Marchpost
Menu

Built for MSPs, not enterprises

See every client's attack surface.
Before someone else does.

Marchpost scans every domain you manage from the outside — email authentication, certificates, DNS, website hardening — and tells you the moment something breaks. Then it hands you the branded report your client actually reads.

  • No agent to install. No admin consent. Paste a domain, get answers in 30 seconds.
  • One dashboard for your whole book of business, ranked by what needs attention.
  • White-label reports for QBRs — and free branded reports to win new logos.

Free plan includes unlimited prospect scans. One paid plan, $99/month, everything included.

Try it on a real domain

Scan any domain — a client's, a prospect's, or your own. No signup, no email required, and a full report in about 30 seconds. Unverified domains get passive checks only: public DNS, one TLS handshake, and the site's own pages.

We only check what any visitor can see — DNS, certificates, headers. Nothing intrusive.

30s

to first report

40+

checks per domain

0

agents to install

You already know this is your blind spot

Your RMM watches the endpoints. Your EDR watches the processes. Other tools can check parts of the external surface too — but almost none of them watch every client you manage, tell you what changed, and hand you something the client can read. That is the part a marketing agency edits without telling you, the part where a certificate quietly expires on a Saturday, and the part an attacker looks at first.

The Monday morning problem

A client's certificate expired over the weekend. You found out because they called. It was on a subdomain nobody remembered existed.

The renewal problem

Twelve months of quiet, competent security work, and nothing to show for it at the renewal meeting. Invisible work is unbillable work.

The pipeline problem

Cold outreach to a 30-seat business goes nowhere. A specific, accurate report about their actual domain gets you a meeting.

Three jobs, one subscription

WIN

Open sales conversations

Run a scan on a prospect's domain before the first call. Bring a branded report showing exactly what is exposed, in language their owner understands. It is the most concrete thing anyone will put in front of them all quarter.

How MSPs use it to prospect →
WATCH

Catch changes the day they happen

Every monitored domain is rescanned on your schedule. When a certificate is about to expire, a DMARC policy is weakened, or a subdomain starts pointing at a decommissioned service, you get an alert — not a phone call from the client.

What we monitor →
PROVE

Make your work visible at renewal

On the first of every month, Marchpost generates a report for each client under your own logo and colours. Score, what changed, what you fixed, what is left. Attach it to the QBR and the renewal conversation answers itself.

See a sample report →

What every scan looks at

Findings are graded by a fixed, published ruleset — never by an AI guessing at a number. The same configuration always produces the same score, so when you tell a client their score went up, it actually means something.

How scoring works →

Email authentication

30%
  • SPF syntax, duplicates, and the 10-lookup limit
  • DMARC policy, enforcement percentage, reporting
  • DKIM keys across 20 platform selectors
  • MTA-STS and TLS-RPT

Certificates & encryption

25%
  • Expiry, with escalating urgency inside 30 days
  • Chain trust and hostname coverage
  • Obsolete TLS 1.0 / 1.1 still accepted
  • HTTP to HTTPS redirection

Website hardening

20%
  • HSTS, CSP, referrer and MIME-sniffing policy
  • Clickjacking protection
  • Cookie Secure / HttpOnly flags
  • Server version disclosure

DNS & domain

15%
  • DNSSEC signing
  • Nameserver redundancy
  • CAA certificate-issuance restrictions
  • Dangling records that allow subdomain takeover

Set up in one sitting

There is nothing to deploy. The longest part is pasting your client list.

  1. 01

    Paste your domains

    One per line, or bulk-import a CSV. Group them under clients as you go.

  2. 02

    First scans run

    Every domain is scanned within a couple of minutes. Your portfolio fills in, ranked worst-first.

  3. 03

    Fix the red ones

    Every finding says what is wrong, why it matters to a non-technical owner, and the exact fix.

  4. 04

    Reports go out monthly

    On the 1st, a branded report is generated for each client. You review and send.

What Marchpost is not

We would rather you know before you sign up. Marchpost is an external, passive view of your clients' internet-facing configuration.

  • Not a penetration test. We never attempt to exploit anything, log in, or send traffic designed to break something.
  • Not an internal network scanner. If it is behind the firewall, we cannot see it, and neither can an attacker on the open internet.
  • Not an EDR or a SIEM. It replaces nothing in your stack. Several other products check parts of this surface; what we do differently is watch it across your whole client book, alert on change rather than state, and produce a report a business owner can read.

Who is behind this

Marchpost is built and run by an operator with a background in managed IT services, Linux and AWS infrastructure, hosting, DNS and security — the same work you do. The checks in this product exist because they are the ones that actually cause Monday morning phone calls.

It is a small, independent company. That means you get direct answers from someone who understands your business, and it means we publish exactly what our scanner does.

Scan one client. See what the outside world sees.

Start with the client you are most confident about. Sometimes the result is clean — we report that as clean, and say so plainly.