The DMARC management platform that does the work
Palisade is a DMARC management platform whose Agent investigates every sender, drafts every fix, and proposes each policy step. You approve the work, then publish through hosted DNS or 64 connected providers, with unlimited report history on paid plans. Free keeps 14 days.
1 domain free up to 1,000 emails/month
AI DMARC Agent
Reads your reports, drafts every fix, and carries domains to enforcement
See how it worksEmail Deliverability Platform
See which sender is failing before campaigns land in spam
See how it worksSmart DNS Deployment
Publish approved SPF, DKIM and DMARC records straight into your own DNS, across 64 providers
See how it worksBIMI & VMC
Hosted BIMI record and the DMARC enforcement it needs. The VMC comes from Signet
See how it worksEvery Palisade platform capability, in detail
The table separates what Palisade monitors, which remediation tickets the Agent opens, what it drafts, what your team approves, and where each capability lives. Every item below is available today.
- platform capabilities
- 95
- report retention on paid plans
- Unlimited
- connected DNS providers
- 64
- MCP tools for AI clients
- 30
| Capability | What it does | Part of |
|---|---|---|
| Monitoring and sender intelligenceTurn raw DMARC data into a current view of senders, authentication, volume, risk, and change over time. | ||
| DMARC aggregate report collection | Collect RUA reports automatically so your team does not have to retrieve or decode XML files. | Core platform |
| Unlimited DMARC report retention on paid plans | Keep the complete DMARC history with no expiry on paid plans; Free keeps 14 days of report history. | Deliverability |
| Sender discovery | Identify the ESPs, CRMs, helpdesks, billing systems, and other services sending as each domain. | Deliverability |
| Sender review states | Triage discovered senders as pending, confirmed, or discarded so the legitimate inventory stays clear. | DMARC Agent |
| SPF result analysis | See SPF pass, failure, and alignment status for each sending source instead of one domain-wide result. | Deliverability |
| DKIM result analysis | See which senders sign correctly, which selectors fail, and whether the signing domain aligns. | Deliverability |
| DMARC compliance and alignment | Track whether mail passes DMARC through aligned SPF or DKIM and where legitimate paths still break. | Deliverability |
| Email activity trends | Chart compliant, failed, unknown, and forwarded volume per domain and watch the mix change over time. | Deliverability |
| Unknown and forwarded traffic classification | Separate unrecognized sources and forwarded mail from known senders so expected forwarding does not look like an attack. | Deliverability |
| Placement view by provider | Review mailbox-provider placement alongside the real sender and authentication data that explains a change. | Deliverability |
| Domain security score | Summarize each domain's posture in one score and use the attached issues to see what will improve it. | Core platform |
| DNS posture and record history | Review DMARC, SPF, DKIM, MX, BIMI, MTA-STS, and nameserver state with periodic snapshots and diffs. | Core platform |
| AI agent, remediation, and enforcementMove from a finding to a reviewed fix and a safer DMARC policy without turning reports into manual project work. | ||
| Agent-generated work queue | Turn sender, SPF, DKIM, DNS, and policy findings into concrete tickets rather than dashboard warnings. | DMARC Agent |
| Severity and score impact | Give every ticket a severity and expected score improvement so the highest-value work rises first. | DMARC Agent |
| Evidence attached to every issue | Show the affected sender, authentication result, record state, and reason for the recommendation in one place. | DMARC Agent |
| Sender authorization tickets | Open a review whenever a new sending source appears, then let your team confirm it as legitimate or discard it before changing authentication. | DMARC Agent |
| Sender-specific SPF remediation | Diagnose how a failing sender authenticates and draft the appropriate SPF path for direct records, subdomains, static IPs, or provider includes. | DMARC Agent |
| Sender-specific DKIM remediation | Turn a sender's missing, failing, or misaligned DKIM signature into a ticket with setup guidance for that sending platform. | DMARC Agent |
| Provider-specific fix instructions | Attach step-by-step instructions matched to the identified email platform when Palisade has a provider-specific remediation path. | DMARC Agent |
| Official documentation interpretation | Read the sending provider's official documentation, extract the relevant SPF or DKIM setup path, cross-check each step against the source, and publish only human-reviewed guidance. | DMARC Agent |
| SPF lookup-limit remediation | Detect SPF records that exceed the 10-lookup limit and open a focused ticket to reduce lookups without removing legitimate senders. | DMARC Agent |
| SPF record cleanup tickets | Identify broken includes and unsafe or missing all-mechanisms, then show the SPF change needed to clean them up. | DMARC Agent |
| DNS conflict remediation | Explain conflicting TXT and CNAME records, identify the value that is live, and draft the specific cleanup needed at that hostname. | DMARC Agent |
| Record setup and repair tickets | Open guided work for missing or drifted DMARC records, missing SPF or MX records, low TTLs, and other email-DNS issues. | DMARC Agent |
| DMARC policy-readiness guidance | Identify when legitimate senders are aligned and a domain is ready for the next enforcement step. | DMARC Agent |
