MX AuditGuides

A repeatable client-portfolio audit for MSPs

Turn an email-domain portfolio into a ranked remediation queue.

A useful MSP audit is not a screenshot of one DMARC record. It is a repeatable evidence pack that shows which client domains need action, what can be proved from public DNS, what still needs message-level verification, and what the team should fix first.

Reviewed: July 21, 2026 · Primary sources below

01

Confirm authority and define the portfolio

Audit only domains the client owns or has authorised the MSP to assess. Record the domain list, business owner, mail platform, known sending services, and whether each domain sends mail, receives mail, or is intentionally parked.

02

Capture one comparable public-DNS baseline

Collect MX, SPF, DMARC, aggregate-reporting, MTA-STS, and TLS-RPT evidence consistently across every domain. Preserve the exact records and lookup failures so the next review can distinguish a configuration change from a temporary DNS error.

03

Separate record presence from real authentication

An SPF or DMARC record can be syntactically present while legitimate mail still fails alignment. Public DNS also cannot discover every DKIM selector. Mark those limits explicitly instead of turning unknown evidence into a pass.

04

Verify active senders with headers and reports

Use recent received-message headers to confirm the envelope sender, DKIM signing domain and selector, visible From domain, and DMARC result. Use aggregate reports to map volume and alignment across the complete sender inventory before recommending enforcement.

05

Rank the queue by operational risk

Put missing DMARC, broken SPF evaluation, unknown high-volume senders, and failed alignment ahead of cosmetic improvements. Keep parked domains, production domains, and delegated marketing subdomains in separate workstreams because their safe end states differ.

06

Deliver a client-ready action package

Give the client an executive summary, one evidence-backed action sheet per domain, a named remediation owner, and the next verification step. Microsoft and Google both recommend gradual DMARC rollout: observe first, correct legitimate failures, then move toward quarantine or reject.

Free MSP portfolio preflight

Find the client domains that need action first.

Compare up to 10 authorised domains in one browser session and download a ranked CSV. If one domain has an active authentication problem, the Fix Sprint provides exact provider-specific changes and post-change verification. MX Audit does not receive or store the scanned domain list.

Audit up to 10 domains free

Important

Do not sell a DNS-only score as proof of delivery or alignment.

Authentication is evaluated on real messages. Public DNS can reveal important configuration evidence, but it cannot prove every active sender, DKIM selector, alignment result, reputation signal, or receiver decision. Never promise inbox placement, and never move a production domain to enforcement without a complete sender inventory and representative report evidence.

If you need continuous monitoring

See who really sends in your name.

DMARCTrust is an external platform for DMARC reports, alerts, and sender inventory. Its free evaluation tier is limited to one domain; paid business plans start at $19/month for two domains. The MX Audit score remains independent.

Business plans from $19/mo · free evaluation · no cardTest monitoring free Not a partner link yet: MX Audit currently receives no compensation.
Common questions
What can an email authentication audit prove?

It can document public MX, SPF, DMARC, reporting, and transport-policy evidence and identify concrete gaps. With buyer-supplied headers or known selectors, it can also verify specific DKIM and alignment evidence. It cannot guarantee inbox placement or enumerate every sender from DNS alone.

Does the audit require mailbox or DNS credentials?

No. The baseline uses public DNS and optional redacted message headers. DNS implementation is a separate change-controlled activity and should use the client's normal privileged-access process.

How should an MSP prioritize multiple client domains?

Start with domains that actively send mail and have missing DMARC, broken SPF evaluation, failed alignment, or unknown high-volume sources. Then address monitoring-only policy, transport signals, and intentionally non-sending domains according to their documented role.

What is included in the paid Fix Sprint?

The USD 99 founding offer covers one authorised business domain and up to three legitimate sending services for buyers outside Switzerland. It includes exact provider-specific SPF, DKIM and DMARC changes, one post-change verification and one correction round. Simple domains that already pass authentication should use the free tools instead.

Primary sources