Add domain and email health to your website care plan
What a website care plan usually misses, what to check each month, what to put in the client's report, and how to price the domain and email part.
By Doug Hall · Updated
- Most care plans cover updates, backups and uptime, and miss the domain renewal, the certificate on www and the email records.
- Those are the failures clients notice most: the site vanishes, or their invoices land in spam.
- Check them daily, report them monthly in plain English, and price them as their own line.
What a typical care plan misses
A website care plan usually covers the site itself: plugin and core updates, backups, uptime monitoring, a security scan and a monthly report of what was done. That's all worth paying for. But the things that take a small business offline most completely aren't on the server at all:
- The domain registration. If it lapses, the website and the email stop together. Auto-renew fails more often than people think: an expired card, a registrar account in the name of someone who has left, or a renewal notice going to an old address.
- The certificate on every name. The certificate on the bare domain renews, but the one on www doesn't, or the other way round. Visitors on one of the two addresses get a full-page browser warning.
- Email authentication. SPF, DKIM and DMARC decide whether the client's quotes and invoices reach the inbox, and whether someone else can send email pretending to be them. Gmail, Yahoo and Microsoft all now expect them.
- DNS changes. Someone moves the MX records while "helping", or a new marketing tool asks for an SPF change that breaks the record. Nobody tells you.
- Blacklists. A compromised mailbox or an abused contact form gets the client's mail server listed, and their email quietly stops arriving.
Uptime monitoring tells you about the first problem only after the site has gone. A care plan that checks these things in advance catches them weeks before the client notices.
Why it belongs in the care plan
Clients don't separate "the website" from "the domain" from "the email". When the site disappears because the domain expired, they ring the people who look after the website. You get the call whether or not it was in the plan, so you may as well be paid to prevent it.
There's a direct link to the site, too. WordPress contact forms send email, usually from the web server. That server is rarely in the domain's SPF record and doesn't sign with the domain's DKIM key, so once the domain has a strict DMARC policy, those form emails fail and go to spam. Enquiries the client never sees look like a quiet website. Our page on domain and email health for WordPress care plans covers the contact-form fix in more detail.
And it's easy to show value. Updates and backups are invisible when they work. A grade that moves from D to B because you fixed the client's email records is something they can see, and something you can put in front of them every month.
What to check, and how often
All of these can be checked from public DNS and the site's own HTTPS connection, so nothing needs installing on the client's server. Daily is the right frequency: these problems arrive without warning, and a monthly check finds them three weeks late.
| Check | What goes wrong | When to act |
|---|---|---|
| Domain expiry | Registration lapses; site and email stop together | 30 days before expiry, urgently at 7 |
| Certificates (bare domain and www) | Expired, wrong name, or broken chain on one of the two | 21 days before expiry, or at once if invalid |
| SPF | Missing, two records, or over the 10-lookup limit | As soon as it fails |
| DKIM | No key for the service that sends, or a weak key | As soon as it fails |
| DMARC | Missing, stuck at p=none, or no reports going anywhere | Missing at once; plan the move to reject |
| MTA-STS and TLS-RPT | Not set up, or the policy file is unreachable | Next review |
| Blacklists | Mail server or sending address listed | Same day |
| DNS records | Records changed without anyone saying | When the change appears |
You can run every one of these by hand with our free tools: the domain health check for the lot, the SPF checker for the lookup count, the DMARC checker for the policy, and the blacklist checker for listings. By hand works for five clients. For thirty, you want something that checks daily and tells you only when something changes.
What to put in the monthly report
The client report is where this part of the care plan earns its keep. Most clients won't read a table of DNS records, and shouldn't have to. Aim for something a business owner understands in thirty seconds:
- One overall grade. A letter from A to F says more to a non-technical reader than a list of passes and fails. If they have several domains, give each its own grade and an overall one.
- The trend. How the grade has moved over the last few months. A rising line is the clearest proof the work is being done.
