Authwright alternative

Authwright vs Palisade in 2026

Both platforms let an AI assistant do email authentication work. They differ on who holds the keys to your DNS, how many providers that reaches, and whether the job ends at setup or keeps running.

Our verdict: Pick Palisade if the DMARC work is the job and you would rather not hand a vendor your registrar keys. Pick Authwright if you manage a domain portfolio on one of its five supported registrars and want certificates, renewals and purchases in the same MCP session.

Samuel ChenardSamuel Chenard · CEO & Co-Founder, PalisadeCompetitor info reviewed 2026-08-20

1 domain free up to 1,000 emails/month

Authwright
Authwright's public domain-check page: a single domain field and Audit domain button, above a note that the free check probes 8 DKIM selectors while the MCP server's email_auth_wizard runs 20+ checks
Palisade
Palisade domains dashboard with email activity chart and DMARC compliance report

Trusted by leading brands worldwide

Partner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner LogoPartner Logo
Feature comparison

Palisade vs Authwright at a glance

FeatureAuthwrightPalisade
DNS and credentials
Publishes approved records into your own DNS without holding your credentialsAuthwright: registrar API key and secret stored in its workspace Source (2026-08-20)
Assistant can write the corrected records, not just recommend themBoth; Authwright writes at the registrar, Palisade through the connection you authorise
Automatic configuration across 64 DNS providersAuthwright: five registrars (GoDaddy, Namecheap, Cloudflare, Porkbun, Route 53) Source (2026-08-20)
Hosted records served on redundant managed DNS, so nothing is written at your registrar at allAuthwright hosts the MTA-STS policy file; other records are written into your zone Source (2026-08-20)
Ongoing operation
DMARC aggregate reports become prioritised tickets with provider-specific fix instructionsAuthwright ingests reports and summarises them for the assistant to read Source (2026-08-20)
DMARC aggregate report ingestionBoth; Authwright includes it on every tier
Webhook endpoints for your own systemsSource (2026-08-20)
Native ConnectWise, HaloPSA and Autotask integrationsSource (2026-08-20)
Connecting an assistant
Listed in the official MCP registryZero results for authwright on registry.modelcontextprotocol.io Source (2026-08-20)
OAuth sign-in to connect an assistantBoth; Authwright documents OAuth 2.1 with PKCE via Microsoft Entra ID, plus a portal-issued bridge token for editor clients Source (2026-08-20) Source 2 (2026-08-20)
MCP access included on the free planBoth; Authwright's free workspace covers one account Source (2026-08-20)
Registrar portfolio work
SSL/TLS certificate lifecycle across a portfolioAuthwright: 7 tools. Outside Palisade's scope
Domain purchasing, renewals and defensive registrationAuthwright: 9 portfolio tools. Outside Palisade's scope
WHOIS privacy and DNSSEC auditing at portfolio scaleOutside Palisade's scope
Commercial terms
Published rates you can read before contacting anyoneAuthwright names Free, Agency Plus and Enterprise without rates; /pricing 404s Source (2026-08-20)

Who holds the keys to your DNS

This is the real decision between the two, and it is worth getting past the marketing on both sides. Authwright writes DNS records for you, and the way it reaches your zone is by holding your registrar's API credentials. Its onboarding is explicit about it: step three asks you to paste a GoDaddy API key and secret, or a Cloudflare API token, into the portal. Its FAQ says those credentials are encrypted at rest in Azure Key Vault, scoped per domain where the registrar API supports it, and never logged, and it recommends creating a dedicated API user for Authwright on each registrar.

That is a reasonable design, handled with more care than most, and it still means a vendor holds keys that can act on your registrar account. A registrar API key is rarely scoped to email authentication alone; on several registrars the same credential can move nameservers, edit unrelated records, or touch billing.

Palisade reaches your DNS a different way. The provider is detected from the domain's live nameservers, and you authorise the connection in that provider's own window. No credentials are shared with Palisade, the access granted is scoped to email-authentication records, and you can revoke it from the provider whenever you want. Records you approve in Palisade are then written into your own zone through that connection. Palisade is not asking for a key it has to store, which is why there is no key to leak.

Five registrars against a wider catalogue

Custody and reach are the same decision seen twice. Because Authwright writes through registrar adapters it has built, it works where an adapter exists: GoDaddy, Namecheap, Cloudflare, Porkbun and Route 53. Its own FAQ says those five "map to the overwhelming majority of agency books" and invites you to email if yours is not covered. Palisade's automatic configuration reaches 64 DNS providers, because it connects through the provider's own authorisation rather than through a credential Palisade had to build a home for.

