. Editorial dimensions last reviewed 2026-09-02.

Authwright
76/100
61 of 80 raw
Palisade
91/100
73 of 80 raw
Dimension
MCP & API connectivityEditorial

How reachable the product is from your own software and AI tools. 10 = a documented API on every plan plus a published MCP server. 6 = an API, gated to a tier or to a sales conversation. 3 = no programmatic access advertised.

Authwright8/10

Authwright publishes a streamable HTTP MCP server with OAuth 2.1 and PKCE and includes MCP access on the Free plan; a separate public API reference is not published. Source (2026-08-29)

Palisade10/10

Palisade publishes a REST API and a remote MCP server on every plan, making the same domain data and remediation workflows available to connected software. Source (2026-08-30)

Analysis automationEditorial

How much of the report analysis is done for you. 10 = the platform turns raw report data into a prioritised, actionable queue on its own.

Authwright8/10

The published wizard reads the current authentication posture, diagnoses gaps, proposes and applies authorized record changes, and ingests aggregate reports for ongoing summaries. Source (2026-08-29)

Palisade9/10

Report data is analysed into a prioritised list of sender, SPF, DKIM and DMARC issues, so nobody reads raw XML. Source (2026-08-30)

Agentic softwareEditorial

How much of the work the vendor's own software does. 10 = it identifies the sending sources, drafts the SPF and DKIM fixes each one needs, and proposes the next policy step. 6 = it applies the records for you, but a person decides what to fix and when to advance. 3 = it reports, and every change is yours to make. A vendor whose team does the work rather than its software scores here on the software alone.

Authwright8/10

The vendor describes LLM-callable MCP workflows that compose diagnostics, DNS changeset previews, authorized writes, propagation checks, and portfolio-scale actions. Source (2026-08-29)

Palisade9/10

The agent investigates each sender, drafts the SPF and DKIM changes it needs, and proposes the next policy step; a human approves before deployment. Source (2026-08-30)

Pricing transparency

10 = full pricing published. 6 = some tiers published, rest quote-gated. 3 = quote only.

Authwright6/10

Free, Pro, Team, Agency, and Agency Plus prices are published; Enterprise is contact-sales. Source (2026-08-29)

Palisade10/10

Published: flat monthly plans by email volume from $19/mo Source (2026-08-30)

Hosted SPF/DKIM/DMARC records

10 = hosts the records for you. 6 = partial or add-on. 3 = you manage your own DNS.

Authwright6/10

Authwright publishes hosted MTA-STS policies and SPF flattening; its public material does not describe it hosting DMARC, DKIM, or BIMI records. Source (2026-08-29)

Palisade10/10

Yes: hosted DMARC, SPF, DKIM, BIMI & MTA-STS Source (2026-08-30)

Free access

10 = a genuine free plan. 6 = time-limited trial only. 3 = no free access.

Authwright10/10

The Free plan includes one domain, one registrar, public audits, MCP server access, and seven-day snapshots. Source (2026-08-29)

Palisade6/10

No free plan: a 15-day full-product trial; nothing is charged until the trial ends Source (2026-08-30)

MSP & multi-tenant

10 = a real MSP program with multi-tenant management. 6 = partial. 3 = none.

Authwright6/10

Agency and Agency Plus plans provide multi-tenant workspaces for domain portfolios; published partner-program terms are not listed. Source (2026-08-29)

Palisade10/10

Yes: MSP-first, multi-tenant with native PSA integrations Source (2026-08-30)

Path to enforcementEditorial

How much work it takes to get a domain from p=none to p=reject. 10 = the platform (or the vendor's team) gets you there without manual DNS edits.

Authwright9/10

Email EasyPass diagnoses email-authentication gaps, proposes the corrected records, writes them after authorization, and verifies propagation across supported registrars. Source (2026-08-29)

Palisade9/10

The DMARC Agent detects when a domain's authentication and alignment are ready for the next policy stage and proposes the move, but a human still approves and applies it, so it is not fully hands-off. Source (2026-08-30)

In depth

Where Palisade and Authwright actually differ

Each argument keeps the product screens, sourced comparison points, and supporting analysis together.

