The breach is never at your company
It is at a shipping portal, a conference registration site, a forum somebody signed up for with a work address in 2019. Nothing in your environment logs it, because nothing in your environment was involved.
DomainGuard · dark web monitoring
Nobody attacks your mail server any more. They buy a password your bookkeeper used on a site that got dumped four years ago, try it against the mailbox, and send an invoice from a real thread. DomainGuard watches a business address against known breach data and tells you when it turns up somewhere new.
Dark-web monitoring is a native tab in the DomainGuard iPhone app, which is in a public TestFlight beta. One monitored address is included on the free plan.
Why this one is watched for you
Every other module in DomainGuard reads a record that is sitting there waiting. This one is an event that happens to you elsewhere, which is why it is the one thing a free account gets automatically.
It is at a shipping portal, a conference registration site, a forum somebody signed up for with a work address in 2019. Nothing in your environment logs it, because nothing in your environment was involved.
An address on its own is a nuisance. An address paired with a password that also opens the mailbox is a takeover, and a mailbox takeover is how a fake invoice gets sent from a real thread.
A domain's DNS is there to be re-read whenever you like. An address turning up in a dump is an event, and an event nobody is watching for is one you learn about afterwards.
What detection actually is
Dark-web monitoring gets sold with hooded figures. The mechanism is a hash, an index lookup, and a schedule.
What it cannot do
This category attracts more overselling than any other part of security software, so here is the boundary.
Once a dump exists it is copied. Any service claiming deletion from the dark web is selling you a feeling. What monitoring buys is knowing which credentials to rotate and how urgently.
Known, catalogued breach corpora. A dump that has not been indexed, or that never became public, is not in there. A clean result means nothing known, not nothing exists.
Today you monitor specific addresses, not every address at a domain. The app says so, and it will take your name so we can tell you when that changes rather than leaving the promise in a toggle on one device.
There is no dark-web panel in the web dashboard. The rest of DomainGuard is on the web; this module is a native tab in the app, which is currently a public TestFlight beta.
What you get on each plan
The number of monitored addresses is the only thing that changes with the plan. The checking itself works the same on all four.
Annual pricing is $69.99, $499.99 and $999.99. Plans are bought through Apple in-app purchase, and DomainGuard is pre-revenue — the app is in beta and nobody is subscribed yet.
Straight answers
The lookup is similar. The difference is that this one keeps running. A one-off search tells you about breaches indexed before the day you searched, and the next one lands after you stopped thinking about it. DomainGuard re-checks the address on a schedule and tells you when the answer changes, and it does that on the free plan.
As a SHA-256 hash and an encrypted envelope, never in the clear. The hash is the identity, the dedup key and the cache key, and it is what appears in audit records. The app addresses a monitored address by hash and never receives the ciphertext.
Not yet. Monitoring is per address. Domain-wide monitoring is on the list rather than in the product, and the app records that you asked for it so there is somebody to notify when it ships. Adding an address for a shared domain also needs the account to own that domain, so one tenant cannot enumerate another company's staff.
Change the password on the breached service, change it anywhere it was reused, and turn on two-factor authentication on the mailbox first. If the exposed data includes anything beyond a password — security questions, a phone number, a physical address — treat those as public now. Our password checker is a reasonable next stop for testing what you replace it with.
It is the other half. Dark-web monitoring is about credentials that already leaked. Mail authentication and inbound filtering are about messages arriving now. DomainGuard covers the first and reports on your SPF, DKIM and DMARC posture; NHM's managed email security is the filtering layer, and that is a separate service.
Check one address
That address is the one attackers want, and the free plan monitors one. Dark-web monitoring is a tab in the DomainGuard iPhone app, which is free to join on TestFlight while it is in beta.