DMARC is unusually useful for prospecting because it is public and operational
DMARC lives in DNS, so an MSP can observe whether a policy is published without credentials or an agent. More importantly, the record exposes operational posture: monitoring, enforcement and reporting configuration can each create a different discovery question.
Signal 1: no DMARC record observed
If no valid DMARC record is observed at the expected location, the domain does not expose a usable DMARC policy at that moment. That can be a qualification signal for email-authentication work, but the wording still matters. DNS failures, delegation issues or temporary resolver problems must not be converted automatically into “DMARC absent.”
Signal 2: p=none
A monitoring-only policy is not inherently “bad.” It is often a deliberate stage in a deployment. Commercially, it can indicate that the organization has started the DMARC journey but may still need reporting, source discovery, alignment work or a controlled move toward enforcement.
“You appear to be monitoring DMARC today. Do you already have ownership of aggregate reporting and an enforcement plan?” is a discovery question. “Your DMARC is insecure” is an overclaim.
Signal 3: enforcement without obvious reporting context
p=quarantine or p=reject shows a stronger receiver policy, but public DNS still does not tell you whether reporting is actively reviewed, whether all legitimate senders are aligned or whether the policy is managed internally or by a provider. This is where a service conversation can shift from implementation to management.
Signal 4: visible reporting providers
Aggregate reporting destinations can sometimes expose a DMARC-management vendor. That changes the sales motion: the opportunity may be migration, consolidation, managed operations or an adjacent service rather than basic DMARC setup.
Segment the opportunity instead of using one generic “DMARC gap”
| Observed posture | Possible discovery angle |
|---|---|
| No valid record observed | DMARC implementation and sender inventory |
p=none | Reporting, alignment and enforcement roadmap |
p=quarantine | Operational tuning and path to reject |
p=reject | Ongoing management, reporting and adjacent email security |
| Known reporting vendor | Management, consolidation or competitive displacement |
Pair DMARC with the rest of the stack
DMARC becomes more useful when combined with Workspace and email-security detection. A Microsoft 365 prospect behind Proofpoint with p=none is a different account from a Google Workspace prospect with no recognized gateway and no enforceable DMARC policy. The value comes from the combination, not from one red flag.
Turn the signal into a prospecting workflow.
SecuTest attaches public infrastructure evidence to each prospect so your team can qualify the account without turning an inference into a claim.