Agency client-domain onboarding should establish ownership and monitoring before the first campaign, migration, or DNS change. A short checklist prevents the familiar problem where nobody knows who controls the registrar, which provider sends mail, or where an expiring certificate is managed.
Collect access and ownership details
Document the registrar, DNS host, web host, email provider, billing owner, recovery contacts, and approval process. Use least-privilege access and avoid sharing one master password. Confirm the client understands who can authorize changes.
Inventory the live configuration
Record nameservers, MX records, SPF, DKIM selectors, DMARC policy, website endpoints, certificates, and renewal dates. Run Beacon’s free domain check and compare its public results with the client’s stated setup. Unknown sending sources should be resolved before a restrictive DMARC change.
Set the monitoring and escalation plan
Agree on who receives uptime, expiry, and authentication alerts; which issues need immediate contact; and how after-hours escalation works. Link the work to DMARC for agencies and the domain-health checklist.
Review after launch
Verify a fresh message, the key website pages, and DNS after the project goes live. Onboarding is complete when the client and agency can both explain the current setup and the alert response path.
Use a repeatable evidence pack
For every client, capture the current DNS export or screenshots, a recent authentication header from each sending system, certificate and renewal dates, and the designated alert contacts. Store only the information the agency is authorized to retain, and keep it accessible to the people who will respond to an incident.
Agree on change control
Define which changes require client approval, who may edit DNS, and how an urgent outage will be communicated. Require a written record for SPF, DKIM, DMARC, MX, nameserver, and redirect changes. This prevents a well-intentioned campaign launch from replacing a working authorization or policy.
Build a first-30-days review
Review alerts, fresh message headers, and public DNS after onboarding. Ask the client whether any new vendor is planned. That conversation often reveals a sender or registrar dependency that was not mentioned during intake. The agency relationship is stronger when the client sees an explicit, calm operational process.
Define success at handoff
Before considering onboarding complete, confirm that the agreed contacts receive alerts, the client knows how to request a DNS change, and the agency has tested the public records and a real sending path. Give the client a concise summary of findings, unresolved risks, and renewal dates. This avoids the ambiguity where monitoring exists but no one knows who is meant to respond.
Decision summary
Strong onboarding protects both the agency and client: it makes scope visible, turns domain health into an ongoing service conversation, and creates evidence for safe future changes.
Make reviews routine
Schedule a post-onboarding check and periodic client review. The agency can use results to spot renewal, authentication, or access drift early and to show the client exactly what is being maintained on their behalf.
Confirm client understanding
Walk the client through the essential records and alert path in plain language. They do not need to manage every detail, but they should know who to contact, what an alert means, and why an unapproved DNS change can affect email and the website.
Record the approved baseline
After the first review, save the approved DNS, sender inventory, and alert contacts as the baseline. Future work can then compare changes against an agreed record, avoiding confusion when a client changes vendors or asks an agency to troubleshoot a delivery incident.
For the ongoing agency process, review DMARC for agencies.