| Staged enforcement | Progress from p=none to p=quarantine and p=reject in reviewed steps after legitimate mail is ready. | DMARC Agent |
| Granular policy controls | Review percentage rollout, subdomain policy, and SPF or DKIM alignment modes before changing enforcement. | DMARC Agent |
| Exact change previews | Compare the current and proposed DNS or policy values side by side before approving a change. | DMARC Agent |
| Human approval gate | Keep every DNS and policy decision under human control. Nothing ships simply because the Agent proposed it. | Core platform |
| Pending-verification state | Move a ticket into pending verification after a change while Palisade monitors the result, then complete it when resolved or reopen it when the issue remains. | DMARC Agent |
| Unresolved-issue resurfacing | Reopen work when monitoring still finds the underlying problem, so closing a ticket cannot hide an SPF, DKIM, or DNS issue that remains live. | DMARC Agent |
| Snooze and dismiss controls | Snooze work that needs more time or dismiss a non-applicable finding, with separate controls for ignoring SPF or DKIM on that sender. | DMARC Agent |
| Completed and dismissed ticket history | Keep completed and dismissed tickets available through status filters instead of removing the closed work from the account. | DMARC Agent |
| New-ticket notifications | Alert the team when the Agent finds a new issue so nobody has to watch the dashboard continuously. | DMARC Agent |
| Unused-sender review | Flag confirmed senders that have gone a year without sending and show the records that still authorize them. | DMARC Agent |
| Domain and DNS operationsManage the estate, host authentication records, or publish approved changes directly into your existing DNS. | ||
| Free, unlimited domain adding | Add domains for monitoring without a card or billing event. Plan limits apply when you set up DMARC, not when you import. | Core platform |
| CSV bulk import | Bring a portfolio into Palisade in one upload instead of creating domains one at a time. | Core platform |
| Domain portfolio view | Compare status, group, score, policy, email volume, compliance, and open tickets across every domain. | Core platform |
| Domain overview | Open one domain to review email activity, senders, hosted-record state, policy, and current work. | Core platform |
| Park and unpark controls | Pause work on a domain without deleting it from the portfolio, then return it to active monitoring when needed. | Core platform |
| Domain groups | Organize domains by client, business unit, team, or portfolio and use the same grouping across workflows. | Core platform |
| Hosted DMARC | Delegate the DMARC record by CNAME so approved policy changes can deploy from Palisade. | Hosted DNS |
| Hosted SPF include | Authorize confirmed senders behind one Palisade-hosted include rather than maintaining a growing record by hand. | Hosted DNS |
| Automatic SPF flattening | Collapse nested includes behind the hosted record so receivers evaluate SPF within the ten-lookup limit. | Hosted DNS |
| Hosted DKIM public records | Manage delegated DKIM public-key records in Palisade while the sending service retains its private signing key. | Hosted DNS |
| Hosted BIMI | Delegate the BIMI record to Palisade and publish approved logo or certificate changes without another DNS edit. | Hosted DNS |
| Hosted MTA-STS | Host the MTA-STS policy and delegated record that tell sending servers to require trusted TLS for inbound mail. | Hosted DNS |
| Redundant managed DNS | Serve delegated email-authentication records on redundant managed DNS while your registrar and nameservers stay in place. | Hosted DNS |
| Automatic DNS-provider detection | Recognize which provider answers for a domain before starting the record-publication flow. | Smart DNS |
| Automatic setup across 64 DNS providers | Use one guided connection flow across a mixed estate instead of learning a different record editor for every provider. | Smart DNS |
| Scoped provider authorization | Authorize in the DNS provider's own window without sharing credentials; access is limited to email-authentication records. | Smart DNS |
| Direct publishing into your own zone | Write an approved SPF, DKIM, DMARC, BIMI, or MTA-STS record into the existing DNS zone without moving nameservers. | Smart DNS |
| Generated-record fallback | Get the complete record ready to copy when a domain stays on external DNS or a provider is not supported. | Core platform |
| Post-publish verification | Confirm receivers can resolve the new value and turn a failed or drifted change into a visible ticket. | Core platform |
| Revocable DNS connection | Disconnect provider access at any time while records already published remain in your own zone. | Smart DNS |
| BIMI and brand displayHandle the authentication, logo, record, and certificate steps needed to show a verified brand mark in supporting inboxes. | ||
| BIMI enforcement readiness | Use the staged DMARC path to reach the quarantine or reject policy that mailbox providers require for BIMI. | BIMI |
| SVG Tiny PS conversion | Convert an existing SVG into the restricted square profile required by the BIMI specification. | BIMI |
| Hosted or provider-published BIMI record | Host the record through delegation, publish it into connected DNS after approval, or generate it for manual use. | BIMI |
| BIMI record, logo, and certificate checks | Validate the public record, SVG file, and certificate references before and after deployment. | BIMI |
| Mailbox-provider requirement guidance | Track the different BIMI and certificate requirements used by Gmail, Yahoo, Apple Mail, and other supporting providers. | BIMI |
