Managing multiple clients (tenants)

How to look after several clients from one DMARCER account: creating customers, assigning their domains, filtering and sorting the grid, managing portal access, and offboarding cleanly when an engagement ends.

Published 22 Jul 2026 2

DMARCER is built so you can look after lots of clients from a single account. Each client is its own customer (sometimes called a tenant): a tidy container for that client's domains, reports, security figures and portal settings. Whether you are an MSP caring for dozens of clients or a single business with several brands, customers keep everything neatly separated and let you see how each client's email security is doing at a glance.

What the Customers area gives you

The Customers page is a sortable grid with one row per customer. Each row sums up that customer's domains, so you can compare clients without opening them one at a time. The columns are:

  • Customer: the name, with a small chain icon if the customer is linked to one or more PSA systems.
  • Domains, Standard, Parked and Unvalidated: the domain counts, split by type. Standard domains send live mail; Parked domains do not send mail; Unvalidated domains have not yet had their ownership confirmed with a TXT record.
  • Quiet: validated Standard domains that have not sent through any DMARC aggregate reports within your quiet window (14 days by default). Brand-new domains (under 7 days old) and Parked domains are left out.
  • Portal: whether the client portal is On, Paused or Off for this customer.
  • SPF, Full DMARC, DKIM, DNSSEC and MTA-STS: the percentage of the customer's domains that pass each check. Full DMARC means a domain is set to the strictest DMARC policy (p=reject) and is reporting back to DMARCER.
  • 90d compliance: DMARC compliance over the last 90 days, based on the volume of messages reported.
  • Security Score and Status: the customer's average Domain Security Score across all their domains, and whether the customer is Active, Inactive or Offboarded.

One thing worth knowing: all of the percentages above are worked out from validated domains only. Unvalidated domains cannot show a meaningful figure (their ownership has not been proven yet), so they are left out of the percentages, and you will see a dash when a customer has no validated domains so far.

Creating a customer

To add a client, open the Customers page and select Add Customer at the top of the grid. Enter a Customer name and select Add. The name needs to be unique within your account: if a customer with the same name already exists, DMARCER will let you know rather than create a duplicate. You can fill in contact details and notes later from the customer's Overview tab.

You can also create a customer on the spot while assigning a domain, without leaving the assignment window. Either way, the customer starts out Active and empty until you assign domains to it.

Assigning domains to a customer

A customer only really comes to life once it has domains. There are two ways to assign them:

  • When adding a domain: choose the customer (and region) at the moment you add the domain, so it lands in the right place straight away.
  • From Domain Management: use the assign-customer action on a single domain, or select several domains and assign them together. Choosing the empty (Unassigned) value detaches a domain from its customer.

Every assignment change is recorded in the audit log, so you can always see when a domain moved between customers and who moved it. Assigning domains needs the relevant permission, so if you cannot see the option, just ask whoever administers your account.

Finding clients quickly with filters

The sidebar on the Customers page lets you build your own filters. Use the Search box to match by name, or create a filter by picking a field, choosing a value and selecting Add filter. Each active filter shows up as a little chip you can remove, and you can clear them all in one go. Handy filters include:

  • Portal access, Customer status and Domain mix (for example, customers with unvalidated domains, or none validated at all).
  • DNS integration, to find customers that do or do not have a linked DNS provider.
  • SPF, Full DMARC, DKIM, DNSSEC and MTA-STS, each grouped into All passing, Some concern, Critical or No data.
  • Blacklist hits and Quiet domains, to bring clients that need attention to the surface.

By default the Customer status filter is set to Live, which shows active and inactive customers but hides offboarded ones. Choose Offboarded (or All) when you need to find a client you have already exited. Click any column header to sort, and customers with no data for that column always drop to the bottom.

Inside a customer: the detail tabs

Selecting a customer name opens its detail page, arranged into tabs:

  • Overview: the customer's contact details (Contact, Email, Phone, Website, Notes), key figures, and the management buttons. Select Edit to update the contact details.
  • Domains: that customer's domains, shown from Domain Management.
  • Stats: compliance and volume trends for the customer, with an optional breakdown by country.
  • Enforcement, Blacklist and Brand Watch: each of these pages, focused on just this customer.
  • Portal: the client-portal settings and portal users for this customer.

From the Overview tab you can also Deactivate or Activate a customer. Deactivating is a gentle step: it hides the customer from the assignment dropdowns but leaves all domains and services running. You can undo it at any time, and it is not the same as offboarding.

Controlling client portal access

The Portal tab controls whether the client can sign in to their own portal. There are two switches: whether the portal is turned on at all, and whether it is currently active. A portal that is turned on but not active shows as Paused in the grid, which is a handy way to switch a client's access off for a while without removing their setup.

You can also set limits and choose what the client sees: Max Standard domains and Max Parked domains, the guidance mode, Brand Watch visibility, and per-feature toggles (My Domains, Reports, Alerts, SPF, DMARC, DKIM, DNSSEC and MTA-STS). Each feature toggle can Inherit your account default or be set to On or Off for this one customer, so you can tailor the portal for each client without changing your overall defaults.

Offboarding a customer

When an engagement ends, use Offboard (on the customer's Overview tab) rather than simply deactivating. Offboarding starts by showing you a summary of the impact, so you can see exactly what will happen to each domain, how many portal users will be switched off, and whether any PSA links will be left out of date. For every active domain you choose what should happen to it:

  • Remove: takes the domain down. Hosted MTA-STS is stopped, SPF is put back to its standard form (undoing the flattening we apply to keep within SPF's lookup limit), any DNS integration link is cleared and DKIM monitoring stops. Reporting stops too, although the data already gathered is kept.
  • Move: hands the domain over to another active customer in your account, so it carries on running under its new owner.

To confirm, you type OFFBOARD, and you can note a reason if you like. Once confirmed, the customer is marked Offboarded and set to inactive, and all of its portal users are switched off. Offboarded customers stay in the grid for your records but are hidden by the default Live filter.

If you ever need a customer back, use Reactivate. It is worth knowing what this does and does not do: it brings the customer back online and returns it to the dropdowns, but it does NOT restore domains that were removed during offboarding, and it does NOT switch the portal users back on for you. You would re-add those domains and re-invite the users as needed. This is on purpose, so reactivation never quietly republishes DNS you expected to be gone.

Common pitfalls

  • A dash in a posture column means there is no data yet (no validated domains for that customer), not zero per cent. Confirm domain ownership before expecting the figures to appear.
  • Unvalidated domains are left out of every posture percentage, so a customer can look incomplete simply because its domains have not been validated yet.
  • Deactivate can be undone and leaves services running; Offboard is the deliberate, recorded exit that takes things down. Try not to use Deactivate when you really mean to fully exit a client.
  • You cannot switch an offboarded customer back on with the Activate button; you need to use Reactivate, and removed domains and portal users will not come back on their own.
  • Customer names must be unique, so if an Add is rejected it usually means that name is already in use.
  • A Quiet count is a nudge to look into something, not always a fault: check whether the reporting address changed, the upstream sender stopped, or the quiet spell is simply seasonal.

Was this article useful?

Be the first to vote.
Got feedback for our team? Send us a comment

Related articles