Portfolio Benchmark Audit
Benchmark up to 25 client domains, prioritize DMARC and SPF work, and export a client-ready report.
Give Every Client a Concrete Next Action—Not a Wall of DNS Records
The audit orders domains by operational urgency. Missing or unusable DMARC comes first, then monitoring-only policies and broken SPF, followed by reporting and mail-routing checks. A clean result is not declared “secure”; it means no prioritized finding was observed in this narrow public-record check.
01
Upload
Paste domains or choose a CSV. Extra client columns remain in your browser.
02
Prioritize
Run bounded public DNS checks and put the highest-impact configuration gaps first.
03
Deliver
Export a branded-neutral PDF for the conversation and a detailed CSV for the work queue.
Portfolio Audit Questions
What does the portfolio benchmark audit check?
It makes point-in-time public DNS checks for a valid DMARC record, DMARC enforcement and aggregate reporting, one valid SPF record and its recursive DNS lookup count, MX publication, and a default-selector BIMI record. It does not access mailboxes, messages, DNS accounts, or private client systems.
What should I put in the CSV?
Use one organizational website domain per row. A Domain, Website, Host, or URL column works, and extra columns are ignored. The file stays in the browser: only the normalized domains extracted from it are submitted to the DNS audit.
Is the MSP benchmark a score for my client portfolio?
No. The reference cohort measured 566 North American MSP organizational domains observed from a sourced public directory. It did not measure those MSPs' customer portfolios. The comparison provides context for a conversation, not a grade, ranking, security-maturity claim, or causal conclusion.
Why can the DMARC and SPF percentages use different denominators?
DMARC adoption is measured across all successfully observed domains, while enforcement and aggregate reporting are measured only among valid DMARC publishers. SPF lookup-limit health is measured only among valid SPF publishers. The report shows every numerator and denominator so a missing record cannot silently enter the wrong metric.
Can this prove that a client is secure or that email will be delivered?
No. Public DNS records show configuration state, not compromise, internal security maturity, mailbox-provider reputation, or final delivery. Use the prioritized findings to decide what to investigate, then verify legitimate senders and message-level authentication before changing an enforcement policy.
Why is the free audit limited to 25 domains?
The 25-domain version is designed to validate the workflow quickly without an account and without creating unnecessary load on public DNS resolvers. The exported CSV and PDF are complete for that sample; Palisade is the path for ongoing monitoring and larger managed portfolios.
How do unlisted portfolio report links work?
After an audit, you can copy an unlisted link to the exact point-in-time public-DNS snapshot. The link is excluded from search, expires after 90 days, and contains no mailbox content, credentials, private DNS access, or client contact fields. Anyone who has the link can view it, so share it as you would any client report.