DomainGuard for agencies

The domain expires. The client blames you.

You did not buy it, you do not hold the card, and the renewal notice went to an inbox on the domain that just stopped resolving. It is still your phone that rings. DomainGuard keeps one list of every client domain you touch — expiry, certificates, mail authentication, uptime and lookalikes — and tells you first.

DomainGuard is in a public TestFlight beta and is not on the App Store yet. The web dashboard is live, and the free plan needs no card.

How it actually goes wrong

Nothing fails on a day you happen to be looking.

Client domains break quietly, in four familiar shapes. Every one of them is invisible from your project tool and obvious from a registry lookup.

  1. Month 14

    The card on the registrar account expired

    Auto-renew fails silently. The renewal notice goes to an address on the domain that is about to stop resolving, so nobody reads it. DomainGuard reads the registrar record itself and warns you at your address, not theirs.

  2. The Friday deploy

    A certificate lapsed on a host nobody owns

    The main site renews automatically. The client portal on a second host does not. Certificate expiry is tracked per host, so the alert names which one rather than saying something is wrong.

  3. A month after the migration

    A new sending platform broke SPF

    Marketing signed up for something and edited a record without telling anyone. SPF, DKIM and the DMARC policy get re-checked and the change is stored as a diff against the last scan.

  4. Once they are worth impersonating

    Somebody registered a domain one letter off theirs

    Almost never to build a website. It is registered to send invoices. The lookalike watch scores the registration, its mail records, and whether the page copies the client's own homepage.

One list, every registrar

Your portfolio is scattered because your clients' portfolios are.

A defensive .net at one registrar, the main name at another, a client account you have view access to. There is no single dashboard because there is no single account, so the list has to live outside all of them.

Client domains kept separate

Domains group as personal, business or client, so a name sitting in somebody else's registrar account is still a name on your list. Every plan holds unlimited domains. What a plan buys is how many are watched without being asked.

Alerts that survive the outage

Notifications go to an address you choose, off the domain being monitored. The reason registrar warnings get missed is that the alarm is wired to the thing it is meant to protect.

A record you can show

Scan history, DNS diffs, certificate timelines and uptime windows are kept per domain, so “when did this change” has an answer that is not somebody's memory.

The part almost nobody else has

Ask Claude about the client portfolio.

DomainGuard ships an MCP server at /api/mcp with 60 tools. Point Claude, or any MCP client, at your own account with an API key and ask in words instead of clicking through a dashboard. Read access is on Pro; Enterprise adds the write scope.

Things an account manager actually asks

  • Which client domains expire in the next 60 days?
  • Show me every domain whose certificate expires before the end of the month.
  • List the domains still on DMARC p=none, oldest first.
  • Has anything changed in DNS on any client domain this week?
  • Draft the client summary for Riverside: what is healthy, what needs a decision.

A key carries resource scopes, and the plan is re-read on every call. A read-only key cannot start a scan, spend a credit or change a record, so handing one to an assistant is not handing it the account.

For an agency the useful part is the monthly client update nobody wants to write. The data is already structured. The assistant does the assembling.

Read the full MCP reference

Where the line is

Deep scans need you to prove you run the site.

Passive checks read what a site already publishes and work against anything. Port scanning and the active vulnerability scanners are gated on proof of control — a DNS record, a file on the site, or an email at the domain — and that proof lasts 90 days.

For an agency that is a feature, not an obstacle. You can prove control of the sites you run, and the gate is what stops the same platform your clients' scans run on from being pointed at somebody else's infrastructure. DomainGuard also never edits DNS, a registrar record or a website. It finds, records and recommends. The change stays yours.

What it costs

Start free. Pay when you want it watched for you.

The free plan holds every domain you manage and runs every health check on demand, with no card and no expiry. What free does not include is monitoring that runs while nobody is looking.

Free

$0

Unlimited domains, every health module on demand. Three domains get a five-minute uptime probe, one address is watched for breaches, and KEV/CVE alerts run. Ad supported.
Starter

$6.99/mo · $69.99/yr

The nightly re-scan on 25 domains, email alerts, DMARC report ingestion, SEO and accessibility scanning, PDF reports, no ads.
Pro

$49.99/mo · $499.99/yr

100 domains watched, the local SEO suite, monthly reports, and read access over the API and the MCP server.
Enterprise

$99.99/mo · $999.99/yr

Hourly scans, unlimited automation, priority queue, and write access over the API and the MCP server.

Plans are bought through Apple in-app purchase. DomainGuard is pre-revenue and the iPhone app is still in beta, so what you can use today is the free plan and the TestFlight build.

Before you add the first client

Questions agencies ask.

Do you need the client's registrar login?

No. Expiry, nameserver, certificate and mail-authentication data all come from public records — DNS, RDAP and certificate transparency — so you can watch a domain you do not hold the login for. That matters, because the domain a former developer registered on their own account is usually the one that lapses.

Can DomainGuard renew a domain or fix DNS for us?

No, and it will not pretend to. DomainGuard scans, records and alerts. Renewing happens at the registrar and DNS changes happen at the DNS provider. What it does is tell you which domain, which record, and how long you have.

How do the scans that need permission work?

Passive checks — DNS, certificates, mail authentication, security headers, technology detection — run against anything, because they only read what a site already publishes. Port scanning and the active vulnerability scanners require proof that you control that specific domain: a DNS record, a file on the site, or an email at the domain. Proof lasts 90 days. It is a deliberate limit. An unauthenticated port scanner pointed at strangers is how a platform account gets banned, and an agency can prove control of the sites it runs.

Is there anything to hand the client?

PDF reports start on Starter at $6.99 a month, alongside email alerts and the scheduled re-scan. On Pro and Enterprise the API and MCP server let you pull the same data into whatever you already send.

What does it cost to try?

Nothing. The free plan holds every domain you manage and runs every health check on demand, with no card and no expiry. What free leaves out is the part that runs while you are not looking: the nightly re-scan and email alerts start at $6.99 a month. The iPhone app is in a public TestFlight beta and is free to join.

Add the client list

Find out what is already wrong before the client does.

Put every domain you manage in the free plan and run the checks yourself. The iPhone app is in public beta on TestFlight, free to join, and signs in with the same account.