Blog · Dmarc

What the CoMIT Study Reveals About MSP Email Authentication Maturity

A study of 37,548 managed service providers found something worth sitting with: MSPs that follow the CoMIT model are measurably better at email authentication than those that do not.

The study compared MSPs using the CoMIT framework against fully-managed-only MSPs across three email authentication standards: SPF, DKIM, and DMARC. The results are not close.

CoMIT MSPs were 2.4 times more likely to have all three properly configured. Among CoMIT MSPs, 85.5% scored 5 out of 5 on email authentication setup. Among fully-managed-only MSPs, that number was 69.5%.

That 16-point gap is not a rounding error. It is a structural difference in how these two groups approach email security.

What CoMIT Means in Practice

CoMIT stands for something like a structured approach to email security maturity for MSPs. The exact specification matters less for this discussion than what it produces in practice: MSPs that follow the model systematically work through SPF, DKIM, and DMARC configuration for every customer domain, and they track ongoing compliance.

The 5/5 score in the study refers to having SPF, DKIM, and DMARC all configured and aligned for a domain. Most MSPs can get SPF and DKIM working. DMARC is where the gap opens up.

DMARC requires both technical configuration and ongoing monitoring. MSPs that skip DMARC monitoring essentially fly blind on domain abuse and authentication failures. The study's 5/5 benchmark rewards MSPs that do not skip that step.

Why Most MSPs Still Lag on Email Authentication

If 69.5% of fully-managed-only MSPs already have proper authentication setup, the picture is not entirely bleak. Most MSPs are not starting from zero.

But there is a difference between having a configuration that technically works and having one that is actively monitored and maintained.

DMARC is where maintenance matters most. Aggregate reports tell you when authentication is failing, which domains are being spoofed, and whether your third-party senders are aligned. Without a process to read those reports, MSPs typically only find out about DMARC problems when a customer calls about deliverability issues.

The gap between 69.5% and 85.5% likely reflects MSPs that have authentication configured but do not monitor it. The CoMIT framework appears to close that operational gap specifically.

What the 2.4x Figure Actually Means

The headline number is 2.4x. That is CoMIT MSPs are 2.4 times more likely to have proper SPF, DKIM, and DMARC configured.

In absolute terms, this means if you randomly selected an MSP from the fully-managed-only group and one from the CoMIT group, the CoMIT MSP is substantially more likely to have all three standards active and aligned.

For MSP owners and IT decision-makers, this is relevant in two ways.

First, if you are evaluating MSP partners or vendors, email authentication maturity is a concrete differentiator. The study gives you a benchmark to ask about.

Second, if you run an MSP, the data suggests that investing in a structured email authentication practice pays off in measurable compliance outcomes. The 85.5% figure is achievable.

How to Reach 5/5 Email Authentication as an MSP

Reaching the 5/5 benchmark the study used requires covering three areas for every customer domain you manage.

SPF configuration. Make sure every sending source is listed in the SPF record and that no record exceeds 10 DNS lookups. Flatten any lookups to include statements rather than mechanisms that cause additional lookups.

DKIM configuration. Deploy DKIM keys for every sending domain and every major email service your customers use. Rotate keys on a schedule.

DMARC configuration and monitoring. Start with p=none and move to quarantine or reject only after reviewing aggregate reports and fixing alignment issues. Do not skip the monitoring step.

The monitoring step is the one most likely to be skipped in practice. Aggregate reports are XML files that are not human-readable by default. MSPs need a way to turn those into actionable summaries. Tools like DMARCFlow handle this by processing aggregate reports and surfacing failures per domain without requiring manual XML parsing.

How DMARCFlow Fits Into This Picture

DMARCFlow is designed to handle the monitoring step specifically. It processes DMARC aggregate reports and converts them into summaries that show which domains are failing, which sources are misaligned, and which domains are being spoofed.

For MSPs that want to move from partial compliance to the 5/5 standard the study measured, the monitoring piece is not optional. The study's benchmark counted MSPs that had monitoring in place, not just configuration.

MSPs evaluating their options for DMARC monitoring can use DMARCFlow to handle multiple customer domains from a single dashboard, which maps directly to how the CoMIT framework structures email authentication as a per-domain, repeatable process.

The fit here is operational: MSPs need automated report processing to maintain 5/5 authentication across a customer base. That is what the tool does.

FAQ

What percentage of MSPs have proper SPF, DKIM, and DMARC configured?

Among fully-managed-only MSPs in the study, 69.5% had all three configured. Among CoMIT MSPs, 85.5% had all three configured. The study covered 37,548 MSPs total.

What does the 5/5 email authentication score mean?

The study scored MSPs on a 5-point scale where 5/5 means SPF, DKIM, and DMARC are all properly configured and aligned for a domain. A domain passes all three checks or it does not get the point.

Is CoMIT certification worth pursuing for an MSP?

The study suggests that MSPs following the CoMIT model have measurably better email authentication outcomes. Whether the formal certification process is worth it depends on your market positioning, but the underlying practices the model encourages are clearly associated with better results.

How does CoMIT certification affect email security outcomes?

Based on the study data, MSPs using the CoMIT model were 2.4x more likely to have proper SPF, DKIM, and DMARC configuration. That translates to fewer customer deliverability issues, less domain spoofing, and better visibility into email authentication health.