MSPs are running with tool sprawl by default. TrackSSL for certs at $99/mo. EasyDMARC for email at $50-500/mo per client. UptimeRobot for uptime at $20-100/mo. DomainTools for lookups at whatever they can extract. Every tool bills separately, alerts differently, and none of them talk to each other.
Meanwhile the buyer pressure is only going up. The CA/Browser Forum SC-081v3 timeline drops TLS cert lifespan to 200 days (March 2026), then 100 days (2027), then 47 days by 2029 — 8× more renewals per domain than today. Manual tracking already breaks at scale; at 47 days it’s a slow-motion crisis.
Google and Yahoo’s bulk-sender rules hit November 2025 for permanent rejection of DMARC-non-compliant senders exceeding 5K/day. Every client with a marketing list now needs DMARC on p=reject or their mail bounces. PCI DSS 4.0.1 Req 5.4.1 (effective March 2025) mandates automated anti-phishing controls; NIS2 (October 2024) requires SPF+DKIM+DMARC+MTA-STS+DANE for in-scope entities with fines up to €10M or 2% of global revenue.
Your clients don’t know any of this yet. They’re going to.
The MSP Playbook, End-to-End
1. Onboarding — the first scan of a new client
Add the client’s root domain to your DomainScan dashboard. Within 60 seconds you have the composite trust score, full WHOIS record, every DNS record type, SSL cert with chain and days-to-expiry, SPF, DKIM, DMARC verdicts, security headers audit, and blacklist status across 47+ RBLs.
Export as a white-labelled PDF. Send to the client. That’s your first quantifiable “what we’re taking over” artefact.
2. Continuous monitoring — the moat
Every capability above runs on a schedule. DNS records diffed hourly. SSL certs checked daily. Email auth verified every 6 hours. Blacklists rechecked every 12 hours. WHOIS every 24 hours. Every drift, every renewal risk, every listing becomes a severity-classified event with timestamp and diff.
Alerts fire to Slack, Discord, or email. Feed into your PSA via the DomainScan API to open tickets automatically.
3. Remediation — Prism AI does the tier-1 work
An alert without a fix is a monitoring receipt. DomainScan’s Prism AI reads every failure and produces provider-specific remediation: “your Cloudflare + Let’s Encrypt setup needs this record, paste it here”. Junior techs handle the fix without pinging you.
4. Compliance evidence — for the QBR
Once per quarter you sit down with the client. Export the compliance evidence — DMARC journey progress, SSL renewal history, blacklist listings avoided, subdomain audit summary. That’s the artifact justifying the MRR.
Bundling for MSP Margins
Most MSPs price DomainScan into their per-client managed-services fee — usually $25-100/domain/month added into the client’s package. Cost to you: much less. Margin: healthy.
Or resell as a standalone “domain health monitoring” line item — $50-200/domain/month, positioned against TrackSSL + EasyDMARC + UptimeRobot combined pricing.
When You Absolutely Need This
- Any client sends >5K/day to Gmail or Yahoo → Google/Yahoo bulk-sender rules apply → DMARC
p=rejectrequired - Any client is PCI-scoped → PCI DSS 4.0.1 Req 5.4.1 → automated anti-phishing controls required
- Any client is NIS2-scoped (financial services, energy, healthcare, digital infra in EU) → SPF+DKIM+DMARC+MTA-STS+DANE required
- Any client renews a TLS cert manually → 47-day cert era coming → automation required
- Any client has a
*.brand.comsprawl → subdomain takeover risk → weekly audit required
Related
Read the DomainScan API + MCP guide, how to set up DMARC for Google Workspace, and how to audit subdomains for takeover.