DomainGuard · dark web monitoring

The breach that gets you happens somewhere else.

Nobody attacks your mail server any more. They buy a password your bookkeeper used on a site that got dumped four years ago, try it against the mailbox, and send an invoice from a real thread. DomainGuard watches a business address against known breach data and tells you when it turns up somewhere new.

Dark-web monitoring is a native tab in the DomainGuard iPhone app, which is in a public TestFlight beta. One monitored address is included on the free plan.

Why this one is watched for you

It is the only risk here you cannot go and check.

Every other module in DomainGuard reads a record that is sitting there waiting. This one is an event that happens to you elsewhere, which is why it is the one thing a free account gets automatically.

The breach is never at your company

It is at a shipping portal, a conference registration site, a forum somebody signed up for with a work address in 2019. Nothing in your environment logs it, because nothing in your environment was involved.

The password is the payload

An address on its own is a nuisance. An address paired with a password that also opens the mailbox is a takeover, and a mailbox takeover is how a fake invoice gets sent from a real thread.

You cannot check for it on demand

A domain's DNS is there to be re-read whenever you like. An address turning up in a dump is an event, and an event nobody is watching for is one you learn about afterwards.

What detection actually is

Five steps, and none of them are mysterious.

Dark-web monitoring gets sold with hooded figures. The mechanism is a hash, an index lookup, and a schedule.

  1. 01You add an addressOne on the free plan, five on Starter, ten on Pro, fifty on Enterprise. It is added in the DomainGuard iPhone app, where the feature lives.
  2. 02It is hashed before it is storedThe row holds a SHA-256 hash plus an encrypted envelope. The hash is what the system works with and what the app addresses the row by. The address itself never appears in a log or an audit entry.
  3. 03It is checked against a public breach indexThe upstream is an open breach index that maps an address to the incidents it appeared in and the categories of data each one exposed. Results are cached by hash, so two accounts watching the same address cost one lookup.
  4. 04You get the breach list, not a score aloneWhich incidents, what kind of data each exposed, and a risk reading derived from that. The useful output is a list of accounts to go change, in priority order.
  5. 05It re-checks on a scheduleManual, weekly or daily. This is the one automatic thing a free account gets, on purpose, because it is the one risk that cannot be found by pressing scan.

What it cannot do

Four limits, said out loud.

This category attracts more overselling than any other part of security software, so here is the boundary.

Nothing can remove your data from a breach

Once a dump exists it is copied. Any service claiming deletion from the dark web is selling you a feeling. What monitoring buys is knowing which credentials to rotate and how urgently.

Coverage is what the index has indexed

Known, catalogued breach corpora. A dump that has not been indexed, or that never became public, is not in there. A clean result means nothing known, not nothing exists.

Whole-domain monitoring is not built yet

Today you monitor specific addresses, not every address at a domain. The app says so, and it will take your name so we can tell you when that changes rather than leaving the promise in a toggle on one device.

It lives in the iPhone app

There is no dark-web panel in the web dashboard. The rest of DomainGuard is on the web; this module is a native tab in the app, which is currently a public TestFlight beta.

What you get on each plan

One address free, forever, on a schedule.

The number of monitored addresses is the only thing that changes with the plan. The checking itself works the same on all four.

Free · $0
1 monitored address, re-checked on a schedule. KEV and CVE alerts are included too — they are not plan-gated at all.
Starter · $6.99/mo
5 monitored addresses, plus email alerts and the nightly re-scan of every other module.
Pro · $49.99/mo
10 monitored addresses, plus read access over the API and the MCP server.
Enterprise · $99.99/mo
50 monitored addresses, hourly scanning elsewhere, and API write access.

Annual pricing is $69.99, $499.99 and $999.99. Plans are bought through Apple in-app purchase, and DomainGuard is pre-revenue — the app is in beta and nobody is subscribed yet.

Straight answers

Questions about breach monitoring.

Is this different from a free breach lookup site?

The lookup is similar. The difference is that this one keeps running. A one-off search tells you about breaches indexed before the day you searched, and the next one lands after you stopped thinking about it. DomainGuard re-checks the address on a schedule and tells you when the answer changes, and it does that on the free plan.

Do you store our email addresses?

As a SHA-256 hash and an encrypted envelope, never in the clear. The hash is the identity, the dedup key and the cache key, and it is what appears in audit records. The app addresses a monitored address by hash and never receives the ciphertext.

Can we monitor every address at our domain?

Not yet. Monitoring is per address. Domain-wide monitoring is on the list rather than in the product, and the app records that you asked for it so there is somebody to notify when it ships. Adding an address for a shared domain also needs the account to own that domain, so one tenant cannot enumerate another company's staff.

What should we do when something comes back exposed?

Change the password on the breached service, change it anywhere it was reused, and turn on two-factor authentication on the mailbox first. If the exposed data includes anything beyond a password — security questions, a phone number, a physical address — treat those as public now. Our password checker is a reasonable next stop for testing what you replace it with.

Where does this sit next to email security?

It is the other half. Dark-web monitoring is about credentials that already leaked. Mail authentication and inbound filtering are about messages arriving now. DomainGuard covers the first and reports on your SPF, DKIM and DMARC posture; NHM's managed email security is the filtering layer, and that is a separate service.

Check one address

Start with whoever pays the invoices.

That address is the one attackers want, and the free plan monitors one. Dark-web monitoring is a tab in the DomainGuard iPhone app, which is free to join on TestFlight while it is in beta.