Dashboard
Customers, domains, DMARC policy across the book, how much mail passes, scores and the trend.
For MSPs and IT providers
Sell managed email protection under your own brand. Put a whole book of clients on it with one bulk request, and let our engineers do the DMARC work behind you.
The partner console
24
61
38
3
Customers, domains, DMARC policy across the book, how much mail passes, scores and the trend.
Every client and domain, with search and filters. Open any client's portal, give a client a login, check DNS for 25 domains a click.
Scan a prospect's domain before you call them, without adding them as a customer.
Your name, colours, logo, browser icon and typeface, a branded sign-in link, and who answers support.
API keys, webhooks, PSA connectors and connection steps for AI assistants.
Invite colleagues as admins or members, and set the daily digest email.
Who on your team changed what, and when.
Unknown senders are asked of you and your client. Whoever answers first places the sender.
Onboarding a whole book
For clients on Cloudflare DNS, one bulk request and one run of a script cover DMARC, SPF, MTA-STS and TLS reporting. Clients on other DNS hosts get the same list of records to publish by hand.
Paste or upload a CSV of customers and domains, up to 500 rows at a time. Importing runs no scans and never emails anyone.
Tick up to 100 domains and the products your plan includes. We set up our side straight away.
A script publishes every record to Cloudflare in one go. Its dry-run mode changes nothing, so you can look first.
We read the DNS every four hours and switch each product on as its records answer. A domain we cannot take over safely is refused with the reason.
| Product | One request and one script run? | What needs more |
|---|---|---|
| Managed DMARC | ✓ Yes | Nothing. We take the policy towards reject one approved step at a time. |
| Managed SPF | ✓ Yes | A domain whose SPF we cannot take over safely is refused and left as it was. |
| Managed MTA-STS | ✓ Yes | Starts in testing mode. One of our engineers moves it to enforce. |
| TLS reporting | ✓ Yes | Nothing. It is included for every domain. |
| DKIM monitoring | ✓ Yes | Nothing, and no record. It learns the keys from DMARC reports. |
| DKIM signing, Microsoft 365 | ! Partly | We find each tenant and supply a script. You run it twice, with delegated admin access. |
| DKIM signing, Google Workspace | By hand | Google offers no way to do it by software. We give the exact steps. |
| Managed BIMI | Per client | Each client supplies a logo, and buys a mark certificate for Gmail and Apple Mail. |
The Microsoft 365 script is proven on our own tenant: on 25 September 2026 a test message passed SPF, DKIM and DMARC at Gmail. It has not yet been run through a partner's access to a client's tenant.
Your brand
The client portal and its sign-in page wear your name, logo, colours and typeface. You set two colours and the rest is worked out for you, with text contrast corrected so it stays readable.
Status colours stay green, amber and neutral under every brand, so protected always looks like protected.
Sign-in emails carry your name. They are still sent from our address.
Your tools
We open a ticket in your HaloPSA or ConnectWise PSA when something changes for a client, and add follow-ups as notes on the same ticket.
13 kinds of event, signed, and retried for about eight and a half hours if your endpoint is down.
Read the whole book, and add customers and domains. Nothing in the API can change a DMARC policy or email anyone.
A read-only MCP server lets Claude, ChatGPT, Microsoft Copilot Studio, n8n or Rewst answer questions about your book.
The commercials
One flat rate per domain, quoted in full on the first call. You set the retail price and keep the margin. Your clients are never billed by us.
Talk to us about partneringNo, never. Neither does adding a customer through the API. And importing runs no scans.
Yes, once a partner admin gives them a login from the Customers page. We show a one-time sign-in link for you to pass on. We email nobody.
Your own desk, once you name it on the Brand page. Until you do, requests reach our support team.
One of our engineers, by approving a step. A rule-based reviewer looks at each step first. Nothing in the API can change a policy.
Every read is scoped to the partner. A record that is not yours answers exactly as one that does not exist.
For DMARC, SPF, MTA-STS and TLS reporting on Cloudflare DNS: one bulk request and one run of the records script. DKIM signing needs a script run twice in each Microsoft 365 tenant, with delegated admin access, or steps by hand in Google Workspace; BIMI needs each client's logo and a mark certificate. The Microsoft 365 script is proven on our own tenant and has not yet been run through a partner's access to a client's tenant.
Yes. We read test mode the way the new standard applies it, and reject waits until every real sender signs with DKIM.
The free check works on any domain. Try it on one of your clients.