HaloPSA DMARC integration
Palisade integrates with HaloPSA on MSP accounts to import client domains, create DMARC tickets and synchronize software-license counts. Connect an API-only agent, map HaloPSA customers to Palisade groups, and choose the ticket workflow your technicians use.
Last verified: · Documentation and connector review
By Samuel Chenard, Palisade
Read the HaloPSA technical setup guideWhat data flows between Palisade and HaloPSA?
HaloPSA supplies client and configuration data. Palisade sends task updates and billing quantities through the mappings you configure.
| Data | Direction | What happens |
|---|---|---|
| Customers and contact domains | HaloPSA → Palisade | Read customers and users/contacts at each customer’s main site to discover domains from their email addresses. |
| Ticket configuration | HaloPSA → Palisade | Read ticket types, teams, statuses and priorities for mapping in Palisade. |
| DMARC tickets and updates | Palisade → HaloPSA | Create tickets for mapped customers and send task status and priority updates to the linked HaloPSA tickets. |
| Software-license count | Palisade → HaloPSA | Create or reuse the customer’s Palisade software license and synchronize its count with the mapped group’s billable domains. |
How are HaloPSA customers and domains imported?
HaloPSA customers map to groups within your Palisade MSP account. Palisade uses that mapping to put imported domains under the correct client and associate new tickets with the right HaloPSA customer.
Domain discovery reads users/contacts at the customer’s main site. The HaloPSA API application and the agent it runs as both need access to Users/Contacts. A customer without a main site or usable contact email addresses may have no domains to import. Review the results and add missing domains directly in Palisade.
Client mappings are managed through Palisade groups. Keep the mapping aligned with the client whose domains your team manages.
How do HaloPSA tickets and statuses stay connected?
Configure the HaloPSA ticket type and default support team, then map Palisade task statuses and priorities to your HaloPSA options. New tickets carry the mapped customer, status and priority along with the task’s details and a link back to Palisade.
Palisade sends task status and priority changes to the linked HaloPSA ticket. Keep all status mappings configured, including deferred and dismissed work, so your queue reflects how the task is being handled in Palisade.
Choose which Palisade task types create new HaloPSA tickets. Disabling a type stops new tickets for that type; existing tickets keep receiving updates. Re-enabling a type does not backfill tasks raised while it was disabled. Read the ticket-control rules.
The DMARC agent investigates issues and prepares fixes. Your technician reviews and approves DNS or policy changes; a PSA ticket is the place to track the work.
What does HaloPSA license synchronization update?
The HaloPSA connector uses a software license named Palisade for each mapped customer. During client synchronization, Palisade creates or reuses that license and stores its association with the client’s Palisade group.
With billing sync enabled, Palisade updates the license count to match the group’s billable domains. This is the quantity supplied to your HaloPSA billing workflow. Configure and verify your own recurring billing and invoice rules in HaloPSA before billing the client.
The HaloPSA API identity needs Software Licences access to read or create the client license during client synchronization and update its count during billing sync. Billing sync can be paused while task updates continue. Review the license count and integration logs after a billable domain change.
Which Palisade plans support HaloPSA?
The HaloPSA connector requires a Palisade MSP account. MSPs pay per client domain, with a rate that improves as your portfolio grows. Your own MSP domain is included as a free Not-For-Resale license.
Standard Free and IT-team accounts need MSP enrollment to use PSA integrations. Explore the MSP program or see how MSP pricing works.
What is required to set up HaloPSA?
Use a HaloPSA API identity with access to the clients and workflow you want to connect. Keep credentials in your team’s credential manager and enter them only in the integration’s credential form.
| Area | Required access |
|---|---|
| API-only agent | Create an API Agent in Configuration > Agents and assign its team and department. Use this agent as the API application’s login identity. |
| Tickets | Read and modify tickets; add new tickets and view unassigned and other agents’ tickets. Allow the ticket type and team used for Palisade work. |
| Customers and Users/Contacts | Read customers and users/contacts, including contacts at the customer’s main site. Apply the access to both the application and its agent. |
| Software Licences | Read and create/update the customer’s Palisade software license for quantity synchronization. |
1. Create the HaloPSA API identity
Create an API-only agent under Configuration > Agents. Grant ticket, customer and user/contact access. Allow software-license reads and creation for client synchronization, plus updates for billing quantities.
2. Create an API application
In Configuration > Integrations > HaloPSA API, create an application using Client ID and Secret authentication. Set it to log in as your API agent and record the Client ID and Client Secret securely.
3. Connect the original HaloPSA host
Select HaloPSA in Palisade Integrations. Enter your original HaloPSA hostname without https:// or /api, plus the Client ID and Client Secret. Use the HaloPSA-provided host rather than a custom domain.
4. Map and verify one client
Choose the ticket type, support team, statuses and priorities. Map a customer to a Palisade group, inspect the imported domains and verify the linked ticket and software-license quantity before extending the rollout.

Follow the HaloPSA technical setup guide for the credential fields and configuration sequence.
What should you verify before rolling out to clients?
Start with a test client in HaloPSA and confirm the mapping, ticket and billing results your team will rely on.
- The API application and its agent can read the mapped customer’s main-site contacts, and the expected domains appear in Palisade.
- A Palisade task creates a HaloPSA ticket for the correct customer, type and team; later Palisade task changes update its mapped status.
- The customer’s Palisade software-license count matches the group’s billable domains, and your HaloPSA billing rules use that quantity as intended.
HaloPSA integration FAQ
Does Palisade integrate with HaloPSA for DMARC?
Palisade integrates with HaloPSA on MSP accounts. The connector imports client domains from contact email addresses, creates DMARC task tickets, sends mapped task updates and synchronizes Palisade software-license quantities.
Which Palisade plan supports HaloPSA?
HaloPSA integration requires a Palisade MSP account. Enroll in the MSP program to use the connector; standard Free and IT-team accounts do not by themselves enable PSA integrations.
Why does HaloPSA connect but import no client domains?
HaloPSA domain discovery needs a customer main site and readable users/contacts with email addresses. Check both the API application and its agent for Users/Contacts access, then review the client-to-group mapping and retry domain import.
Does Palisade create HaloPSA invoices?
Palisade updates the mapped customer’s Palisade software-license count from billable domains. Your HaloPSA billing configuration determines how that quantity is used on invoices. Verify the license and billing rules together before invoicing.