Credential storage vs provider authorization

Who holds the keys to your DNS

This is the real decision between the two, and it is worth getting past the marketing on both sides. Authwright writes DNS records for you, and the way it reaches your zone is by holding your registrar's API credentials. Its onboarding is explicit about it: step three asks you to paste a GoDaddy API key and secret, or a Cloudflare API token, into the portal. Its FAQ says those credentials are encrypted at rest in Azure Key Vault, scoped per domain where the registrar API supports it, and never logged, and it recommends creating a dedicated API user for Authwright on each registrar.Source 1, Source 2

Authwright

A relevant product screenshot was not available in the reviewed evidence.

Authwright, from its own site
  • Publishes approved records into your own DNS without holding your credentials: Stores registrar credentialsSource
  • Assistant can write the corrected records, not just recommend them: Registrar record writes
  • Automatic configuration across 64 DNS providers: Five registrar adaptersSource

Palisade

A relevant product screenshot was not available in the reviewed evidence.

Palisade product evidence
  • Publishes approved records into your own DNS without holding your credentials: Provider-window authorization
  • Assistant can write the corrected records, not just recommend them: Approved zone writes
  • Automatic configuration across 64 DNS providers: Automatic provider configuration

That is a reasonable design, handled with more care than most, and it still means a vendor holds keys that can act on your registrar account. A registrar API key is rarely scoped to email authentication alone; on several registrars the same credential can move nameservers, edit unrelated records, or touch billing.

Palisade reaches your DNS a different way. The provider is detected from the domain's live nameservers, and you authorise the connection in that provider's own window. No credentials are shared with Palisade, the access granted is scoped to email-authentication records, and you can revoke it from the provider whenever you want. Records you approve in Palisade are then written into your own zone through that connection. Palisade is not asking for a key it has to store, which is why there is no key to leak.

Five registrars vs broader reach

Five registrars against a wider catalogue

Custody and reach are the same decision seen twice. Because Authwright writes through registrar adapters it has built, it works where an adapter exists: GoDaddy, Namecheap, Cloudflare, Porkbun and Route 53. Its own FAQ says those five "map to the overwhelming majority of agency books" and invites you to email if yours is not covered. Palisade's automatic configuration reaches 64 DNS providers, because it connects through the provider's own authorisation rather than through a credential Palisade had to build a home for.Source 1, Source 2 +1 more

Authwright

A relevant product screenshot was not available in the reviewed evidence.

Authwright, from its own site
  • OAuth sign-in to connect an assistant: OAuth with PKCESource 1, Source 2
  • MCP access included on the entry tier: One-account free workspaceSource
  • Published rates you can read before contacting anyone: Rates not publishedSource

Palisade

A relevant product screenshot was not available in the reviewed evidence.

Palisade product evidence
  • OAuth sign-in to connect an assistant: OAuth sign-in
  • MCP access included on the entry tier: Included on every plan
  • Published rates you can read before contacting anyone: Published IT pricing

For a book of client domains, that gap decides how much of the book the tooling covers. Five adapters handle a portfolio consolidated at a big registrar. A mixed inheritance, which is what most agencies actually have, spreads past them.

Setup completion vs continuous operation

A setup run against an operating loop

Authwright's flagship is Email EasyPass, its email_auth_wizard tool. Its homepage sets out the sequence: read the current state, diagnose against the Gmail and Yahoo rules, write corrected records at the registrar, host the MTA-STS policy, wait for propagation, verify, then ingest DMARC reports on an ongoing basis and summarise them in plain language. The homepage transcript clocks the run at 47 seconds and moves a score from 32 to 94.Source

Authwright

A relevant product screenshot was not available in the reviewed evidence.

