Domain scorecard
Sample domain · public signals only · no internal access
If I told you there was a security control that costs nothing, requires no new software, protects your clients' brand and their customers at the same time, and most small businesses still haven't turned on, you'd assume there was a catch. There isn't. It's DMARC, and the only real explanation for how rare it still is: it's nobody's job to notice it's missing.
In plain language, this is what it does. Email, as originally designed, lets anyone send a message claiming to be from anyone. Nothing in the old protocol stops a scammer from putting your client's exact domain in the from line and mailing their customers an invoice. Not a lookalike domain, the real one. DMARC, together with the two records underneath it, is how a domain tells the world's mail servers: here are the servers legitimately allowed to send as us, and here's what to do with mail that fails the check. Reject it, quarantine it, or just report it.
What that actually prevents is worth spelling out for an owner. Without enforcement, criminals can send invoices, payroll-change requests, and password resets as your client, to your client's customers and vendors, and the receiving servers have no instruction to refuse them. The client's brand becomes the attack tool, and the client finds out when an angry customer calls about a fake invoice. With enforcement at reject, that entire category of impersonation gets refused before a human ever sees it. There's a bonus, too: enforced authentication improves deliverability of the client's legitimate mail, because receiving servers trust authenticated senders more. Better security and better inbox placement, from the same DNS records.
So why is it still missing everywhere? Because free doesn't mean done. Publishing the records takes knowledge: which services legitimately send as the domain, the marketing platform, the invoicing tool, the CRM, all need to be accounted for before you enforce, or legitimate mail starts bouncing. That small amount of real work, owned by no one, is the entire barrier. It's not hard. It's just unassigned.
Which makes it a perfect first move for an MSP. The domain scan shows the status from the outside, no permissions needed, so you can walk into a first conversation already knowing. The fix is an afternoon. The client gets a visible, explainable win, their own brand, protected from impersonation, at no product cost, and you get something better than a project fee: proof, delivered in week one, that you find real things and fix them without drama.
Ten minutes to check. An afternoon to fix. Years of impersonation risk, closed. Start there.