DomainGuard · DNS monitoring

Know when your DNS changed, and what it changed from.

An unauthorized or accidental DNS edit can stop mail, hand traffic to someone else, or be the first visible sign of a compromise. DomainGuard compares every scan of a domain to the previous one and records exactly which record changed, the old value, and the new one.

What is compared

Five record sets, diffed field by field.

The comparison is intentionally narrow. These are the records whose quiet change breaks email delivery or signals that someone else now controls the domain.

SPF record and status
The full TXT value and whether it passed. A new include, a flipped -all, or a second SPF record that makes the whole thing permerror all show up as a diff.
DKIM record and status
The selector record we can see and its pass/fail state, so a rotated or deleted key is visible before signatures start failing at the receiving end.
DMARC record and status
The policy line itself. A p=reject that quietly becomes p=none, or a rua address that changes to one you do not recognize, is the kind of edit this exists to catch.
MX routing
Every mail exchanger and its priority, sorted so a re-ordering is not mistaken for a change and a new host is never missed.
Authoritative name servers
The NS set for the domain. A name server change is the single strongest signal that a domain has been transferred, re-delegated, or hijacked.

How it works

Snapshot, compare, record.

  1. Step 1

    Baseline

    The first scan of a domain stores the current SPF, DKIM, DMARC, MX and NS values. There is nothing to compare yet, so no event is written.

  2. Step 2

    Compare

    Each later scan builds the same snapshot and checks it against the last stored one. Sorting is applied first, so MX or NS entries in a different order do not count as a change.

  3. Step 3

    Record and alert

    Every differing field is written to the domain's change log with its previous and current value. On paid plans, the same diff becomes an alert in the dashboard and a push to the iPhone app.

On the free plan the scan is something you run; on Starter and above it runs on a schedule without being asked. Either way the log is the same, and it lives next to the rest of the domain's history in the dashboard.

Why records change

Most DNS incidents are not attacks. The ones that are look identical.

A change log does not have to decide which is which. It has to make sure a human sees the change while it is still cheap to reverse.

A provider migration nobody finished
The new email platform published its SPF include; the old one was never removed. Two includes later the lookup limit is exceeded and SPF fails for everyone.
A registrar or DNS host change
The name servers move, the zone is rebuilt from memory, and the DKIM selector and the DMARC record do not come across. Mail keeps sending. Authentication does not.
A compromised account
Someone with the DNS login points MX at a host they control or drops DMARC to p=none before a spoofing campaign. Both are single-record edits that look ordinary in a zone editor.
A well-meaning vendor
A marketing tool's setup wizard writes its own SPF record over the one that was there. Nobody on your side made a change, and nothing tells you until bounces start.

Straight answers

Questions about DNS change monitoring.

How does DomainGuard know a DNS record changed?

Every scan stores a snapshot of the records above. The next scan is compared field by field against the last stored one, and any field that differs is written to the dashboard as a change event with the previous value and the new value side by side. The first scan of a domain is the baseline, so there is nothing to compare until the second.

Does it watch A records, CNAMEs, or TXT records in general?

The change log above is deliberately narrow: mail authentication (SPF, DKIM, DMARC), MX routing, and name servers, because those are the records whose silent change breaks mail or signals a takeover. Hijack Guard, which sends the change alert, also compares the apex A and AAAA addresses, DNSSEC, the registrar, the transfer lock and the certificate issuer. CNAMEs and arbitrary TXT records are not compared today.

What runs on the free plan?

Every domain you own can be added on the free plan, and every scan you run on demand is compared to the previous one, with the change log kept in the dashboard. What free does not include is the nightly re-scan that runs without being asked and the alert that follows a change. Both start on the Starter plan at $6.99 a month.

How do I get told about a change?

On Starter and up, turn on Domain changes (Hijack Guard) in the dashboard's alert settings. Each change then lands in the Alerts page of the dashboard with its previous and current value, and it is pushed to your iPhone if the DomainGuard app is signed in there. Neither depends on mail for the watched domain, which matters for the same reason a registrar's expiry notice is worth nothing once the domain stops resolving.

Is a detected change always a problem?

No. Planned migrations and key rotations produce diffs too, which is why the event shows the exact before and after rather than a generic warning. The value is knowing that the change happened and when, so the one that was not planned stands out.