Authwright, from its own site
  • DMARC aggregate reports become prioritised tickets with provider-specific fix instructions: No prioritised ticketsSource
  • DMARC aggregate report ingestion: Included on every tier
  • SPF flattening kept under the 10-lookup limit: Included on every tier

Palisade

'Fix SPF for Microsoft Outlook' guided wizard on step 3 (Fix) with an Update SPF automatically button and manual-setup link — flat full-frame app capture
Palisade product evidence · Vendor source, checked 2026-07-17
  • DMARC aggregate reports become prioritised tickets with provider-specific fix instructions: Provider-specific work tickets
  • DMARC aggregate report ingestion: Agent analyzes reports
  • SPF flattening kept under the 10-lookup limit: One-lookup hosted SPF

Getting a domain to a good configuration quickly is genuinely useful, and that sequence does it. The part that decides whether a domain stays there is what happens over the following weeks, when a marketing team adds a sender nobody told you about, or an upstream provider changes its SPF include and the lookup count creeps back over ten.

Palisade is built around that second phase. Aggregate reports feed a work queue: the agent investigates each sending source, works out whether it is legitimate, drafts the fix, and files it as a prioritised ticket with instructions specific to the provider involved. Webhooks push those events into your own systems. The agent investigates every sender, drafts every fix, and proposes each policy step, and you approve before anything ships. The output is a task with an owner rather than a report to read.

Email focus vs portfolio breadth

Where Authwright is the better tool

Authwright is not really a DMARC product with extras. Of its 42 published tools, 8 are email authentication; the other 34 handle DNS records, domain portfolio lifecycle, SSL/TLS, bulk operations and health checks. Its registrar pages make the actual pitch plainly: renewals you keep forgetting, certificates expiring on inconvenient days, WHOIS privacy that flips off after a billing failure, defensive registrations that each cost a trip through a checkout flow.

Authwright

A relevant product screenshot was not available in the reviewed evidence.

Authwright, from its own site
  • SSL/TLS certificate lifecycle across a portfolio: Seven certificate tools
  • Domain purchasing, renewals and defensive registration: Nine portfolio tools
  • WHOIS privacy and DNSSEC auditing at portfolio scale: Supported

Palisade

A relevant product screenshot was not available in the reviewed evidence.

Palisade product evidence
  • SSL/TLS certificate lifecycle across a portfolio: Outside Palisade's scope
  • Domain purchasing, renewals and defensive registration: Outside Palisade's scope
  • WHOIS privacy and DNSSEC auditing at portfolio scale: Outside Palisade's scope

If that is the job in front of you, Authwright covers ground Palisade does not and is not trying to. Palisade does not renew certificates, buy domains, manage WHOIS privacy, or audit DNSSEC. An agency whose real problem is a sprawling registrar portfolio should weigh that breadth seriously, and can run both: the two overlap only on the email-authentication tools.

Two smaller things worth knowing before you commit. Authwright is not listed in the official MCP registry, checked on 20 August 2026, so an assistant that discovers servers through the registry will not find it. And its /docs and /pricing URLs both returned 404 that day, which for a product sold on its MCP surface is worth a question before you connect it.

What each side charges

Three points on each published range: the cheapest plan, one in the middle, and the top of what the vendor publishes. Every plan on both sides is in the pricing section further down.

Authwright
  • Free
    Not published

    One account end to end, no card. Sign in with Google, Microsoft or a magic link

  • Agency Plus
    Not published

    Named on the homepage anchor and in the white-label FAQ answer; no rate or limits given

  • Enterprise
    Not published

    Contact is a founder email rather than a sales form; no rate or limits given

Palisade
  • IT teams: up to 100,000 emails/mo
    $19/mo ($15/mo billed annually)

    2 set-up domains (adding is unlimited), unlimited retention, every core feature

  • IT teams: up to 1,000,000 emails/mo
    $99/mo ($79/mo billed annually)

    Same product: 10 set-up domains, pick the tier that matches your sending

  • Enterprise (more than 2.5M / month)
    Custom

    Custom volume, retention, and terms

Dashboard access vs programmatic access

Authwright's 42-tool MCP surface, with no public REST or GraphQL API

Authwright advertises a Model Context Protocol server rather than a dashboard or a documented REST or GraphQL API. Its capabilities page lists 42 tools across email authentication, DNS, domain portfolios, SSL/TLS, bulk operations, and health diagnostics. That surface includes export_portfolio and a quarterly compliance audit export in CSV form. On its homepage, Authwright says an LLM can call email_auth_wizard to read the current state, diagnose gaps, write approved records, host MTA-STS, verify propagation, and ingest DMARC reports. The public pages cited do not advertise a REST or GraphQL reference (checked 2026-08-27). Source (2026-08-27) Source 2 (2026-08-27)

Authwright

A relevant product screenshot was not available in the reviewed evidence.

