DMARC for service providers: scope it, price it, deliver it

10 min read

Your clients were not asking about DMARC two years ago. They are starting to, and you are going to have to decide whether it is a technical chore you throw in or an engagement you sell.

This article is about the second option.

Why the demand is arriving now

Two movements converge.

The major mail operators have tightened their requirements for bulk senders. What used to be recommended has become conditional: without proper authentication, deliverability degrades. Clients who send newsletters or invoices in volume notice it before they understand why.

In parallel, supplier-impersonation fraud has become commonplace. A falsified invoice sent from your client's domain to their own customers costs almost nothing to produce. When it happens once inside a professional network, everybody hears about it.

The result: the question comes up, often badly phrased. “Somebody told us we need to do DMARC.”

What you are actually selling

First decision, and it determines everything else: you are not selling a software subscription.

The tool that analyzes the reports costs a few euros per domain per month. If you resell it with a markup, you are selling a five-euro product and you will fight on price against vendors who do this for a living.

What you are selling is the decision and the responsibility. The client does not want a dashboard; they want somebody to tell them they can tighten without breaking their invoicing, and they want that somebody to stand behind it. That is consulting, it is billed like consulting, and the margin bears no resemblance.

The tool remains indispensable, but as an instrument of production, in the same way as your monitoring or your ticketing system. It makes the engagement possible and repeatable. It is not the offer.

Three tiers, to be sold separately

The engagement splits naturally into three blocks, whose economics are very different.

The audit

Two to three hours of work. You record the existing DNS state, publish a monitoring policy, wait two weeks for reports, and produce a picture: here are the eleven tools writing in your name, here are the four that are not authenticated, here is the risk.

Rate cards published by English-language vendors put an audit between €500 and €1,500, with a margin of 80 to 90%. On smaller markets, and with small and mid-sized clients, the lower end is more realistic.

Many providers give it away. That is defensible, but on one measurable condition: that the conversion rate into a deployment stays above four in ten. Below that, you are funding curiosity.

The deployment

Twenty to forty hours spread over eight to twelve weeks. You get every legitimate sender signing with the client's domain, eliminate abandoned tools, and progress toward quarantine and then reject.

The same rate cards put a deployment between €3,000 and €15,000 depending on complexity, with a margin of 50 to 70%. The margin is lower because the human workload is real and variable.

The important point: most of the elapsed time does not come from you. It comes from provider support desks that take three weeks to answer a DKIM configuration request. Quote a fixed price, never time and materials, and build that latency into the schedule you give the client.

The monitoring

One to two hours per month per client. You read the reports, handle newly appeared senders, and check that the policy is holding.

Between €50 and €300 per domain per month depending on client size, with a margin of 70 to 90%.

This is where your business is. The audit is a lead product, the deployment is a project, the monitoring is the recurring revenue that justifies everything else. A client who is deployed and not monitored degrades within six months: a department plugs in a new tool, nobody sees it, and the reject policy starts blocking legitimate messages.

An order of magnitude to put things in perspective: the platform producing those reports costs you between €5 and €50 per domain per month. The ratio between the cost of the tool and the price of the engagement around it runs from one to ten, sometimes more.

Scoping the audit so you do not deploy for free

The classic trap is familiar to anyone who has done this before. You give away the audit. During the audit, you spot a misconfigured sender. The client asks “could you take a look?”. You fix it, because it is ten minutes. Three weeks later, you have delivered half the project without signing anything.

Three rules to avoid it.

The audit observes, it does not fix. Write that into the proposal. The deliverable is a document, not a change.

The document names the fixes and prices them. Every non-compliant sender appears with the action required and the estimated effort. That is what turns an observation into a quote.

One DNS change is included, the one that publishes the monitoring policy. It is required in order to produce the audit at all, and it carries no risk for the client. Every other change belongs to the deployment.

The deliverable that justifies the price

An audit billed at a thousand euros cannot end with a phone call and a screenshot.

You need a dated document, on your company's letterhead, that stands up on its own when the client's director passes it around. It contains the sender inventory with names, the volume of each one, its authentication state, the risk in plain language, and the costed plan.

That document has a second function, often underestimated: it is your best sales tool with other clients. An anonymized picture shown in a meeting sells better than any brochure, because the prospect recognizes their own situation in it immediately.

If the tool you use produces that document under your brand rather than its own, you save half the audit time. That is the selection criterion that matters most in your line of work, well ahead of feature depth.

The DNS trap

One last point, and it is the first place projects overrun.

Any DMARC engagement means changing the client's DNS. And in one small business out of three, nobody knows where it is hosted. The domain was registered by the previous web developer, the zone is managed at a registrar whose credentials are lost, or the website provider refuses to grant access.

Settle that question before signing, not during. Add it to your qualification: who manages the DNS, who has the access, and how long it takes to get a change made. If the answer is vague, your eight-week project will take twelve, and you will not bill for it.

What to take away

Sell three distinct tiers, not a subscription. Bill for the monitoring — that is where the revenue is. Scope the audit so that it observes without fixing. Produce a document that stands up on its own. And check DNS access before committing to a deadline.

For the technical side, two articles complete this one: alignment, which explains why your clients' senders fail, and moving to reject, which details the conditions to meet before tightening.

Frequently asked questions

How much should I charge for a DMARC audit? Published rate cards put an audit between €500 and €1,500 for two to three hours of work. The lower end is more realistic with small and mid-sized clients. Giving it away is defensible if the conversion rate stays above four in ten.

Should DMARC be billed separately or folded into the managed services retainer? Separately. A distinct line item makes the value visible. Folded into an overall retainer, the work becomes invisible and therefore free in the client's eyes.

What if the client does not control their own DNS? Settle it before signing. It is the absolute prerequisite and the first place a project overruns.

How long does a full deployment take? Eight to twelve weeks for an ordinary small business, most of which is waiting on third-party provider support desks rather than technical work.

Should I resell the tool to the client or keep it in house? Keep it as an instrument of production and bill for the engagement. Reselling the subscription puts you in a price fight over a product that is not yours.


Alignmarc produces the audit document under your brand, with no mention of our name, and tracks your client domains from a single account. See the Agency plan.

Read next