Built for MSPs, not enterprises
See every client's attack surface.
Before someone else does.
Marchpost scans every domain you manage from the outside — email authentication, certificates, DNS, website hardening — and tells you the moment something breaks. Then it hands you the branded report your client actually reads.
- No agent to install. No admin consent. Paste a domain, get answers in 30 seconds.
- One dashboard for your whole book of business, ranked by what needs attention.
- White-label reports for QBRs — and free branded reports to win new logos.
Free plan includes unlimited prospect scans. One paid plan, $99/month, everything included.
Try it on a real domain
Scan any domain — a client's, a prospect's, or your own. No signup, no email required, and a full report in about 30 seconds. Unverified domains get passive checks only: public DNS, one TLS handshake, and the site's own pages.
30s
to first report
40+
checks per domain
0
agents to install
You already know this is your blind spot
Your RMM watches the endpoints. Your EDR watches the processes. Other tools can check parts of the external surface too — but almost none of them watch every client you manage, tell you what changed, and hand you something the client can read. That is the part a marketing agency edits without telling you, the part where a certificate quietly expires on a Saturday, and the part an attacker looks at first.
The Monday morning problem
A client's certificate expired over the weekend. You found out because they called. It was on a subdomain nobody remembered existed.
The renewal problem
Twelve months of quiet, competent security work, and nothing to show for it at the renewal meeting. Invisible work is unbillable work.
The pipeline problem
Cold outreach to a 30-seat business goes nowhere. A specific, accurate report about their actual domain gets you a meeting.
Three jobs, one subscription
Open sales conversations
Run a scan on a prospect's domain before the first call. Bring a branded report showing exactly what is exposed, in language their owner understands. It is the most concrete thing anyone will put in front of them all quarter.
How MSPs use it to prospect →Catch changes the day they happen
Every monitored domain is rescanned on your schedule. When a certificate is about to expire, a DMARC policy is weakened, or a subdomain starts pointing at a decommissioned service, you get an alert — not a phone call from the client.
What we monitor →Make your work visible at renewal
On the first of every month, Marchpost generates a report for each client under your own logo and colours. Score, what changed, what you fixed, what is left. Attach it to the QBR and the renewal conversation answers itself.
See a sample report →What every scan looks at
Findings are graded by a fixed, published ruleset — never by an AI guessing at a number. The same configuration always produces the same score, so when you tell a client their score went up, it actually means something.
How scoring works →Email authentication
30%- —SPF syntax, duplicates, and the 10-lookup limit
- —DMARC policy, enforcement percentage, reporting
- —DKIM keys across 20 platform selectors
- —MTA-STS and TLS-RPT
Certificates & encryption
25%- —Expiry, with escalating urgency inside 30 days
- —Chain trust and hostname coverage
- —Obsolete TLS 1.0 / 1.1 still accepted
- —HTTP to HTTPS redirection
Website hardening
20%- —HSTS, CSP, referrer and MIME-sniffing policy
- —Clickjacking protection
- —Cookie Secure / HttpOnly flags
- —Server version disclosure
DNS & domain
15%- —DNSSEC signing
- —Nameserver redundancy
- —CAA certificate-issuance restrictions
- —Dangling records that allow subdomain takeover
Set up in one sitting
There is nothing to deploy. The longest part is pasting your client list.
-
01
Paste your domains
One per line, or bulk-import a CSV. Group them under clients as you go.
-
02
First scans run
Every domain is scanned within a couple of minutes. Your portfolio fills in, ranked worst-first.
-
03
Fix the red ones
Every finding says what is wrong, why it matters to a non-technical owner, and the exact fix.
-
04
Reports go out monthly
On the 1st, a branded report is generated for each client. You review and send.
What Marchpost is not
We would rather you know before you sign up. Marchpost is an external, passive view of your clients' internet-facing configuration.
- ✕Not a penetration test. We never attempt to exploit anything, log in, or send traffic designed to break something.
- ✕Not an internal network scanner. If it is behind the firewall, we cannot see it, and neither can an attacker on the open internet.
- ✕Not an EDR or a SIEM. It replaces nothing in your stack. Several other products check parts of this surface; what we do differently is watch it across your whole client book, alert on change rather than state, and produce a report a business owner can read.
Who is behind this
Marchpost is built and run by an operator with a background in managed IT services, Linux and AWS infrastructure, hosting, DNS and security — the same work you do. The checks in this product exist because they are the ones that actually cause Monday morning phone calls.
It is a small, independent company. That means you get direct answers from someone who understands your business, and it means we publish exactly what our scanner does.
Scan one client. See what the outside world sees.
Start with the client you are most confident about. Sometimes the result is clean — we report that as clean, and say so plainly.