| VMC and CMC certificate guidance | Prepare the domain and logo for a Verified Mark or Common Mark Certificate supplied through Signet. | Signet partner |
| MSP, team, and client reportingOperate across clients, control access, and turn technical progress into client-facing proof under your own brand. | ||
| Multi-organization portfolio | Manage separate customer organizations from one operating view instead of maintaining one login per client. | MSP workspace |
| Per-client separation | Keep each client's domains, reports, access, and operational context separated inside the shared portfolio. | MSP workspace |
| Group-scoped access | Restrict users to the domain groups or clients they are responsible for without exposing the full estate. | MSP workspace |
| Unlimited users on every plan | Invite the full team without per-seat charges on every published plan, including Free. | Team administration |
| Team invitations | Add colleagues and client stakeholders to the correct organization or portfolio workflow. | Team administration |
| Roles and viewer access | Give people the level of access they need, including read-only visibility for stakeholders who should not change settings. | Team administration |
| Client portal access | Let clients view their own separated domain and reporting context when you want them involved directly. | MSP workspace |
| Microsoft and Google sign-in | Use familiar identity-provider sign-in alongside the platform's role and access controls. | Team administration |
| Organization and account administration | Manage organization settings, profiles, team membership, notifications, and billing from the same account. | Core platform |
| Notification preferences | Control which platform and reporting events reach the people responsible for acting on them. | Core platform |
| Prospecting assessments | Add a prospect's domain free and build an evidence-based email-security assessment before the first meeting. | Client reporting |
| White-label PDF reports | Generate client-ready assessments under your own name and logo so your firm gets the credit for the work. | Client reporting |
| Before-and-after progress | Show the score and posture where a domain started, where it stands now, and what changed between reports. | Client reporting |
| Detailed report content | Include score, policy stage, sending sources, authentication results, and changes since the previous report. | Client reporting |
| Scheduled reports and reporting preferences | Set reports to run on a schedule and control how recurring client reporting is delivered. | Client reporting |
| ConnectWise PSA integration | Connect client and domain work to ConnectWise PSA for MSP account operations. | MSP integration |
| Autotask integration | Connect client and domain work to Autotask for MSP account operations. | MSP integration |
| HaloPSA integration | Connect client and domain work to HaloPSA for MSP account operations. | MSP integration |
| PSA workflow synchronization | Support domain import, client mappings, task or ticket creation, and billing or domain synchronization in the connected PSA. | MSP integration |
| Developer, automation, and enterprise controlsConnect Palisade to the systems and AI clients your team already uses, with enterprise identity and support options when required. | ||
| API access on every plan | Use Palisade programmatically on any published plan, including the Free plan. | Developer |
| 30-tool remote MCP server | Connect Claude, ChatGPT, Copilot, or another compatible client to 30 Palisade tools over Streamable HTTP. | MCP |
| OAuth for interactive MCP clients | Sign in through the browser instead of creating and pasting a long-lived secret into an AI client. | MCP |
| Bearer API keys for headless use | Authenticate CI, scripts, and unattended MCP clients with an organization-scoped API key. | Developer |
| MCP domain operations | List, inspect, add, verify, update, and remove organization domains from a connected AI client. | MCP |
| MCP DNS and policy operations | Retrieve exact records, inspect SPF, and manage supported Palisade-hosted DMARC and MTA-STS operations. | MCP |
| MCP work-queue operations | List, inspect, complete, or dismiss the authentication tasks Palisade finds. | MCP |
| MCP DMARC summaries and senders | Read volume, SPF, DKIM, and DMARC pass rates and list confirmed or unknown senders from an AI client. | MCP |
| MCP group management | List, create, update, and remove the groups used to organize domains and client portfolios. | MCP |
| Webhook endpoint management | Register HTTPS endpoints, choose supported event types, inspect delivery health, and remove endpoints when finished. | Developer |
| Generic platform webhooks | Send domain and task events into the operational workflows your team already runs. | Developer |
| SAML single sign-on | Use enterprise SAML identity controls for larger deployments with centralized access requirements. | Enterprise |
| Custom data retention | Set bespoke retention or deletion terms for enterprise compliance while paid plans otherwise keep unlimited report history. | Enterprise |
| Dedicated technical contact and SLA | Add a dedicated technical relationship and documented service terms for enterprise deployments. | Enterprise |
| Custom volume and commercial terms | Shape packaging for higher sending volume, procurement, and contract requirements outside the self-serve plans. | Enterprise |
Every DNS or policy change still requires your approval. Verified Mark and Common Mark Certificate guidance is supplied through Signet; Palisade handles the DMARC, logo, record, and verification workflow.