Authwright, from its own site
  • Documented REST or GraphQL API for domain data: No public API listedSource 1, Source 2
  • MCP server for connecting AI assistants to domain data: MCP server publishedSource
  • AI assistant can run an email-authentication workflow: LLM runs Email EasyPassSource

Palisade

Palisade Create Support Request form with subject, description, optional domain reference, file attachments, and link attachment fields
Palisade product evidence · Vendor source, checked 2026-08-31
  • Documented REST or GraphQL API for domain data: REST API published
  • MCP server for connecting AI assistants to domain data: MCP server published
  • AI assistant can run an email-authentication workflow: Agent drafts fixes

Palisade publishes an MCP server at /mcp. Its agent investigates senders, drafts SPF and DKIM fixes, and proposes each policy step. A human approves before anything ships.

Reachable from your own AI tools

Palisade's MCP server exposes 42 tools over OAuth, so the assistant your team already uses can read domains, pull the exact records to publish and work the task queue. These are the clients the connection guide walks through.

Palisade

Still deciding between Authwright and Palisade? See what changes with Palisade.

15-day full-product trial. Nothing is charged until it ends.

The agent does the heavy lifting

Sources identified, SPF and DKIM fixes drafted, each policy step proposed. You approve; nothing ships on its own.

Connect your AI with MCP

  • ChatGPT
  • Claude
  • Codex
  • Cursor
  • Windsurf

42 tools over MCP, so your assistant reads your domains and works the queue.

Connect your DNS manager directly

  • GoDaddy
  • Cloudflare
  • Namecheap
  • Amazon Route 53

Approved records go into your own zone at your own provider, across 64. No credentials reach us.

“We evaluated many DMARC providers before choosing Palisade. The quality of their product, the responsiveness and friendliness of their team and their rapid progress on their product roadmap made it a no-brainer for us to move forward.”
Read the case study
Pricing

Authwright pricing explained (and how Palisade compares)

Authwright prices per agency rather than per seat, and names three tiers. It does not publish rates for any of them. On 20 August 2026 the /pricing URL returned 404 and the tier copy sat on a homepage anchor instead, so this table records the tier names and what the site says every tier includes:

What you'd actually pay

The same five buyer sizes on every comparison, so a shape carries from one page to the next.

Buyer size
Small

1 domain, up to 1,000 emails a month

Authwright
$0/mo

Free: 1 domain and 1 registrar; no email-volume limit is published

Palisade
$19/mo ($15/mo annual), entry tier covers up to 100K emails
Medium

2 set-up domains, up to 100K emails a month

Authwright
$29/mo

Pro: 5 domains and 1 registrar; no 2-domain tier or email-volume limit is published

Palisade
$19/mo ($15/mo annual)
Large

10 set-up domains, up to 1M emails a month

Authwright
$99/mo

Team: 25 domains and 5 registrars; no 10-domain tier or email-volume limit is published

Palisade
$99/mo ($79/mo annual)
Enterprise

20 set-up domains, up to 2.5M emails a month

Authwright
$99/mo

Team: 25 domains and 5 registrars; no 20-domain tier or email-volume limit is published

Palisade
$249/mo ($199/mo annual)
MSP

Client domains under management, any volume

Authwright
$299/mo

Agency: 100 domains, 15 registrars, and multi-tenant workspaces; no email-volume limit is published

Palisade
Quoted per client domain; minimum of 5 client domains; no email metering

Palisade’s figures are derived from its published tiers. Authwright figures read from their pricing page on 2026-08-28. Plans and prices may have changed since.

