Back to Learning CenterMSP Business

How should MSPs price DMARC management services?

By Samuel ChenardJuly 21, 20269 min read
How should MSPs price DMARC management services?

Price DMARC management as a recurring monthly or annual fee per domain, with a separate one-time setup charge for the initial rollout to enforcement. Anchor the recurring price to two cost drivers — how many sending sources a domain has and how much report analysis you commit to — and bundle it into your security stack rather than selling it as a standalone line item. The setup fee covers the labor-heavy move from p=none to p=reject; the recurring fee covers monitoring, report triage, and keeping records correct as the client's mail changes.

Quick Takeaways

  • The durable model is per-domain recurring + one-time setup: the setup fee pays for the rollout labor, the recurring fee pays for ongoing monitoring and remediation.
  • Your real cost is tool cost plus your technician's hours, not the DNS records themselves — price the labor, because that is where the work lives.
  • Tier on sending sources and reporting depth, not on message volume; a domain with fifteen sending tools is far more work than one with two, regardless of how much mail flows.
  • Charging a setup fee prevents the classic trap: doing the hard p=reject rollout for free and then earning a few dollars a month.
  • Bundle DMARC into a managed email-security or compliance offering so it rides existing invoices and renewals instead of competing as an à-la-carte add-on.
  • Automating record management and report triage is what turns DMARC from a time sink into a margin-positive recurring service.

What does an MSP actually deliver in DMARC management?

Pricing only makes sense once you name the deliverable, because clients are paying for your time and judgment, not for a TXT record they could paste themselves. A complete DMARC service covers the full lifecycle: discovering every legitimate source that sends as the client's domain, publishing aligned SPF and DKIM for each one, deploying a DMARC record, then walking the policy from p=none through p=quarantine to p=reject without breaking real mail.

After enforcement, the work does not stop — it changes shape. You monitor aggregate reports for new or failing sources, fix alignment when the client adds a marketing platform or help-desk tool, and produce a periodic report the client (or their cyber-insurer or auditor) can act on. If you are new to positioning this, our guide on why MSPs should offer email-security services covers the demand side before you set a number.

Split the deliverable into two priced pieces and the pricing model follows naturally:

  • Onboarding / rollout — one-time, labor-heavy, finite. Ends when the domain reaches enforcement.
  • Ongoing management — recurring, lighter per month but perpetual. This is the annuity.

How should MSPs structure the pricing model?

Charge a one-time setup fee for the rollout and a recurring per-domain fee for ongoing management. This mirrors how the work actually lands — a burst of effort up front, then steady low-touch monitoring — and it protects your margin from the most common mistake, which is absorbing the expensive rollout and hoping the thin monthly fee makes it back.

A few structures work in practice:

  • Per-domain recurring + setup. The default. Simple to quote, scales with the client's footprint, and every domain you protect is a line of recurring revenue.
  • Tiered flat fee. Good/better/best packages (e.g. monitoring-only, managed-to-enforcement, managed-plus-monthly-reporting). Easier for clients to compare than usage math.
  • Bundled into a security stack. DMARC folded into a broader managed-security or compliance bundle. Best for retention because the client never sees a separate cancellable line.
For the recurring price itself, avoid pricing on message volume — a low-traffic executive domain can be a spoofing target that demands strict enforcement, while a high-traffic transactional domain may be trivial once its two senders are aligned. Price on sending sources and reporting depth instead. A useful reference frame:
LeverLow effortHigh effort
Sending sources per domain1–3 (M365 + one ESP)8+ (CRM, help desk, billing, marketing, dev alerts…)
Policy targetMonitoring at p=noneFull rollout to p=reject
Reporting cadenceQuarterly summaryMonthly report + alerting
RemediationClient self-serves changesYou own every DNS change

The columns on the right are where your hours go, so they are what your tiers should track.

How do you set the actual numbers?

Work bottom-up from cost, then price to your target margin — never guess a round number. Your cost per domain per month is essentially your DMARC tooling cost plus the fraction of a technician-hour that domain consumes in monitoring and remediation. Add your setup cost as the technician-hours the rollout takes multiplied by your loaded labor rate.

