DMARC agent that does the work for busy MSPs
Stop babysitting reports for every client. Palisade’s agent finds every sender, drafts the SPF and DKIM fixes, and carries each client domain to enforcement. You approve every step.
Not-For-Resale license on your own MSP domain. 15-day full-product trial.






































and 1,000+ more
Built to make MSPs’ jobs easier
Ten client domains or thousands. One dashboard, and an agent that does the work.
Unlimited Email Volume
No email caps. No overage fees. High-volume client domains won’t eat your margins.
Per-Client-Domain Pricing
New MSP accounts are billed for a minimum of 5 client domains. Your rate improves as your client-domain portfolio grows.
PSA Integrations & API
ConnectWise, Autotask, HaloPSA. Sync tickets and billing automatically. Build workflows and integrations with our API, included on every plan.
Multi-tenant solution
Domain groupings, team permissions, client portal access, Microsoft/Google SSO, and role-based controls, all in one view.
Fully Hosted SPF, DKIM, DMARC, BIMI & MTA-STS
Managed for you, and served on redundant DNS.

Smart DNS Deployment
Connect a client's Cloudflare, Route 53 or eligible GoDaddy account once, or sign in per domain at any of 64 providers. Every record you approve is published straight into the client's own zone.
SPF Flattening
Automatic flattening keeps every client domain under the 10-lookup limit.
Dedicated Onboarding
Our team gets you and your first client domains live fast. We do the setup with you.
North American Support
Real people. Your timezone. Built and supported in North America.
MSP Program Tiers
Better pricing, MDF funds, and priority support as you grow with us.
Sales Enablement Suite
Co-selling support, battle cards, pitch decks, and social media templates, ready to use.
15-day full-product trial.
Your client list is already in your PSA. So start there.
Palisade pulls client domains straight from ConnectWise, Autotask or HaloPSA, then keeps tickets and billing in sync as you protect them.
Run Palisade from the AI you already use
An agent or a script can add client domains, read what Palisade found, and fetch the exact records to publish. Publishing into a client's DNS provider stays in the app, where you approve it. Point your assistant at the MCP server, or build on the REST API. Both are included on every plan.
MCP server
Point Claude, or another MCP client that signs in through Palisade's OAuth client, at Palisade to add a client domain, inspect the problems Palisade found, fetch the exact records to publish, and verify the domain after the records are live.
https://api.palisade.email/mcp
Authenticates with OAuth through Palisade's public connector client.
Explore the Palisade MCP server →MCP server docs →REST API
Add and remove domains, group them, and pull the exact records each one needs. Build the PSA and RMM integrations and internal dashboards your team actually runs on. You can even create an account over the API, with no browser involved.
API guide and reference →Works with
MCP is an open protocol: other clients connect through the same OAuth sign-in or the official stdio bridge, and the MCP page lists the setup for each. Build your own agents and workflows on the same tools and wire them into whatever you already run.
Priced per client domain, not per client’s email volume
MSPs pay per client domain, with a rate that improves as your portfolio grows. New MSP accounts are billed for a minimum of 5 client domains. Your own MSP domain is included as a free Not-For-Resale license.
How you are billed
Billed on
Each client domain you set up DMARC for.
Minimum
New MSP accounts are billed for a minimum of 5 client domains. Your own NFR domain is free on top.
Your rate
Gets cheaper as your portfolio grows. The more client domains you run, the less each one costs.
Your own MSP domain
Free, as a Not-For-Resale license.
Client email volume
Not metered. A client tripling their sending costs you nothing extra.
Adding a domain
Always free. Import a whole book and read the audit first. Billing starts at DMARC setup, not at import.
Client domains
Unlimited.
Users
Unlimited, on every plan.
Report retention
Unlimited. Report history never expires.
Support
Priority.
Trial
15 days, full product. You add a card at checkout to start it, and nothing is charged until it ends.
Included with every MSP account
- True multi-tenant dashboard
- White-label client reports
- HaloPSA, Autotask and ConnectWise
- Bulk domain import and migration help
- Hosted DMARC, SPF, DKIM, BIMI and MTA-STS
- Automatic SPF flattening
- Advanced reporting, blocklist and reputation monitoring
- API access
From people who run this for a living
MSPs and MSSPs protecting client domains with Palisade.

