A WHMCS DMARC add-on is a module that lets a hosting provider sell managed DMARC (Domain-based Message Authentication, Reporting and Conformance) monitoring and enforcement directly through the billing system it already runs. PowerDMARC is currently the only vendor shipping a native WHMCS module with reseller pricing built in. Every other serious vendor in this space, including EasyDMARC, dmarcian, Valimail and Red Sift OnDMARC, runs its own partner or MSP (managed service provider) programme instead, which means manual provisioning outside your billing panel.
I get the same support ticket three or four times a month now. A small business customer's newsletter or invoice emails start landing in spam, or bouncing outright, and the first question is always "can you fix this". Since Google and Yahoo started enforcing authentication rules for bulk senders, this stopped being a niche technical request and became a standard line item customers expect their host to sell. Most hosts still have nothing to offer beyond "add an SPF record and hope."
What does a customer actually need for email authentication?
A customer needs three things working together, not just one DNS record. They need SPF, DKIM, and a DMARC policy that starts loose and tightens over weeks, plus someone actually reading the reports it generates.
SPF (Sender Policy Framework) is a DNS record that lists which mail servers are allowed to send email for a domain. DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing mail so the receiving server can confirm it wasn't altered in transit. DMARC then tells receiving mail servers what to do when a message fails either check, and it publishes reports back to the domain owner about who is sending mail using their name.
The policy itself moves through stages. You start at p=none, which just monitors and reports without blocking anything. Once the reports show legitimate mail passing cleanly, you move to p=quarantine and eventually p=reject, which actually blocks spoofed mail. Most customers never get past p=none because nobody is reading the reports. They arrive as raw XML files that need parsing software to make any sense of, and that parsing is the actual product you are selling, not the DNS record itself.
Google's own guidance for bulk senders and Yahoo's sender requirements both spell out the same baseline: valid SPF or DKIM, a DMARC record in place, and low spam complaint rates. Neither company cares how you get there. Check current DNS status for any domain using our own DMARC checker, SPF checker and DKIM checker before you even open a support ticket about it.
Do cPanel and Plesk already handle DMARC for free?
Partly. Both panels generate SPF and DKIM records automatically when you create an email account, but neither does DMARC report parsing. That gap is exactly what you're being asked to sell.
cPanel's Email Deliverability tool checks whether SPF and DKIM records exist and match what the server expects, flagging anything missing in red. Plesk does something similar through its Mail settings. Both will happily publish a basic DMARC TXT record at p=none if you ask, or in some configurations by default.
Neither panel does anything with the aggregate and forensic reports that DMARC generates once it's live. Those reports arrive daily by email as compressed XML attachments, addressed to whatever reporting address you specified in the record. Nobody reads them manually, and without software to parse them, the customer has no visibility into who is actually sending mail as their domain. Which means nobody ever moves the policy from monitoring mode to actual enforcement.
That's the entire commercial opportunity in one sentence: cPanel and Plesk get a customer to p=none for free, and someone needs to get them the rest of the way to p=reject with actual enforcement. That someone can be you, or it can be whichever vendor the customer finds on Google after their newsletter starts bouncing.
Which vendors run a DMARC reseller or MSP programme?
Five vendors dominate this space for hosting providers and MSPs: PowerDMARC, EasyDMARC, dmarcian, Valimail and Red Sift OnDMARC. Only one of them, PowerDMARC, ships a module that plugs directly into WHMCS.
PowerDMARC built its business around channel partners from the start, with over 700 partners and a genuine free tier alongside pay-as-you-go pricing that scales with domain count. EasyDMARC targets MSPs specifically, with a dedicated console and native integrations for ConnectWise, HaloPSA and Autotask, the three PSA (professional services automation) tools most MSPs already run their tickets through, plus white-label PDF reports you can put your own logo on.
dmarcian has a different pitch entirely: it was founded by one of the people who co-authored the DMARC specification, which carries weight with technically minded customers who want to buy from the source rather than a reseller layer. Valimail offers a genuinely free Monitor tier, but its paid Enforce product jumps straight to enterprise pricing, and it isn't built as a reseller product at all. Red Sift OnDMARC is a UK vendor with entry pricing aimed at direct business customers rather than hosting resellers.
Which vendor actually integrates with WHMCS?