- What changed this month. What improved, what got worse, and anything that happened without them knowing (a DNS change, a renewal, a new sender appearing).
- The top three fixes. Not twenty. Three, each with why it matters in business terms and roughly how long it takes. That's also where the extra work you can quote for comes from.
- How much of their email passed. From the DMARC reports: the share of the client's email that passed SPF, DKIM and DMARC, and any service sending as them that isn't set up. If you need to make sense of the raw reports first, see how to read a DMARC report.
Leave out record syntax, IP addresses and anything that needs a glossary. Keep it to two pages, with your logo on it, sent at the same time each month. Our sample report card follows exactly this shape, and you can download it as a PDF to see how it reads.
Packaging and pricing it
There are two common ways to add it. Either fold it into every care plan and raise the price a little, or sell it as a named add-on ("Domain and email care"). The add-on is easier to explain and easier for the client to say yes to, because they can see exactly what the extra money buys.
A pattern that works well is a one-off set-up fee to fix what's broken today, then a monthly fee for monitoring and the report. The figures below are examples to show the structure, not market rates; set your own from your costs and your clients.
| Example tier | What's included | Example price |
|---|---|---|
| Set-up (one-off) | Fix SPF, DKIM and DMARC; move the registration into the client's name; confirm renewals | £150 to £300 |
| Essentials | Daily checks, expiry and certificate alerts, monthly report card | £10 to £15 a month |
| Plus | Essentials, plus DMARC reports read and acted on, and the move to p=reject | £25 to £40 a month |
Whatever you charge, put it on the invoice as its own line. A line called "Domain and email care" with a report card behind it is much harder to cut than an unexplained increase.
Answering the usual objections
"Email isn't the website." True, but the domain is both, and the website sends email through its forms. When either breaks, you're the one they call.
"We've never had a problem." Run a free check of their domain in front of them. Most small business domains have at least one thing to fix: no DMARC, DMARC at p=none with nobody reading the reports, or an SPF record that has crept towards the lookup limit.
"Our IT company does email." Then the report is something to share with them. Most small IT providers are glad of a second pair of eyes on DNS they don't look at often.
Getting started with existing clients
- List every domain. Not just the main one: old brand names, the .com beside the .co.uk, and domains bought for a campaign. Unused domains need protecting too.
- Check who owns each registration and where the renewal notices go. Fix the ones in a former employee's name first.
- Run a check on each. Note the grade. That's your baseline, and the first report shows the improvement.
- Publish DMARC with reporting on any domain that has none, at p=none to start. Our DMARC record generator writes the record. The DMARC guide explains how to move to reject once the reports show every real sender passing.
- Send the first report with the add-on offer attached. It's the most persuasive sales document you have, because it's about their domain.
For agencies with more than a handful of clients, our page for web agencies shows how the daily checks, alerts and report cards fit together, and pricing sets out what each plan covers.
Doing this for clients? Domain Health Hub checks every client domain each day and puts the results in a monthly report card with your logo. Start a free trial; no card needed.
Questions
Do I need access to the client's DNS to monitor it?
No. Domain expiry, certificates, SPF, DKIM, DMARC and MTA-STS can all be checked from public data. You only need DNS access to fix what you find, or to point the DMARC reports somewhere useful.
Who should own the domain registration, the agency or the client?
The client, in an account they control, with you added as a user or given the login. Registering it in your own name makes leaving awkward for both of you, and an expired card on your account takes their site down.
Is DMARC really part of website care?
It's part of the domain, and the domain is what the website and the email share. The contact form on the site sends email too, and a strict DMARC policy will junk it if it isn't set up properly.
How much should I charge for this?
That's your call; we don't publish market rates. The examples in this guide show one way to structure it. Price it as a visible line so the client can see what they're paying for.
Watch every client's domains, every day.
Reports read for you, and a monthly report card your clients will understand.