Qualification
Qualifying the request: domains, current operation, owners, gaps
For CISO, CIO, IT and deliverability roles, the request form works best from a concrete decision record rather than a generic brief. It should name the enforced domains, who reads the reports today, how exceptions are tracked and what is slipping. With that, dotNice can separate a light health check from taking over the operation, rescuing a neglected policy or building the run-book — and recommend clearly what to onboard, read, govern or alert on.
The review is most valuable when the buyer can describe the current gap: which domains are enforced, whether anyone reads the aggregate reports, how new senders get added, and which team owns DNS and the sending platforms. A request is qualified when it states the domains, the current operation and the gaps. The output is a scoped decision — a managed run state with owners and cadence — not a service catalogue.
The cost of waiting belongs in the same record. An unmanaged enforced policy drifts: a new sender breaks, a stale exception widens the gap, an abuse spike goes unseen, and the first signal is a customer complaint or a blocked invoice. Quantifying that exposure — deliverability loss, spoofing risk, operational firefighting — is what moves DMARC management from a backlog item to a funded operation with an owner and a cadence.