“Palisade allowed our team to deploy DMARC on our domains in minutes instead of hours and making sure our clients are compliant with cutting edge security recommendations from Microsoft.”


“Since we started using Palisade, managing email authentication at scale has been clearer and more proactive. It lets us go further, with better visibility and greater efficiency.”


“Palisade streamlined all of our DMARC operations. It was so complicated at first, it was taking so much time. It allowed us to get everything done faster and have a complete overview of our operations, at such an affordable cost. We're saving so much time. It's a great improvement for our operations.”

“Flotek has integrated Palisade into its website and Partner Portal as Flo Verified Mail. The public reporting experience helps businesses identify email-security risks and begin an informed conversation with Flotek.”

“I've migrated all my clients from PowerDMARC. The agent was so powerful it allowed us to do the work in a fraction of the time.”

“We moved all our clients from a competitor, which gave us so much more clarity about what to do with the remediation option from the agent.”

Choose What to Improve in Your Managed DMARC Service
Explore a focused guide for reducing technician work, enabling MSP teams, scaling across clients, or growing recurring revenue.
Monitoring one domain is a task. Monitoring two hundred is an operation.
The work recurs. Every new client, every SaaS tool a client signs up for, every key rotation restarts part of the cycle. This is the job description, and the part Palisade takes.
Questions MSPs ask
Can I manage DMARC for every client from one place?
Yes. Every client domain sits in one dashboard, with per-client separation for reporting and access, from a handful of domains to thousands. You get domain groupings, team permissions, client portal access, Microsoft and Google SSO, and role-based controls. One account per client multiplies logins and billing, and makes it harder to spot the same spoofing campaign across your book.
How does MSP pricing work?
MSPs pay per client domain, with a rate that improves as your portfolio grows. New MSP accounts are billed for a minimum of 5 client domains. Your own MSP domain is included as a free Not-For-Resale license. The more client domains you run, the less each one costs. Client email volume is not metered either, so a client's growth costs you nothing extra. Book a call and we will quote against your portfolio.
Do I get an NFR license for my own MSP?
Yes. Your own MSP domain is free as a Not-For-Resale license: run Palisade on your own environment before rolling it out to a single client. Your account starts with a 15-day full-product trial, and nothing is charged until it ends.
Does adding a client domain cost me anything?
No. Adding domains is free and unlimited on every plan. Bulk-import a client's whole portfolio and read the audit without paying anything. Billing applies to setting a domain up, not to adding it.
Which PSAs do you integrate with?
ConnectWise PSA, Autotask and HaloPSA, on MSP accounts. Client domains import straight from the PSA you already run. Need more than the native integrations? The API and the MCP server are free on every plan, documented at developer.palisade.email.
Can I put client-facing reports under my own brand?
Yes. White-label reports go out under your brand, ready to put in front of a client at a QBR. Prospecting reports do the same for accounts you have not won yet.
Do I have to touch each client's DNS host?
Not by hand. Palisade publishes the records you approve, and how often you open a client's DNS host depends on the path you choose. If the client's DNS is at Cloudflare or Amazon Route 53, or at a GoDaddy account with API access, connect that account once and every record you approve is published into the client's own zone. At any of 64 providers, you can instead approve a domain's records in a one-time sign-in, and Palisade keeps no access afterwards. To stop visiting the DNS host after setup, delegate: Palisade hosts SPF as an include, DMARC, BIMI and MTA-STS through CNAME delegation, and DKIM through NS delegation of _domainkey, so later changes happen in Palisade. That keeps key rotation and SPF upkeep survivable across a book of clients.
What if DMARC breaks a client's mail?
This is the number one fear, and it is a fair one: badly done DMARC really does fail legitimate mail. Palisade starts every domain at p=none, which collects data without touching delivery. The agent proposes enforcement only once every legitimate sender authenticates, and you can see exactly which messages would have been affected before anything changes. Nothing ships without your approval.
Can I migrate clients from another DMARC platform?
Yes, and you do not have to cut over blind. A DMARC record takes multiple rua recipients, so both platforms receive the same reports while you run them in parallel. When Palisade shows the same senders you were tracking, drop the old address.
