DMARC Reseller: How MSPs Run Client Domains
A DMARC reseller is not a shared inbox of XML and one TXT record for every customer. It is a practice that runs email authentication per client organisation — inventory, reports, alignment, and policy — without dumping every domain into one tenant.
This field guide is for MSPs and resellers who search for a DMARC platform with per-client billing for MSPs, partner programmes for MSPs, or simplified DMARC management for multi-domain clients. It is the operator sequence. To talk about joining a programme, use Partners (enquiry — there is no public self-serve partner signup). If the domains are your brands, start at For Teams or Enterprise instead.
What a DMARC reseller actually is
Receivers evaluate the From domain on each message. Your client’s bank, law firm, or retailer is the brand that gets spoofed — not your practice name.
A reseller or MSP that “does DMARC” therefore:
- keeps one organisation per client (their domains, their reports, their policy path)
- runs a rollout sequence inside that organisation
- bills against that client’s protected domains, not a blended pool that finance cannot explain
If every customer domain lives in one account, you do not have a reseller model. You have a messy shared mailbox with extra DNS.
Why one shared tenant fails
Mixing clients looks cheaper on day one. It fails the first time you need a clean answer:
- Reports — rua volume for Client A’s ESP sits next to Client B’s payroll mail. You cannot brief either finance team.
- Policy — raising
p=quarantineon the “practice domain” does nothing for the client From domains that actually get spoofed — or worse, you change the wrong zone. - Billing — a blended domain count cannot become per-client billing for MSPs. The invoice cannot follow the book.
- Offboarding — when a client leaves, you cannot detach their zones without an archaeology project.
Isolation is not bureaucracy. It is how you stay able to delete, invoice, and raise policy without collateral.
Per-client billing for MSPs
Per-client billing for MSPs means the invoice can be tied to the organisations you actually protect this month — active sending names, parked names you still defend, and the work you did.
What that is not:
- one lump that mixes Client A’s parked names with Client B’s mail platform
- a public price list of wholesale unit rates
- card auto-collect or partner payout automation as a default
Honest commercial shape for a partner practice: usage-based wholesale sized with you, invoices settled by EFT, terms agreed for the practice. We do not publish unit rates in Rands on this site. Programme detail lives on Partners.
Partner programmes for MSPs
DMARC partner programmes for MSPs should answer four questions before you sign:
- Isolation — is each client a separate organisation, or one shared tenant?
- Who may edit DNS — can you connect a client’s DNS host and apply SPF, DKIM, and DMARC when they permit it, or only email screenshots?
- Who the client sees — managed-by branding with your name, or only the platform’s?
- How you join — a conversation and a contract, or a public “create partner account” form?
We onboard partners personally. There is no public self-serve partner signup. After that, you work a partner portfolio for the book — not a copy of the tenant product on the partner login. Client monitoring stays in the client’s organisation.
An MSP domain name reseller program that only resells registrar names, with no per-client authentication ops, is a different product. Do not confuse “we can register the domain” with “we can defend the From domain.”
Simplified DMARC management for multi-domain clients
Simplified DMARC management for multi-domain clients is a control-plane problem, not a prettier XML viewer.
For each client organisation:
- Inventory domains they can still renew (including parked and campaign names). See unused domains.
- Publish monitoring you will actually read — free domain check then aggregate reports.
- Fix alignment before you add another SPF include.
- Raise policy in stages on that client’s domains. Never flip every client to
p=rejecton the same Friday. Walk the enforcement path. - Keep parked names on a no-send posture.
The first DNS record on a single zone is still how to set up DMARC. The reseller job is repeating that sequence without mixing clients.
First 30 days with a new client
Keep the first month boring:
- Confirm the client organisation exists on its own — not as extra rows in another customer.
- Import the domain list from registrar + DNS host + marketing, not from memory.
- Publish
p=nonewith aruadestination someone on your team will open weekly. - Run a free check on the primary sending name and fix obvious DNS errors before you promise enforcement dates.
- Agree who may edit DNS, and whether you connect the client’s DNS host or hand records to their IT.
- Do not sell BIMI, MTA-STS hosting, or “we will be at reject in two weeks” until reports show known senders.
What to refuse
Do not treat these as “the reseller package”:
- flattening every client domain under one customer
- self-serve partner signup on a marketing site
- published wholesale unit rates
- SLA-backed support as a search-result promise (we do not claim SLA-backed support here; any SLA is only what is agreed in writing)
- custom-host white-label SSL, partner API keys, or processor auto-collect as if they were standard
- moving consumer mailboxes onto the partner book as a default
Those are either a different product, or not how a safe multi-client practice should work.
Where this sits
| You are… | Start here |
|---|---|
| MSP / reseller / referral with a client book | This article, then Partners → Talk to Partners |
| Protecting your own brands | For Teams or Enterprise |
| One domain, self-serve | Guides and pricing |
Final takeaway
A DMARC reseller runs per-client authentication: separate organisations, usage you can invoice, and a partner programme that does not flatten the estate. Simplified multi-domain management is isolation plus a repeatable rollout — not one shared tenant. If that is your practice, contact Partners. If it is your own company, do not apply as a reseller.