PowerDMARC is the answer, and it's not close. It's the only one of the five with a WHMCS module you can install, configure and start billing through without building custom middleware yourself.
That matters more than it sounds. Every other vendor requires you to provision the customer's domain in a separate portal, then manually keep your WHMCS invoice and their vendor subscription in sync. Fine for five customers. It falls apart at fifty, when someone forgets to cancel a vendor seat after a customer churns and you're left paying for accounts nobody uses.
A native module means provisioning, billing and cancellation all happen in one place, which is the entire point of running WHMCS as your hosting business's backbone in the first place. If you're set up around EasyDMARC, dmarcian, Valimail or Red Sift instead, you're not wrong to use them, but budget time for manual reconciliation or build a lightweight API bridge, because WHMCS won't do it for you out of the box.
| Vendor | WHMCS module | White label | Entry price | Pricing basis | Who it suits |
|---|---|---|---|---|---|
| PowerDMARC | Yes, native module | Yes | Free tier, then pay-as-you-go | Per domain | Hosts wanting billing built directly into WHMCS |
| EasyDMARC | No | Yes, white-label PDF reports | Around $36/month for 2 domains (Plus) | Per domain | MSPs already on ConnectWise, HaloPSA or Autotask |
| dmarcian | No | Not marketed as a reseller product | Around $24/month (Basic) | Per sending source | Technical customers who want the spec authors' tool |
| Valimail | No | No | Free (Monitor), Enforce from around $5,000/year | Per domain, enterprise tiers | Large enterprise customers, not typical resale |
| Red Sift OnDMARC | No | No | From around $35/month annual (Basic) | Per domain | UK businesses buying direct rather than through a host |
How much should you charge for managed DMARC?
Most hosts I've worked with land somewhere between $3 and $10 a month per domain for managed DMARC, depending on whether it includes active report reading and policy progression or just record generation.
The lower end suits a largely automated offering, where the underlying vendor tool does the parsing and you charge a margin on top of the wholesale cost. The higher end applies when you're actually reviewing reports monthly and manually advancing the policy from p=none towards p=reject, which is real work even with good tooling, because forensic reports still need a human to interpret unusual senders.
Don't undercharge this just because the underlying vendor cost looks small. The value isn't the DNS record, it's the fact that the customer's invoices and marketing emails keep landing in the inbox instead of spam, which for a small business is directly tied to revenue. Price it like the business continuity service it actually is.
Should DMARC be bundled or sold as a standalone SKU?
Bundle it. A standalone DMARC line item converts poorly because customers don't understand what they're buying until something has already gone wrong.
Fold managed DMARC into a business email plan and the conversation changes entirely. Instead of pitching an unfamiliar acronym, you're selling "professional email that reliably reaches the inbox," a benefit every business owner understands immediately. The DMARC piece becomes a feature of the plan rather than a separate decision they have to research and justify.
This also solves your churn problem. A standalone DMARC add-on gets cancelled the moment a customer's accountant asks what it does. Bundled into email hosting, it just sits there quietly protecting deliverability, and nobody questions a line item they've stopped noticing.
- Standalone SKU: requires the customer to understand DMARC before buying, which most won't, so conversion stays low.
- Bundled into business email: sold as inbox deliverability, a benefit that needs no explanation, and it rides along with a plan customers already value.
- Bundled into a security add-on: works well if you already sell SSL, malware scanning or backups as a package, since DMARC fits the same "we handle the boring stuff" positioning.
What's the actual implementation checklist for WHMCS?
Adding this to WHMCS takes an afternoon if you use PowerDMARC's module, or a few days of custom work if you're building around another vendor manually. Either way, the steps are the same.
Decide your provisioning model before you touch WHMCS itself. Will every domain get its own DMARC record and reporting mailbox, or will you consolidate reporting for all customers through a single aggregator address? That decision affects how the module needs to be configured, so get it right before installation, not after your first ten customers sign up.
- Install and license the module against your existing WHMCS installation, following the vendor's provisioning API documentation exactly, since DNS record creation is where most integrations break.
- Create a distinct product in WHMCS rather than a configurable option buried inside hosting, so it shows up cleanly on invoices and in your reporting.
- Set up automated onboarding emails that explain the p=none to p=reject journey in plain terms, since customers who understand the timeline are far less likely to cancel mid-way.
- Build a monthly review process for accounts still stuck at p=none after 60 days, because those are the ones generating support tickets later.
