For agencies, MSPs & consultants

Many clients. Many domains. One place, with your name on it.

Sentinely has been multi-tenant since the first day: a separate space per client, per-domain access for each user, and your brand applied to the application, the emails and the PDF reports.

Everything that decides if your domain is trusted

  • SPF
  • DKIM
  • DMARC
  • BIMI
  • MTA-STS
  • TLS-RPT
  • MX
  • NS
  • DNSBL/RBL
  • rDNS/PTR

Sentinely watches the full stack of signals mailbox providers use to trust — or reject — your mail. MX and NS are watched too: not for the score, but so you know the day they change.

The problem

The work scales. The reporting is what doesn't.

Running email authentication for other people is mostly an administration problem, and most tools are built for one company watching itself.

Every client is a separate login

Domains scattered across accounts nobody has a full view of, and a monthly report you assemble by hand from screenshots.

The report carries someone else's name

You did the work and wrote the recommendation, and the PDF that reaches the client has another vendor's logo at the top of it.

Onboarding eats the margin

If setting up a client takes a day of agent installs and gateway changes, the engagement is underwater before it starts.

What you get

Built for running this on other people's domains.

Not a single-tenant tool with a client dropdown bolted on.

A separate space per client

Many domains and many clients kept properly apart, with per-domain access assignable to individual users — so a client's own staff can see their domain and nothing else.

Your brand, end to end

Name, colour, logo and footer applied to the application, the alert and digest emails, and the exported PDF reports.

A read-only REST API

A public /api/public/v1 with a per-tenant key covering domains, alerts and reports, documented with Swagger — so the data can live in your dashboard or your client's.

One email per person, not one per domain

Whoever watches twenty domains gets a single message covering all of them, worst first: what changed, the grade, sources on a blocklist, domains that stopped sending reports. Daily, weekly or both — each recipient picks the cadence, the language and the severity threshold. Plus PDF export for the report the client keeps.

The change the client made without telling you

The initial setup is rarely the problem; the edit three months later is. Every run compares each client's DNS with the previous observation and raises an alert on the difference — MX and NS included, watched but never scored.

Selectors on domains you inherited

You take a domain over and nobody remembers which DKIM selectors are in use. Sentinely proposes the ones that appear in the aggregate reports and you confirm them — a partial list, since many senders omit the selector, but better than interrogating the previous supplier.

A number to put in the audit

How many IPv4 addresses a client's SPF authorises, and how many actually sent in the last 90 days. It's the line that makes a clean-up easy to justify — and a floor, since it counts the addresses written literally in the record.

Onboarding is one DNS record

No agent, no gateway change, no mail rerouting. Hand the client the rua= record to publish — or push reports yourself over a signed HTTP webhook. The first report lands within a day.

External domains handled

When reports cover a third-party domain, Sentinely manages the consent record the standard requires, automatically, instead of leaving you to chase it.

Run every client's email authentication from one place.

Start with the 30-day trial — white-label and AI Insights are switched on while it runs — or talk to us about volume.