For a book of client domains, that gap decides how much of the book the tooling covers. Five adapters handle a portfolio consolidated at a big registrar. A mixed inheritance, which is what most agencies actually have, spreads past them.

A setup run against an operating loop

Authwright's flagship is Email EasyPass, its email_auth_wizard tool. Its homepage sets out the sequence: read the current state, diagnose against the Gmail and Yahoo rules, write corrected records at the registrar, host the MTA-STS policy, wait for propagation, verify, then ingest DMARC reports on an ongoing basis and summarise them in plain language. The homepage transcript clocks the run at 47 seconds and moves a score from 32 to 94.

Getting a domain to a good configuration quickly is genuinely useful, and that sequence does it. The part that decides whether a domain stays there is what happens over the following weeks, when a marketing team adds a sender nobody told you about, or an upstream provider changes its SPF include and the lookup count creeps back over ten.

Palisade is built around that second phase. Aggregate reports feed a work queue: the agent investigates each sending source, works out whether it is legitimate, drafts the fix, and files it as a prioritised ticket with instructions specific to the provider involved. Webhooks push those events into your own systems. The agent investigates every sender, drafts every fix, and proposes each policy step, and you approve before anything ships. The output is a task with an owner rather than a report to read.

Where Authwright is the better tool

Authwright is not really a DMARC product with extras. Of its 42 published tools, 8 are email authentication; the other 34 handle DNS records, domain portfolio lifecycle, SSL/TLS, bulk operations and health checks. Its registrar pages make the actual pitch plainly: renewals you keep forgetting, certificates expiring on inconvenient days, WHOIS privacy that flips off after a billing failure, defensive registrations that each cost a trip through a checkout flow.

If that is the job in front of you, Authwright covers ground Palisade does not and is not trying to. Palisade does not renew certificates, buy domains, manage WHOIS privacy, or audit DNSSEC. An agency whose real problem is a sprawling registrar portfolio should weigh that breadth seriously, and can run both: the two overlap only on the email-authentication tools.

Two smaller things worth knowing before you commit. Authwright is not listed in the official MCP registry, checked on 20 August 2026, so an assistant that discovers servers through the registry will not find it. And its /docs and /pricing URLs both returned 404 that day, which for a product sold on its MCP surface is worth a question before you connect it.

Pricing

Authwright pricing explained (and how Palisade compares)

Authwright prices per agency rather than per seat, and names three tiers. It does not publish rates for any of them. On 20 August 2026 the /pricing URL returned 404 and the tier copy sat on a homepage anchor instead, so this table records the tier names and what the site says every tier includes:

Authwright planPublished priceWhat you get
FreeNot publishedOne account end to end, no card. Sign in with Google, Microsoft or a magic link
Agency PlusNot publishedNamed on the homepage anchor and in the white-label FAQ answer; no rate or limits given
EnterpriseNot publishedContact is a founder email rather than a sales form; no rate or limits given
  • Every tier is described as including MTA-STS hosting, SPF flattening, DMARC aggregate report ingestion and multi-registrar support, so the tiers appear to differ on scale rather than features.
  • White-label is described as on the roadmap for Agency Plus and Enterprise, not shipped.
  • The /pricing and /docs URLs both returned 404 on 20 August 2026. Footer links to About and Security resolve to anchors on those same 404 pages.

Authwright pricing read from their public pricing page on 2026-08-20. Plans and prices may have changed since.

How Palisade prices instead

  • Published rates for IT teams, metered on one thing: monthly email volume, with every organization domain included.
  • MSPs pay per client domain, with a rate that improves as the portfolio grows. Your own MSP domain is included as a free Not-For-Resale license.
  • A Free plan for one domain and up to 1,000 emails a month, and a 15-day full-product trial. No credit card at signup, at domain add, or to start the trial.
  • API access and MCP access on every plan, including Free.
Palisade planPublished priceWhat you get
Free$01 domain, your own, capped at 1,000 emails/mo
IT teams: up to 100,000 emails/mo$19/mo ($15/mo billed annually)All your organization's domains, unlimited retention, every core feature
IT teams: up to 250,000 emails/mo$29/mo ($23/mo billed annually)Same product: pick the tier that matches your sending
IT teams: up to 500,000 emails/mo$59/mo ($47/mo billed annually)Same product: pick the tier that matches your sending
IT teams: up to 1,000,000 emails/mo$99/mo ($79/mo billed annually)Same product: pick the tier that matches your sending
MSPQuoted per client domain: portfolio-basedNo client email metering, free NFR domain, 15-day trial, multi-tenant + PSA integrations
Enterprise (1M+ emails/mo)CustomCustom volume, retention, and terms

1 domain free up to 1,000 emails/month

The decision

Which one is right for you?

