Every client domain at p=reject in 60 days, for a fixed price
Reject Ready is a project, not a dashboard. We inventory every legitimate sender behind a domain, fix SPF and DKIM for each one, step the DMARC policy up to reject, and then watch the domain for new or broken senders every month. If a domain isn't at p=reject after 60 days, you don't pay the project fee for it.
- Parses DMARC aggregate reports from day one and produces a named sender inventory (Microsoft 365, Google Workspace, Mailchimp, the printer in the back office) with a fix for each.
- Flattens SPF to stay under the 10-lookup limit and keeps it flat as vendors change their IP ranges.
- Moves policy from none to quarantine to reject in stages, with a weekly report of what would have been blocked at the next stage.
Most domains still aren't enforced, and the receivers have stopped being patient
DMARC has been around for over a decade, yet nearly half of company domains have no record and only a small fraction have reached p=reject, the only setting that actually stops spoofing. Publishing a record is easy; finding every system that sends mail as the domain and authenticating each one before you enforce, without breaking something, is the work.
Since 2024 the big mailbox providers have required authentication from bulk senders, and since May 2025 Microsoft rejects non-compliant bulk mail outright. For a small business that means invoices and newsletters disappearing. For an MSP it means a ticket, then a scramble, for every client, one at a time.
The market is full of DMARC dashboards that show you the reports. Reports aren't the problem. Reject Ready sells the finished outcome: the domain at p=reject, documented, with monitoring so it stays that way.
- In a 2026 study of 67,336 company domains, 45.1% had no DMARC record and only 16.3% were at p=reject. Source: ciphercue.com
- Microsoft has rejected bulk mail that fails SPF, DKIM and DMARC requirements since 5 May 2025. Source: dmarcian.com
Without it
- DMARC dashboards (EasyDMARC, Suped, DMARCwise and others): Report-parsing dashboards from about €1 to $7 per domain per month, or around $44.99 a month for a bundle. Good tools,…
- MSP white-label DMARC platforms: Platforms priced around $0.33–5 per domain per month give you a multi-tenant dashboard to do the job yourself. If you…
- Doing it in-house: Everything here is public DNS and documented standards. The cost is attention: a typical domain needs 10–30 vendor…
With Reject Ready
- Parses DMARC aggregate reports from day one and produces a named sender inventory (Microsoft 365, Google Workspace, Mailchimp, the printer in the back office) with a fix for each.
- Flattens SPF to stay under the 10-lookup limit and keeps it flat as vendors change their IP ranges.
- Moves policy from none to quarantine to reject in stages, with a weekly report of what would have been blocked at the next stage.
- Aggregate report parsing and sender inventory
- SPF flattening and lookup monitoring
How it works
- 1
Scan and scope
Send us the domains. We run a free public scan (DNS is public) and return a one-page status per domain: current SPF, DKIM and DMARC, obvious problems, and a fixed project price.
- 2
Collect reports, build the inventory (weeks 1–2)
We publish a p=none record pointing aggregate reports to us, parse them, and produce a sender inventory. You or the client confirm which sources are legitimate; everything unknown is treated as suspect.
- 3
Authenticate every sender (weeks 2–6)
For each legitimate source we supply or apply the exact DNS changes: DKIM selectors for every SaaS, SPF includes with flattening, and an authenticated relay (Microsoft 365 connector or dedicated relay) for devices and apps that can't sign. We verify each one in the reports before moving on.
- 4
Enforce and monitor (weeks 6–8 and after)
Policy moves to quarantine, then reject, with a check at each stage. After reject, monthly monitoring flags new senders and SPF drift, and you get a white-label report per client.
Features
Aggregate report parsing and sender inventory
RUA reports are collected and parsed into a list of sending sources with volume, pass/fail per mechanism and a plain-English name where we can identify the vendor.
SPF flattening and lookup monitoring
Nested includes are flattened to IPs under the 10-DNS-lookup limit and refreshed automatically when vendors change ranges. You get an alert before the record would break.
DKIM for every SaaS sender
Step-by-step instructions, or hands-on setup where you grant access, for Microsoft 365, Google Workspace, Mailchimp, HubSpot, SendGrid, Zendesk and dozens of other common senders.
Relay for devices and legacy apps
Printers, scanners, alarm panels and line-of-business apps that can't do DKIM are routed through an authenticated relay under the client's domain, so enforcement doesn't silence them.
Staged policy ramp with impact preview
Each stage (none, quarantine at a percentage, full quarantine, reject) is preceded by a report of what the next stage would block.
Monthly monitoring and alerts
After enforcement: new unauthenticated sources, failing DKIM selectors, SPF drift and record changes are flagged within 24 hours, with a monthly report.
White-label MSP reporting
Reports and the client portal carry your logo and name. Clients see their domains; you see all of them.
Hebrew and English support
Documentation, portal and support are available in English and Hebrew, for MSPs serving Israeli SMBs.
A look inside
What you see day to day: the working view and the monthly summary.
Who it's for
MSPs with 20–500 client domains
You know the clients need DMARC and you don't have the hours to do the inventory and chase vendors for each one. You get a fixed price per domain, a project you can resell, and reports with your name on them.
