For managed service providers

Email security built around how MSPs actually operate.

Protect every customer domain, manage tenants from one platform, and avoid the cost and complexity of per-user licensing.

Up to 250 mailboxes per domain. Per-domain pricing. Clear filtering decisions.

Designed for MSPs That Want Predictable Control

  • Protect domains without mailbox-count surprises
  • Manage customer environments centrally
  • Review why individual messages were classified the way they were
  • Introduce enforcement gradually with Monitor Mode
  • Turn optional services on per domain

Per-domain instead of per-user

A customer growing from 20 mailboxes to 60 changes your cost with per-user licensing. It does not change it here: MailThreatZero pricing is based on protected domains rather than charging separately for every mailbox.

The arithmetic

Work it out with your own numbers rather than ours:

  • Per-user model: mailboxes across all customers × monthly per-user price
  • MailThreatZero: protected domains × the domain rate for your volume tier

Our rates are published in full on the pricing page, and the calculator there runs the comparison against figures you enter.

Partners start at $39 per protected domain. The rate falls to $37 at 40 domains and $35 at 100 domains. A direct organization pays $39 per protected domain, so the volume tiers create the partner margin.

Your margin is yours

Partners set their own resale price. We bill you by protected domain rather than by mailbox, so your cost stays flat as a customer hires people — and whatever you charge above it stays yours.

We publish no required or recommended resale price. What a managed security line item is worth depends on what you wrap around it, and that is your call rather than ours.

Why it matters for packaging

  • A fixed per-domain input makes a managed security line item easy to price
  • A customer’s headcount changes do not reopen your margin
  • Volume tiers reward portfolio growth rather than penalizing it
  • Month to month, with no setup fee, so a pilot customer is not a commitment

Every tenant in one console

Multi-tenant administration and role-based access are standard rather than an upsell tier.

Multi-tenant dashboard

One sign-in across every customer you manage. Domains, filtering policy, quarantine and reporting for all of them from the same place, with each tenant’s data scoped to them.

Customer and domain onboarding

A wizard for the domain, its destination and its mail platform, which generates that domain’s platform-side configuration with copy-ready settings. Mailboxes and mail platform stay exactly where they are.

Policy per domain

Thresholds, which engines run, geographic rules, allow and deny lists, advanced content filters and retention are all set per domain, so one customer’s tuning never becomes another’s.

Roles

Platform administrator, tenant (owns domains), domain administrator and read-only user, with TOTP two-factor available on any administrative account.

Delegated customer access

Hand a customer a domain-administrator account scoped to their own domain, so they can review their own quarantine without seeing anyone else’s.

Portfolio health triage

Customers ranked worst-first, every row opening to the findings behind it: DNS results, connector status, quarantine backlog, administrators without two-factor, and an active domain that has stopped receiving mail. Every finding carries its fix.

Prove the decision instead of arguing about it

Most of the time an MSP spends on email security is spent explaining a single message. Closing that ticket means showing exactly what happened to it.

Message search across customers

Search sender, recipient, subject, IP, domain and verdict across every domain your role can see, then open a message for each stage’s verdict and score — including which one actually pushed it over the line.

Quarantine management

Every domain your role can see in one queue. Release, delete, or add the sender to an allow or deny list from the same screen; a released message reinjects the retained original content and queues like any other.

Monitor before you enforce

Monitor Mode scores and records every message for a domain with delivery unchanged, so you can size the impact of a policy on a real customer’s traffic before it is enforced on anything.

Reporting customers can see

What the gateway did, in a form you can put in front of the person paying for it.

  • Per-domain summaries of what was delivered, quarantined and rejected, over selectable ranges
  • Threat detection broken down by filter, so a number has a reason behind it
  • Scheduled summary emails, opt-in per domain, plus a platform summary for you
  • DMARC aggregate reports ingested and analyzed per domain, with alerting on unauthorized senders, senders that authenticate without aligning, new sources and reports that stop arriving
  • An audit log of administrative and security-sensitive activity, to support accountability and investigation

Usage and billing figures are per tenant too: domains at your tier rate plus any storage, producing the figure you put on your own invoice.

How a customer domain is deployed

The conditions are the same for every domain, which is what makes the work repeatable.

  • Mail routes through the gateway. The domain's MX points at mt0.mailthreatzero.com and filtered mail is handed to the customer's platform over its own supported inbound path — an Exchange Online inbound connector, a Google Workspace inbound gateway, or any SMTP destination you configure per domain.
  • Verified before cut-over. The wizard checks the tenant, public DNS, the destination and that the platform will accept mail from the gateway, each check returning a specific remedy.
  • Outbound inspection and DLP are available for mail routed through the MailThreatZero gateway. Authenticated submission on port 587 with a per-domain credential, with payment card numbers, US Social Security numbers and IBAN bank accounts each validated by their own checksum, plus any patterns you configure. Coverage depends on mail-flow configuration.
  • Attachment intelligence uses your own accounts. Signature scanning, document and macro analysis are included; multi-engine attachment reputation runs on your own VirusTotal account, billed by them directly with no markup from us.
  • Internal mail can be captured for the archive add-on. Point the customer's journal rule at the gateway and user-to-user mail is retained alongside everything else; the console generates the exact steps.

See the full capability comparison.

Evaluate One Domain Before You Commit

Run a customer domain in Monitor Mode to review classifications, policy behavior, and message-level decisions before enabling enforcement.

Evaluate One Domain

Stop paying more every time a customer adds a mailbox.

Protect customer domains with layered filtering, clear decisions and MSP-friendly pricing.