A simple illustrative build-up (use your own real rates — these figures are examples, not market data):

  • Setup: if a rollout to enforcement takes roughly 4–8 hours of technician time at your loaded rate, your one-time setup fee has to clear that plus margin. Many MSPs quote setup as a flat per-domain figure so clients are not staring at an hourly meter.
  • Recurring: if a managed domain costs you your platform fee plus, say, 15–30 minutes of monitoring a month, your recurring per-domain price is that cost marked up to your standard managed-services margin.
Two guardrails keep this honest. First, decide whether tooling cost is passed through or absorbed into margin, and be consistent. Second, set a floor price per domain so a client with fifty low-traffic domains does not turn a healthy percentage margin into pennies of absolute dollars. If you are still weighing whether to build this in-house or lean on an automated platform, should you DIY DMARC or use an automated service breaks down the cost sides of that decision.

How do you package and sell it to clients?

Sell the outcome — "no one can send email as your company, and you can prove it to your insurer" — not the acronym. Most buyers do not know what DMARC is, but they understand brand impersonation, wire fraud, and failing a cyber-insurance questionnaire. Anchoring the value there lets you hold price; anchoring it on "a DNS record" invites a race to the bottom.

Bundling is your best retention lever. Fold DMARC into an email-security or compliance package alongside spam filtering, security-awareness training, and reporting, so it renews with everything else. DMARC increasingly shows up on insurance and framework checklists, which gives you a concrete reason to include it — our overview of how DMARC affects cyber insurance is a useful leave-behind for that conversation. For a wider view of how service lines are priced across the industry, the main MSP types and their pricing models gives helpful context. If you want to see the ongoing delivery motion this pricing pays for, our DMARC monitoring for MSPs overview walks through it.

Common mistakes when pricing DMARC services

Giving away the rollout to win the recurring fee

The move from p=none to p=reject is the most labor-intensive part of the whole engagement, and doing it for free to land a small monthly fee can take years to recoup. Always attach a setup fee to the rollout, even a modest one, so your most expensive hours are paid for when you spend them.

Pricing on message volume instead of complexity

Volume is easy to measure and almost irrelevant to your workload. A quiet domain with a dozen shadow-IT senders and a spoofing history is more work than a busy newsletter domain with one aligned platform. Tier on sending sources, policy target, and reporting depth, or you will systematically underprice the hard accounts.

Forgetting the perpetual maintenance

DMARC is not "set and forget." Clients add SaaS tools that send mail, rotate ESPs, and spin up new subdomains — each event can break alignment and land legitimate mail in spam. If your price assumes zero ongoing changes, the first busy quarter erases the margin. Price the monitoring, not just the setup.

No floor price on multi-domain clients

Percentage margins look fine until a client with dozens of parked or low-traffic domains drags your absolute revenue per domain toward zero. A per-domain floor keeps every protected domain worth managing.

Frequently asked questions

Should DMARC be a standalone SKU or bundled?

Bundling into a security or compliance package almost always retains better, because the client never evaluates DMARC as a separate cancellable expense. Keep a standalone SKU available for clients who explicitly ask to buy only DMARC, but lead with the bundle.

One-time setup fee or roll it into the monthly price?

Charge the setup fee separately. The rollout is a finite, expensive project; hiding it inside a low recurring price means you either underprice the service permanently or need an uncomfortably long contract to break even. A visible setup fee also signals that real work is happening.

How do you price per-domain when a client has many domains?

Use a per-domain rate with volume breaks and a floor. Genuinely active sending domains carry the standard rate; parked or non-sending domains you are simply monitoring can be discounted, but never below the floor that keeps them worth your attention.

Does message volume ever matter for pricing?

Rarely as a primary lever. It can be a secondary signal — very high-volume senders sometimes need tighter report analysis and faster remediation — but sending-source count and reporting commitment predict your labor far better than raw message counts.

Palisade is built to make this pricing model profitable for MSPs: it discovers every sending source, publishes and maintains aligned SPF, DKIM, and DMARC records, and turns raw aggregate reports into plain-language actions, so the recurring work that used to eat your margin becomes a few minutes per domain. Run any client domain through the free Email Security Score tool to produce an instant gap report you can turn into a scoped quote, and use the DMARC checker to validate a record before you hand over an invoice.

Keep going with AI

Ask AI how this applies to you

Take this guide to your assistant — each question opens pre-filled, with a link back to this page so it can read the details.

  • How should MSPs price DMARC management services?
  • How does this apply to my domain?
  • What should I do about it, step by step?

Share this article

Samuel Chenard

Written by

Samuel Chenard

CEO & Co-Founder, Palisade

Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.

More from Samuel

Related articles