Microsoft 365 partners
Your clients are on M365 with a tangle of third-party senders. We handle the connectors, DKIM selectors and relay setup around your tenancy.
Small businesses whose mail is being rejected
Invoices are bouncing or landing in junk. You get the fix done for a single domain, then monitoring for a few dollars a month.
Works with
- Microsoft 365 / Exchange Online (connectors, DKIM)
- Google Workspace
- DMARC aggregate reports (RFC 7489 RUA)
- Cloudflare, GoDaddy, Route 53 and other DNS providers (records supplied, or applied via API where available)
- Mailchimp, HubSpot, SendGrid, Zendesk, Salesforce and other SaaS senders
- SPF, DKIM and DMARC; MTA-STS and BIMI readiness checks
- Authenticated SMTP relay for devices
- PDF and CSV reports; webhook alerts
Pricing
Project fees are one-time per domain and include everything needed to reach p=reject within 60 days; monthly monitoring is optional afterwards and billed per domain. Founding customer pricing: the rates below are held for 12 months for MSPs who sign during early access. If a domain is not at p=reject within 60 days because of our work, the project fee for that domain is waived (conditions in the FAQ).
Single domain
$450 one-time per domain
One business, one domain
- 60-day project to p=reject
- Sender inventory and fixes
- SPF flattening
- DKIM setup for up to 10 senders
- 3 months of monitoring included
- Then $4 per domain per month
- Email support
MSP bundle
$300 one-time per domain, 5+ domains
MSPs starting with a batch of clients
- Everything in Single domain
- Minimum 5 domains per order
- Relay setup for non-signing devices
- White-label reports and portal
- Monitoring at $3 per domain per month
- Priority support, same business day
- Hebrew or English
MSP partner
$2 per domain per month, 50+ domains
MSPs enrolling their whole client base
- Monitoring for all enrolled domains
- Projects at $250 per domain
- Free public scan of your full client list
- API and webhook alerts into your PSA
- Quarterly review call
- Co-branded sales material
- Dedicated contact
Compared with the alternatives
- DMARC dashboards (EasyDMARC, Suped, DMARCwise and others)
- Report-parsing dashboards from about €1 to $7 per domain per month, or around $44.99 a month for a bundle. Good tools, but they leave the inventory, vendor chasing and DNS work to you. We use the same reports and do the work.
- MSP white-label DMARC platforms
- Platforms priced around $0.33–5 per domain per month give you a multi-tenant dashboard to do the job yourself. If you have the engineer hours, that is cheaper; if you don't, the project is what gets domains enforced.
- Doing it in-house
- Everything here is public DNS and documented standards. The cost is attention: a typical domain needs 10–30 vendor interactions over several weeks.
- Leaving it at p=none
- A monitoring-only record satisfies some bulk-sender checklists but stops no spoofing. If the domain is used for invoices, it is the setting attackers hope for.
Your first week
We onboard new accounts within 2 business days. By day 7 you have a sender inventory for every domain in the batch.
- Day 1: Send us the domain list; receive the free scan and a fixed quote per domain.
- Day 2–3: p=none records with our reporting address go live; reports start arriving within 24–48 hours.
- Day 7: First sender inventory delivered; we walk through it with you and agree which sources are legitimate.
- Weeks 2–8: Fixes, staged ramp and enforcement, with a status report each Friday.
Security and data
- Aggregate (RUA) reports contain sending IPs and pass/fail counts, not message contents; we don't request forensic (RUF) reports unless you ask.
- Report data and inventories are stored encrypted at rest; access is limited to the engineers assigned to your account and logged.
- Any delegated access to DNS or Microsoft 365 is through roles you grant and can revoke; we never ask for passwords.
- Data is retained while monitoring is active plus 90 days, exportable as CSV, and deleted on written request.
Questions
What exactly does the 60-day guarantee cover?
If we can't get a domain to p=reject within 60 days of starting because of our work, you don't pay the project fee for that domain and we keep working. It assumes the DNS changes we request are applied within 5 business days and the client confirms its legitimate senders.
Will enforcement break our clients' email?
Not if the inventory is complete, which is the point of the staged ramp. Each stage comes with a preview of what the next one would block. Unknown senders that turn out to be legitimate are caught at quarantine, not reject.
Do you need access to our DNS and Microsoft 365?
No. We can supply the exact records and instructions and verify through the reports; many MSPs prefer to apply changes themselves. If you'd rather we do it, we work with delegated access that you can revoke at any time.
What about vendors that don't support DKIM?
They are either moved behind the authenticated relay or sent from a subdomain with its own policy. Each case is documented in the inventory with the chosen approach.
Is monitoring required after the project?
No. The domain stays at p=reject without us. We recommend monitoring because new SaaS tools get added and vendors change IPs; most MSPs fold the few dollars into their client's plan.
Do you handle BIMI or MTA-STS?
We check readiness and advise. Setting up a Verified Mark Certificate for BIMI involves a third-party cost and a registered trademark, so it is quoted separately if wanted.
Ready when you are
Tell us about your setup. We confirm by email and get you running within 2 business days.
Request service