Hosted DMARC, SPF and DKIM. Just tell your agent “GO”
Hosted DMARC is Palisade serving your DMARC, DKIM, BIMI and MTA-STS records by CNAME delegation, and your SPF by hosted include. After that, every fix ships when you approve it.
The current Palisade workflow creates acme.com, publishes one managed CNAME with Cloudflare, verifies DNS automatically, and confirms that the domain is protected.
What Hosted DNS helps you accomplish
Approve, and it ships
No copying records into a registrar, no waiting on whoever holds the DNS login. The change you approve in Palisade is the change that goes live.
Your provider stays
Palisade touches the email-authentication records and nothing else. Your registrar, your nameservers, and every other record stay exactly where they are today.
Records that stay watched
Palisade serves the records and keeps monitoring them: if something drifts or a key needs rotating, that's a ticket, not a surprise.
Trusted by leading brands worldwide




































Delegate once, deploy forever
One setup step turns every future fix into a review-and-approve.
Connect the domain once
Delegate the email-authentication records to Palisade with one CNAME each (DMARC, DKIM, BIMI and MTA-STS) and publish a single hosted include for SPF. Your registrar and nameservers do not move.
The Agent drafts a change
A new sender needs DKIM, a policy step is ready, an SPF source changed. The fix arrives as a ticket with the exact record drafted.
You approve the diff
Every ticket shows precisely what will change, down to the record diff. Nothing deploys until you say so.
Palisade deploys and verifies
The approved change goes live on Palisade's DNS and the monitoring confirms receivers see it. On domains without delegation, you copy the generated record instead.
What hosted DMARC gives you
CNAME delegation, reversible
Delegate DMARC, DKIM, BIMI and MTA-STS with one standard CNAME each, and point SPF at a hosted include. Remove the CNAME and you are back where you started.
Hosted SPF include
SPF joins through one hosted include, flattened to stay under the 10-lookup limit as your senders grow.
Redundant managed DNS
Hosted records are served on redundant managed DNS, so the answers receivers get are fast and consistently available.
Diffs before deploys
Approval means seeing the exact before-and-after of the record, not trusting a summary of it.
History and snapshots
See the authentication records Palisade sees right now, plus periodic snapshots of what changed and when.
Last seen, per sender and key
Every SPF entry and DKIM key shows the last day mail actually used it, drawn from a year of your own reports. Removing one becomes a decision with evidence behind it.
Optional, per domain
Hosted DNS is the fast path, not a requirement. Domains on external DNS get every record generated and ready to copy to your provider.
Proof from teams managing authentication at scale.Less manual work. More domains moving forward.
5.0 out of 5 on G2Trusted by over 10,000 domains
Built for MSPs
A no-brainer.Why Integris chose Palisade after evaluating the field.
“We evaluated many DMARC providers before choosing Palisade. The quality of their product, the responsiveness and friendliness of their team and their rapid progress on their product roadmap made it a no-brainer for us to move forward.”
Integris

Hosted DNS: FAQ
What is hosted DMARC?
Hosted DMARC is Palisade serving your email-authentication records. You delegate DMARC, DKIM, BIMI, and MTA-STS with CNAME records (and point SPF at a hosted include) so approved changes can be applied from Palisade instead of hand-edited at your DNS provider.
Do I have to move my domain or nameservers?
No. You publish one CNAME per record type at your existing DNS provider and Palisade serves those records from its own zone. Your registrar, your nameservers, and every non-email record stay untouched, and the delegation can be undone at any time.
Which records can Palisade host?
DMARC, DKIM, BIMI, and MTA-STS through CNAME delegation, and SPF through a hosted include. Together that covers the records email authentication depends on.
Can Palisade change my records without me?
No. The Agent investigates, drafts the fix, and proposes each step, you approve before anything ships. Hosted DNS changes what happens after approval: deployment is a click instead of a copy-paste.
What if I'd rather keep records at my own provider?
That works everywhere in Palisade, and it no longer means copy-paste. Smart DNS Deployment connects your DNS provider and publishes each record you approve straight into your own zone, across 64 providers. If a provider is not covered, the record is still generated in full for you to paste, and monitoring confirms when it is live. Hosted DNS is the other option: delegate the records once and Palisade serves them for you.
How reliable is the hosting?
Hosted records are served on redundant managed DNS. And because Palisade also monitors the records it serves, a resolution problem surfaces as a ticket rather than going unnoticed.
Stop copying DNS records
1 domain free up to 1,000 emails/month