How Authwright prices

  • Every tier is described as including MTA-STS hosting, SPF flattening, DMARC aggregate report ingestion and multi-registrar support, so the tiers appear to differ on scale rather than features.
  • White-label is described as on the roadmap for Agency Plus and Enterprise, not shipped.
  • The /pricing and /docs URLs both returned 404 on 20 August 2026. Footer links to About and Security resolve to anchors on those same 404 pages.

How Palisade prices

  • Published rates for IT teams, metered on monthly email volume, with 2 to 20 set-up domains by tier and free unlimited domain adding.
  • MSPs pay per client domain, with a rate that improves as the portfolio grows and a minimum of 5 client domains. Your own MSP domain is included as a free Not-For-Resale license.
  • A 15-day full-product trial. Nothing is charged until the trial ends.
  • API access and MCP access on every plan.

Authwright pricing read from their public pricing page on 2026-08-20.Plans and prices may have changed since.

Start a 15-day full-product trial of Palisade. Nothing is charged until it ends.

Standing

What each one covers, and where it stops

Published facts only, read from each vendor's own material. Neither column describes a hands-on trial, because we have not run one.

Authwright · Overview

Authwright is an MCP-based domain-portfolio platform for agencies on its five supported registrars: GoDaddy, Namecheap, Cloudflare, Porkbun and Route 53. Its 42 published tools span email authentication, DNS, certificates, domain lifecycle, bulk operations and health checks, so it suits teams that want registrar work and email-authentication setup from one assistant session.

Email EasyPass is its email-authentication workflow. It reads a domain's state, diagnoses gaps, writes approved records at the registrar, hosts an MTA-STS policy, verifies propagation, then ingests and summarises DMARC reports. Authwright offers Free, Agency Plus and Enterprise per-agency tiers but does not publish rates or domain limits for any of them.

Palisade · Overview

Palisade is built around an agent that does the DMARC work rather than reporting on it. It identifies every sending source, drafts the SPF and DKIM changes each one needs, and proposes the next policy step when the evidence supports it.

The agent investigates every sender, drafts every fix, and proposes each policy step, you approve before anything ships.

Authwright · What it covers
  • Provides registrar record writes for approved DNS changes
  • Includes DMARC aggregate report ingestion and SPF flattening on every tier
  • Provides OAuth with PKCE and MCP access in its one-account free workspace
  • Provides certificate lifecycle, domain portfolio, WHOIS privacy and DNSSEC tools
Palisade · What it covers
  • The agent investigates senders and drafts the fix, so the work arrives prepared rather than as a list of findings
  • Hosted SPF, DKIM and DMARC on redundant managed DNS, so an approved change can be carried out rather than handed off
  • Portfolio workflow for MSPs, with ConnectWise, HaloPSA and Autotask integrations and a free NFR domain
  • An MCP server and a REST API, so the same data and workflow are reachable from the AI tools a team already uses
Authwright · Where it stops
  • Does not advertise webhook endpoints
  • Does not advertise native ConnectWise, HaloPSA or Autotask integrations
  • Does not advertise a documented REST or GraphQL API
  • Does not publish rates for any tier
Palisade · Where it stops
  • Every policy change waits for a human approval, by design: nothing ships on the agent's own authority
  • MSP pricing is quoted per client domain rather than published as a rate card, with a minimum of 5 client domains
  • Plans are sized by monthly email volume, so a low-domain, high-volume sender lands on a higher tier than domain count alone suggests
Authwright · At a glance
Starts at
Not published
Free tier
One account, no card
Tiers
Free, Agency Plus, Enterprise
Domain limit
Not published
Included services
MTA-STS, SPF, DMARC reports
Palisade · At a glance
Starts at
IT plans from $19/mo by email volume; 15-day trial
Trial
15 days, full product
MSP model
Quoted per client domain, portfolio-based; minimum of 5 client domains

What Palisade customers say

Read customer stories

5.0 out of 5 on G2Trusted by over 10,000 domains

Pick a customer

“Palisade made it so easy for us to get our blue verified checkmark and achieve our BIMI compliance”

Max LeRoy

Max LeRoy

VP Product, Politico

Read case study
Evidence

Sources and further reading

Source checks run through 2026-08-20; every entry keeps its individual check date.