Every free checker, generator, and analyzer
Use these one-off diagnostics before signup or alongside the platform. Continuous monitoring, history, tickets, and remediation live inside your Palisade account.
| Tool | What it does | Type |
|---|---|---|
| Checkers | ||
| Email Security Score | Email Performance | Checkers |
| Email Spam Checker | Send an Email, Get Your Spam Score | Checkers |
| DMARC Checker | Domain Defender | Checkers |
| SPF Checker | Authorized Senders List | Checkers |
| DKIM Checker | Digital Signature | Checkers |
| BIMI Checker | Brand Display and Verified Checkmark | Checkers |
| MX Checker | Mail Exchange Addresses | Checkers |
| MTA-STS Checker | Enforced TLS for Inbound Mail | Checkers |
| Microsoft Compliance Checker | DMARC 2025 Requirements | Checkers |
| For MSPs | ||
| Portfolio Benchmark Audit | Compare Up to 25 Domains | For MSPs |
| Generators | ||
| DMARC Record Generator | Create Your DMARC Record | Generators |
| SPF Record Generator | Build Your SPF Record | Generators |
| DKIM Record Generator | Create a DKIM Key Pair | Generators |
| BIMI Record Generator | Create Your BIMI Record | Generators |
| BIMI SVG Converter | Make Your Logo BIMI-Ready | Generators |
| Calculators | ||
| Deliverability & Bounce Rate Calculator | Delivery, Bounce and Complaint Rates | Calculators |
| Email Warmup Calculator | Plan a Sending Ramp | Calculators |
| BEC Cost Calculator | Model Your Cost from FBI IC3 Data | Calculators |
| Reputation | ||
| Domain Reputation Checker | Domain Blacklist Status | Reputation |
| IP Reputation Checker | IP Blacklist Status | Reputation |
| URL Reputation Checker | Threat Analysis | Reputation |
| Blocklist Checker | DNSBL Listing Status | Reputation |
| Phishing Link Checker | Is This Link Safe? | Reputation |
| Analyzers | ||
| Spam Words Checker | Spam Trigger Words in Your Copy | Analyzers |
| Email Header Analyzer | Delivery Path and Auth Results | Analyzers |
| DMARC Report Analyzer | Read Aggregate RUA Reports | Analyzers |
| DNS Lookup | Record Verification | Analyzers |
How the platform closes the DMARC loop
Most DMARC tools stop after showing you a report. Palisade joins the evidence, the remediation, the DNS change, and the proof in one human-approved workflow. Start with the part creating the most work today; the rest of the platform is already connected.
1. See
Name the sender behind the failure
The Email Deliverability Platform turns aggregate reports into a view of every sender, its volume, and its SPF, DKIM, and alignment status. You begin with the system that is actually failing, not a generic warning.
2. Decide
Review the fix before it ships
The AI DMARC Agent turns each issue into prioritized work with the evidence and recommended remediation attached. A person reviews every sender, record diff, and policy step before anything changes.
3. Deploy
Remove the DNS copy-paste
Use Hosted DNS for approved authentication changes and SPF Flattening to keep provider includes under the lookup limit. Your DNS provider stays in place while the recurring upkeep moves into Palisade.
4. Prove
Show the outcome where it matters
Turn progress into white-label client reports, carry enforced domains into BIMI, or manage the same work from your assistant through the Palisade MCP server.