Pick Authwright if…

  • Your domains sit on GoDaddy, Namecheap, Cloudflare, Porkbun or Route 53, the five registrars its adapters reach.
  • You want one MCP session to also renew SSL certificates, buy defensive domains, and flip WHOIS privacy, which Palisade does not do.
  • Storing registrar API credentials at a vendor is a trade your security review accepts.

Pick Palisade if…

  • You want the DMARC work carried from report to verified fix, not a one-shot setup run.
  • You would rather authorise a scoped, revocable connection in your own DNS provider's window than store registrar API keys at a vendor.
  • Your domains are spread across providers: automatic configuration covers 64 of them.
  • You need DMARC aggregate reports turned into prioritised tickets with provider-specific fix instructions, plus webhooks and ongoing monitoring.

1 domain free up to 1,000 emails/month

Migration

Switching from Authwright takes three steps

1

Connect your DNS provider instead of handing over keys

Authorise Palisade in your own provider's window. Access is scoped to email-authentication records and revocable, and you can revoke the registrar API credentials you gave Authwright once the switch is done.

2

Run both platforms in parallel

DMARC reporting supports multiple recipients, so Palisade and Authwright receive the same reports during the overlap window. Nothing breaks while you compare.

3

Move hosted records on your schedule

Repoint the MTA-STS policy host and the rua address to Palisade's hosted infrastructure (redundant managed DNS), then retire the old setup when you are satisfied.

1 domain free up to 1,000 emails/month

Our onboarding team handles the technical transition with you.

Customers

MSPs that made the switch

Palisade made it so easy for us to get our blue verified checkmark and achieve our BIMI compliance

Max LeRoy

Max LeRoy

VP Product, Politico

MSP Corp

Palisade allowed our team to deploy DMARC on our domains in minutes instead of hours and making sure our clients are compliant with cutting edge security recommendations from Microsoft.

Alvin Kalli

Alvin Kalli

CSIO, MSP Corp

gaiia

We increased our meetings booked by 21% and slept better at night knowing our emails are now secured

Marc-André Campagna

Marc-André Campagna

CEO, gaiia

Read case study
MSP Corp

We absolutely love it. We are actively selling it and growing the usage.

Ravi Ramharak

Ravi Ramharak

Co-Founder, MSP Corp

gaiia

All our emails started magically reaching the inbox in less than a week

Marc-André Campagna

Marc-André Campagna

CEO, gaiia

Elli Complice TI

Since we started using Palisade, managing email authentication at scale has been clearer and more proactive. It lets us go further, with better visibility and greater efficiency.

Alexandre Tremblay

Alexandre Tremblay

CTO, Elli Complice TI

Palisade streamlined all of our DMARC operations. It was so complicated at first, it was taking so much time. It allowed us to get everything done faster and have a complete overview of our operations, at such an affordable cost. We're saving so much time. It's a great improvement for our operations.

James Morin

IT Maestro, SecurITShell

dupe.com

Their responsive support, agent task lists, white-label reporting, and centralized dashboard make managing our customer domains, effortless.

Bobby Ghoshal

Bobby Ghoshal

CEO, dupe.com

We moved all our clients from EasyDMARC, which gave us so much more clarity about what to do with the remediation option from the agent.

Jodie Kretzer

Jodie Kretzer

VP of Service Management, Invision Technologies

dupe.com

Using Palisade made it easy to ramp up our email marketing channel from 0 to 100 in no time

Bobby Ghoshal

Bobby Ghoshal

CEO, dupe.com

I've migrated all my clients from PowerDMARC. The agent was so powerful it allowed us to do the work in a fraction of the time.

Marc-Olivier Hardy

Marc-Olivier Hardy

VP & CTO, CDT Connexion

Read our reviews on G2 →

Evidence

Sources and further reading

Primary product and pricing pages reviewed on 2026-08-20.

Questions

Palisade vs Authwright: FAQ

See the difference on your own domains

1 domain free up to 1,000 emails/month

Competitor information on this page was last reviewed against public sources on 2026-08-20. Spotted something out of date? Tell us and we'll fix it.