Questions

Palisade vs Authwright: FAQ

What is the main difference between Authwright and Palisade?

Who holds the keys to your DNS, and how long the job lasts. Authwright writes records by storing your registrar's API credentials in its workspace. Palisade writes records too, but you authorise the connection in your own DNS provider's window, so no credentials reach Palisade and the access is scoped and revocable. Past setup, Authwright ingests DMARC reports and summarises them; Palisade turns them into prioritised tickets with provider-specific fix instructions that a person approves.

Does Authwright have OAuth?

Yes. Its capabilities page documents the MCP transport as Streamable HTTP behind OAuth 2.1 with PKCE via Microsoft Entra ID, and separately its portal issues a workspace-scoped bridge token for editor clients like Claude Code and Cursor. Its security page is more cautious, describing workspace-scoped revocable MCP tokens as planned. All three statements were checked on 20 August 2026. The difference from Palisade is not the presence of OAuth on the assistant connection, it is that Authwright also needs your registrar API credentials underneath it.

Which registrars and DNS providers does each one support?

Authwright's adapters reach five registrars: GoDaddy, Namecheap, Cloudflare, Porkbun and Route 53, checked 20 August 2026. Palisade's automatic configuration reaches 64 DNS providers. Where a provider is not covered, Palisade returns the exact records for you to publish yourself, and hosted records are a second route that needs no write access at your provider at all.

What does Authwright do that Palisade does not?

Certificate lifecycle, domain purchasing and defensive registration, WHOIS privacy management, and DNSSEC auditing across a portfolio. Those account for most of its 42 tools and sit outside what Palisade does. If managing a registrar portfolio is the job, that is a real advantage, and the two overlap only on email authentication, so running both is workable.

Is Authwright in the official MCP registry?

No, checked on 20 August 2026: a registry search for authwright returns zero results. Palisade is listed and active as email.palisade/palisade. A registry listing is a distribution choice rather than a quality judgement, but it decides whether an assistant that discovers servers through the registry can find the server at all.

What does Authwright cost?

It does not publish rates. It names three tiers, Free, Agency Plus and Enterprise, and prices per agency rather than per seat, with every tier described as including MTA-STS hosting, SPF flattening and DMARC report ingestion. On 20 August 2026 the /pricing URL returned 404 and the tier copy sat on a homepage anchor. Palisade publishes its IT-team rates, and quotes MSP portfolios per client domain at a rate that improves as the portfolio grows, with a minimum of 5 client domains.

Can I try either one without paying?

Authwright's free workspace covers one account end to end with no card, and it runs an ungated domain audit at /check with no login or email gate. Palisade offers a 15-day full-product trial, and nothing is charged until the trial ends.

How do I switch from Authwright to Palisade?

Connect your DNS provider to Palisade by authorising it in the provider's own window, then run both in parallel: DMARC reporting supports multiple recipients, so both receive the same reports while you compare. When you are satisfied, repoint the MTA-STS policy host and the rua address, and revoke the registrar API credentials you gave Authwright.

Switching from Authwright takes three steps

  1. 1

    Connect your DNS provider instead of handing over keys

    Authorise Palisade in your own provider's window. Access is scoped to email-authentication records and revocable, and you can revoke the registrar API credentials you gave Authwright once the switch is done.

  2. 2

    Run both platforms in parallel

    DMARC reporting supports multiple recipients, so Palisade and Authwright receive the same reports during the overlap window. Nothing breaks while you compare.

  3. 3

    Move hosted records on your schedule

    Repoint the MTA-STS policy host and the rua address to Palisade's hosted infrastructure (redundant managed DNS), then retire the old setup when you are satisfied.

Our onboarding team handles the technical transition with you.

15-day full-product trial. Nothing is charged until it ends.

Competitor information on this page was last reviewed against public sources on 2026-08-20. Spotted something out of date? Tell us and we'll fix it.