- Test cancellation flow end to end so a customer offboarding also removes the DMARC record cleanly, rather than leaving orphaned DNS entries behind.
Once it's live, add it to your onboarding checklist for every new business email customer by default, rather than waiting for them to ask. Most never will, until the day their invoices bounce.
What is white-label DMARC and why do MSPs specifically want it?
White-label DMARC means the reporting dashboard, PDF summaries and customer-facing communication carry your brand, not the underlying vendor's. MSPs care because their entire value proposition is being the single point of contact, and a vendor logo on a report undermines that.
EasyDMARC leans hardest into this, with dedicated white-label PDF reports built for exactly this use case, alongside its PSA integrations for ConnectWise, HaloPSA and Autotask, so tickets and alerts flow into tools MSPs already monitor daily. That combination matters more to an MSP managing forty client domains across different companies than it does to a hosting company selling the same product to its own direct customers.
If you're a pure hosting provider selling to your own customer base, white labelling matters less, since the customer already trusts your brand for hosting and email. If you're an MSP layering DMARC on top of managed IT services for clients who also use other providers, white labelling is close to non-negotiable, because your brand is the entire relationship.
What are the risks of getting this wrong?
The biggest risk isn't a failed DNS record, it's rushing a customer straight to p=reject before their legitimate senders are properly identified. That blocks their own marketing platform or CRM's mail alongside anything malicious.
This is why the monitoring stage at p=none matters so much, and why report parsing is the real service rather than an afterthought. A small e-commerce customer might have their storefront platform, an email marketing tool and an invoicing system all sending mail on their behalf. Move to enforcement too fast and you've just broken their order confirmation emails.
Set expectations early that the journey from monitoring to full enforcement takes weeks, not days, and that this is deliberate rather than slow service on your part. Reference the DMARC.org specification body if a technical customer wants to understand the standard itself, and lean on your own DMARC checker to show them progress in a format simpler than raw XML reports.
Recommendations
Three things I'd tell any host reading this before they build anything.
- If you want native WHMCS billing without custom middleware, install PowerDMARC's module first and evaluate the free tier before committing budget.
- Price managed DMARC between $3 and $10 a month per domain, bundled into your business email plan rather than sold as a standalone item, because bundled offerings convert and retain far better.
- Build the report-reading process before you sell a single seat. The DNS record is free with cPanel or Plesk; the parsing and policy progression is what customers are actually paying you for.
Frequently Asked Questions
Is there a free WHMCS DMARC module?
PowerDMARC offers a free tier that works through its WHMCS module, covering basic monitoring for a limited number of domains. It's a reasonable way to test the workflow before committing to paid pricing across your customer base. See our PowerDMARC profile for current tier details.
Do I need DMARC if I already have SPF and DKIM set up?
Yes. SPF and DKIM check individual messages, but DMARC tells receiving servers what to do when those checks fail and reports back who's sending mail as your domain. Without it, you have authentication with no enforcement and no visibility.
Can I just tell customers to use cPanel's built-in DMARC record?
You can, but it only gets them to p=none, monitoring mode with no enforcement. Nobody at the customer end will read the resulting XML reports, so the policy never advances and inbox placement issues persist. That report-reading step is the actual product to sell.
Which vendor is cheapest for a small hosting company just starting out?
PowerDMARC's free tier and pay-as-you-go pricing suit a small host testing the market with a handful of domains before scaling. dmarcian's Basic tier, around $24 a month, is also accessible if you prefer per-sending-source pricing.
Is Valimail or Red Sift OnDMARC worth considering for a hosting reseller programme?
Not really. Neither is built as a reseller product; Valimail's Enforce tier jumps to enterprise pricing and Red Sift OnDMARC targets direct business buyers rather than hosts. They're better suited to enterprises buying directly than to a hosting company reselling at scale.
The bottom line
DMARC stopped being optional the moment Google and Yahoo started enforcing bulk sender rules, and customers now expect their host to have an answer ready. PowerDMARC is the only vendor that plugs cleanly into WHMCS today, which makes it the sensible default unless you've already committed to an MSP stack built around EasyDMARC's PSA integrations. Bundle it into email hosting, price it properly, and read the reports you're charging for.
Follow HostList for new rankings, original research, and changes across the hosting industry.



