Skip to Main Content

Portfolio Benchmark Audit

Benchmark up to 25 client domains, prioritize DMARC and SPF work, and export a client-ready report.

Paste one domain per line or paste rows directly from a CSV.

Up to 25 domains. For CSV files, the browser extracts the Domain, Website, Host, or URL column; only normalized domains—not the file or other columns—are submitted for public DNS checks. .
0 unique domains ready

Free validation scan • Up to 25 domains • No login required

From Scan to Conversation

Give Every Client a Concrete Next Action—Not a Wall of DNS Records

The audit orders domains by operational urgency. Missing or unusable DMARC comes first, then monitoring-only policies and broken SPF, followed by reporting and mail-routing checks. A clean result is not declared “secure”; it means no prioritized finding was observed in this narrow public-record check.

01

Upload

Paste domains or choose a CSV. Extra client columns remain in your browser.

02

Prioritize

Run bounded public DNS checks and put the highest-impact configuration gaps first.

03

Deliver

Export a branded-neutral PDF for the conversation and a detailed CSV for the work queue.

Common Questions

Portfolio Audit Questions

What does the portfolio benchmark audit check?

It makes point-in-time public DNS checks for a valid DMARC record, DMARC enforcement and aggregate reporting, one valid SPF record and its recursive DNS lookup count, MX publication, and a default-selector BIMI record. It does not access mailboxes, messages, DNS accounts, or private client systems.

What should I put in the CSV?

Use one organizational website domain per row. A Domain, Website, Host, or URL column works, and extra columns are ignored. The file stays in the browser: only the normalized domains extracted from it are submitted to the DNS audit.

Is the MSP benchmark a score for my client portfolio?

No. The reference cohort measured 566 North American MSP organizational domains observed from a sourced public directory. It did not measure those MSPs' customer portfolios. The comparison provides context for a conversation, not a grade, ranking, security-maturity claim, or causal conclusion.

Why can the DMARC and SPF percentages use different denominators?

DMARC adoption is measured across all successfully observed domains, while enforcement and aggregate reporting are measured only among valid DMARC publishers. SPF lookup-limit health is measured only among valid SPF publishers. The report shows every numerator and denominator so a missing record cannot silently enter the wrong metric.

Can this prove that a client is secure or that email will be delivered?

No. Public DNS records show configuration state, not compromise, internal security maturity, mailbox-provider reputation, or final delivery. Use the prioritized findings to decide what to investigate, then verify legitimate senders and message-level authentication before changing an enforcement policy.

Why is the free audit limited to 25 domains?

The 25-domain version is designed to validate the workflow quickly without an account and without creating unnecessary load on public DNS resolvers. The exported CSV and PDF are complete for that sample; Palisade is the path for ongoing monitoring and larger managed portfolios.