For MSPs and IT providers

Every client domain, one console.

Sell managed email protection under your own brand. Put a whole book of clients on it with one bulk request, and let our engineers do the DMARC work behind you.

The partner console

Your whole book, at a glance.

Partner console · DashboardScreenshot to come

Customers

24

Domains

61

At reject

38

Need attention

3

Customers

Harbourview Lettings
harbourview.example
✓ Reject
Calder & Finch
calderfinch.example
Quarantine 50%
Tidewell Dental
tidewell.example
Observing

Dashboard

Customers, domains, DMARC policy across the book, how much mail passes, scores and the trend.

Customers

Every client and domain, with search and filters. Open any client's portal, give a client a login, check DNS for 25 domains a click.

Domain Scanner

Scan a prospect's domain before you call them, without adding them as a customer.

Brand

Your name, colours, logo, browser icon and typeface, a branded sign-in link, and who answers support.

Integrations

API keys, webhooks, PSA connectors and connection steps for AI assistants.

Team

Invite colleagues as admins or members, and set the daily digest email.

Activity

Who on your team changed what, and when.

Senders to confirm

Unknown senders are asked of you and your client. Whoever answers first places the sender.

Onboarding a whole book

One request. One script run.

For clients on Cloudflare DNS, one bulk request and one run of a script cover DMARC, SPF, MTA-STS and TLS reporting. Clients on other DNS hosts get the same list of records to publish by hand.

  1. 01

    Import

    Paste or upload a CSV of customers and domains, up to 500 rows at a time. Importing runs no scans and never emails anyone.

    rows: up to 500
  2. 02

    One bulk request

    Tick up to 100 domains and the products your plan includes. We set up our side straight away.

    domains: up to 100
  3. 03

    One script run

    A script publishes every record to Cloudflare in one go. Its dry-run mode changes nothing, so you can look first.

    mode: dry run, then apply
  4. 04

    It finishes itself

    We read the DNS every four hours and switch each product on as its records answer. A domain we cannot take over safely is refused with the reason.

    check: every 4 hours

What that covers, and what needs more

What that covers, and what needs more
ProductOne request and one script run?What needs more
Managed DMARC✓ YesNothing. We take the policy towards reject one approved step at a time.
Managed SPF✓ YesA domain whose SPF we cannot take over safely is refused and left as it was.
Managed MTA-STS✓ YesStarts in testing mode. One of our engineers moves it to enforce.
TLS reporting✓ YesNothing. It is included for every domain.
DKIM monitoring✓ YesNothing, and no record. It learns the keys from DMARC reports.
DKIM signing, Microsoft 365! PartlyWe find each tenant and supply a script. You run it twice, with delegated admin access.
DKIM signing, Google WorkspaceBy handGoogle offers no way to do it by software. We give the exact steps.
Managed BIMIPer clientEach client supplies a logo, and buys a mark certificate for Gmail and Apple Mail.

The Microsoft 365 script is proven on our own tenant: on 25 September 2026 a test message passed SPF, DKIM and DMARC at Gmail. It has not yet been run through a partner's access to a client's tenant.

Your brand

Your name on the portal. Ours in the engine room.

The client portal and its sign-in page wear your name, logo, colours and typeface. You set two colours and the rest is worked out for you, with text contrast corrected so it stays readable.

Status colours stay green, amber and neutral under every brand, so protected always looks like protected.

Sign-in emails carry your name. They are still sent from our address.

Client portal · your brandScreenshot to come

Your brand · Client portal

harbourview.example
Protected: fakes are refused
✓ Reject
Security score
Scan complete
91 Excellent

Your tools

It works with what you already run.

PSA tickets

We open a ticket in your HaloPSA or ConnectWise PSA when something changes for a client, and add follow-ups as notes on the same ticket.

AutotaskBUILT, NOT YET LIVE

Webhooks

13 kinds of event, signed, and retried for about eight and a half hours if your endpoint is down.

Events13 KINDS

API

Read the whole book, and add customers and domains. Nothing in the API can change a DMARC policy or email anyone.

WritesADD ONLY

AI assistants

A read-only MCP server lets Claude, ChatGPT, Microsoft Copilot Studio, n8n or Rewst answer questions about your book.

AccessREAD ONLY

The commercials

Simple wholesale. One invoice.

One flat rate per domain, quoted in full on the first call. You set the retail price and keep the margin. Your clients are never billed by us.

Talk to us about partnering
  • A flat wholesale rate per domain
  • Minimum 5 domains to start
  • Parked and inactive domains free
  • No email volume metering
  • Month to month
  • Founding partners get locked pricing

Questions

Does importing customers email them?

No, never. Neither does adding a customer through the API. And importing runs no scans.

Can our clients sign in to their own portal?

Yes, once a partner admin gives them a login from the Customers page. We show a one-time sign-in link for you to pass on. We email nobody.

Who answers our clients' support requests?

Your own desk, once you name it on the Brand page. Until you do, requests reach our support team.

Who can change a DMARC policy?

One of our engineers, by approving a step. A rule-based reviewer looks at each step first. Nothing in the API can change a policy.

How is one partner's data kept from another's?

Every read is scoped to the partner. A record that is not yours answers exactly as one that does not exist.

Is onboarding really one step?

For DMARC, SPF, MTA-STS and TLS reporting on Cloudflare DNS: one bulk request and one run of the records script. DKIM signing needs a script run twice in each Microsoft 365 tenant, with delegated admin access, or steps by hand in Google Workspace; BIMI needs each client's logo and a mark certificate. The Microsoft 365 script is proven on our own tenant and has not yet been run through a partner's access to a client's tenant.

Are you ready for the 2026 DMARC standard?

Yes. We read test mode the way the new standard applies it, and reject waits until every real sender signs with DKIM.

Scan a prospect before you call them.

The free check works on any domain. Try it on one of your clients.