Once a PSA is connected and a customer is linked, DMARCER can keep that customer's domains in step with the assets in your PSA. Each validated domain becomes (or updates) one asset record, so your technicians can see the email-security state of every domain without leaving the PSA. This article walks you through exactly what the sync does, how to set it up on the Assets tab, what each option means, and the things to watch out for.
What asset linking does
For every domain belonging to a linked customer, DMARCER always looks for a match before it creates anything. Before it creates a new asset, it searches the asset template you have chosen, under the same client, for an existing asset whose name exactly matches the domain. If it finds one, it links to that asset (shown as "matched"). If it does not, it creates a brand-new asset (shown as "created"). Either way, DMARCER remembers the connection between the domain and the asset, so future syncs know which record to update.
- It never creates a duplicate: an existing asset is always matched and reused.
- It never deletes an asset from your PSA. If you later remove a domain from DMARCER, the PSA asset is left in place and you decide what happens to it inside the PSA.
- Only validated domains are sent across. A domain whose ownership has not yet been proven (through its _DMARCER TXT record) is never sent to a PSA, even if you ask for a full re-push.
- Every match, creation and update is recorded in the activity log, so you can see exactly what was sent and when.
Before you start
Asset linking builds on the earlier integration steps, so please make sure these are in place first.
- The PSA integration is connected and active. PSA integration is included on some plans, so if the options below are not showing, your plan may not include it yet: get in touch and we will help.
- The DMARCER customer is linked to the matching PSA customer. You do this from the Integrations page: open the integration's menu (the three-dot icon) and choose Manage customer links. A DMARCER customer can only be linked to one PSA at a time, so if you need to move it, unlink it from the other PSA first. The Customers grid and a customer's Overview tab show a chain icon when a link exists, but these are just indicators: the linking itself is always done from the integration.
- The domains you want to send are validated (ownership proven). Domains that are not yet validated are skipped.
- The asset template you want to use already exists in your PSA. If it does not, create it directly in the PSA (in HALO under Configuration then Asset Templates; in SuperOps under Settings then Assets).
Setting it up on the Assets tab
Open the Integrations page, find the PSA integration, open its menu (the three-dot icon) and choose Configure. The dialog opens on the Assets tab. Work through it from top to bottom:
- Turn on Enable Asset sync. This is the main switch: with it off, nothing is sent.
- Pick a Sync cadence. The options are Real-time (where the PSA supports it), Every 5 minutes, Every hour, Every 6 hours and Daily. Real-time does its best, but it queues changes and respects the limits your PSA sets on how often it can be contacted, so the smallest practical interval in practice is five minutes.
- Choose the Remote asset template that DMARCER domains should be sent into. If the list is empty or out of date, create the template in your PSA first, then click Reload fields.
- On Autotask only, pick a Default product. This is required: every asset DMARCER creates is tagged with it. If you would like a dedicated one, create a product or SKU in your PSA catalogue first.
- Set up the Field mapping (see the next section).
- Click Save. You will see "Configuration saved".
Mapping fields
The Field mapping table lists every DMARCER field on the left (for example Domain name, DNS provider, Expiration date, SPF status, DMARC status, DKIM status, MX status, DNSSEC, MTA-STS status, TLS-RPT status, 30-day deliverability compliance and a last-updated timestamp). For each one, choose the PSA asset field to send it into, or tick Don't sync to leave it out altogether. The badge above the table shows how many PSA fields were found for the template you chose.
- Reload fields fetches the PSA field list again for the selected template, which is handy after you have just added a field in the PSA.
- If a field is missing, the reliable way to add it is to create it in your PSA and then click Reload fields. In HALO that is Configuration then Asset Templates, then your template, then the Fields tab. There is a Create new field shortcut at the bottom of each dropdown, but it does not always succeed on every HALO setup, so adding the field in the PSA is the safer route.
- Status fields are shown using a simple red-amber-green scheme. Each protocol appears as Not Implemented, Healthy, Problems Identified or Critical Issue, matching the colour you see in Domain Management, so a technician sees the same signal in the PSA.
- If the template you chose has required fields you have not mapped, a warning banner lists them, and a Default values panel lets you set a fixed value for any field that DMARCER has no natural source for. A mapped DMARCER field always takes priority over a default.
Running a sync and what gets overwritten
You do not have to wait for the cadence. Click Sync now on the Assets tab to send every linked customer's domains straight away. By default, DMARCER only sends domains whose state has actually changed since the last successful sync, so a sync on a quiet account does little or no work and barely contacts the PSA. Tick Force re-push to send every mapped value again regardless: use this after you change the field mapping, or when something has been edited directly in the PSA and you want DMARCER's values to take over again. The validation check still applies even with Force on, so domains that are not validated are never sent.
It helps to know what a sync overwrites. On every sync, whether the asset was just matched or was already linked, DMARCER overwrites the value in every PSA field listed in your mapping with the value it works out. Fields you did not map, or marked Don't sync, are left untouched. So if you have filled in a mapped field by hand in the PSA, that value will be replaced on the next sync. After a sync, the on-screen message and the activity log tell you how many assets were created, matched, updated, unchanged and failed.
Common pitfalls
- "No customers are linked": link a DMARCER customer to its PSA customer before syncing, otherwise there is nothing to send.
- "Nothing has changed": this is normal. DMARCER skips domains that have not changed since the last sync; use Force re-push if you really do want everything sent again.
- A domain you expected is missing: this is almost always because the domain is not validated yet, or it belongs to a customer that is not linked.
- Asset creation fails on Autotask with a "required" message: the template has a required field that is neither mapped nor given a default. Map a DMARCER field to it or set a default value, then sync again. DMARCER remembers fields it finds this way and lists them for you next time you open Configure.
- Fields you maintain by hand get wiped: do not edit any PSA field by hand that you have also mapped, or set it to Don't sync if you want the PSA to own that value.
- An asset was deleted in the PSA: on the next sync DMARCER notices the linked asset has gone, clears the old link, and either re-links to another asset with the same name or creates a fresh one. There is nothing you need to do.