DomainGuard for MSPs

At the QBR, coverage is whatever you can show.

You know the tenant is watched. Proving it is a different job, and it usually turns into an afternoon of screenshots. DomainGuard keeps the record while the monitoring runs: expiry, certificates, DNS changes, uptime windows, open ports and CVE exposure, per tenant, with dates on everything.

DomainGuard is in a public TestFlight beta and is not on the App Store yet. The web dashboard is live, and the free plan needs no card.

Evidence, not assertion

Six questions a client asks, and the record that answers each one.

The gap at a quarterly review is rarely the work. It is that the work left no artifact, so the answer has to be a sentence beginning with “we monitor for that”.

Common quarterly business review questions and the DomainGuard record that answers each of them.
What they askWhat you open
Is every domain we own being watched?The domain list, with the last scan time on each one. Every plan holds unlimited domains, so nothing is left out for being over a cap.
Did anything change without us knowing?The DNS diff and the domain-event feed: nameserver, registrar, certificate and hosting changes, each with a timestamp and a severity.
Were we down last quarter?Uptime snapshots and recorded downtime windows, including the ones nobody was awake for.
Are we exposed to anything in the news?KEV and CVE alerts carrying a verdict — confirmed, possible, not affected or unconfirmed — derived from that tenant's own scan evidence rather than a product name match.
Can our email be spoofed?SPF, DKIM and the published DMARC policy per domain, with aggregate report data on Starter and up.
What did you actually do about it?The activity feed and the compliance tracker, which turns PCI, HIPAA and cyber-insurance requirements into items with a status.

How it scales across tenants

The domain count is never what you pay for.

Adding a domain is never refused, on any plan, including the free one. What a plan sells is attention: how many domains are re-checked without anyone asking, and how often.

Unlimited domains on every plan

Including free. What a plan buys is how many are watched without being asked: three on Free, 25 on Starter, 100 on Pro, no limit on Enterprise. A domain over the automation cap still scans on demand and still accepts edits, and the oldest domains keep the automation.

Cadence is the paid part

Free runs every module the moment you ask for it, and keeps a five-minute uptime probe on three domains. The nightly re-scan starts at Starter. Enterprise moves it to hourly with a priority queue.

One key per integration

API keys carry resource scopes — domains, scans, seo, vulnscan, compliance, status, accessibility — plus an optional write scope on Enterprise. Keys are rate limited per hour, and the plan is re-read on every request, so a downgrade drops write access on the next call rather than at the next renewal.

The part almost nobody else has

Your tenant data, inside Claude.

DomainGuard runs an MCP server at /api/mcp over Streamable HTTP with 60 tools. An API key is the bearer token, the tool list is filtered to that key's scopes, and the plan is checked on every call. Pro gets the 35 read tools; Enterprise adds the writes.

Questions worth asking on a Monday

  • Across every tenant, which domains have a certificate expiring in the next 14 days?
  • Which KEV alerts are confirmed rather than just name-matched?
  • Give me the last 30 days of downtime by tenant.
  • Which tenants still have no DMARC record published at all?
  • Build this quarter's coverage summary for Ashland Manufacturing.

This is the piece that changes the reporting job. Quarterly summaries, exception lists and “which tenants need a call this week” all become questions rather than exports, and the answer is built from the account's own records rather than from a model's guess.

Mint one key per use and give it only the scopes it needs. Tools outside a key's scopes are never offered and cannot be called.

Read the full MCP reference

What it is not

Three things to be clear about before you slot it in.

DomainGuard sits next to the stack you already run rather than replacing a piece of it.

It is not an RMM

There is no agent, nothing installed on an endpoint, and no patch deployment. DomainGuard watches the outside of a tenant: the domain, the DNS, the certificate, the mail authentication, the exposed services and the site itself.

It does not change anything for you

No DNS edits, no registrar actions, no site changes. Enterprise write access reaches the account's own data — starting a scan, spending a credit, updating a saved record — and nothing outside it.

Active scans need proof per domain

Port scanning and the aggressive vulnerability scanners run only on domains where the account has proved control, by DNS record, a file, or an email at the domain. Proof lasts 90 days and is per domain, not per account.

The ownership gate is worth defending rather than apologizing for. An unauthenticated port scanner aimed at arbitrary third parties is how a platform account gets terminated, and every tenant on it goes with it. Proving control per domain is what keeps the scanner available at all.

What it costs

Free covers the inventory. Paid covers the watching.

Put every tenant domain in on the free plan and run the checks yourself, with no card. Automation, alerts and the reporting surface start at $6.99 a month.

  • Free · $0Unlimited domains, every module on demand, five-minute uptime probe on three domains, one monitored address for breach exposure, KEV and CVE alerts. Ad supported.
  • Starter · $6.99/mo or $69.99/yrNightly re-scan on 25 domains, email alerts, DMARC report ingestion, SEO and accessibility, PDF reports.
  • Pro · $49.99/mo or $499.99/yr100 domains watched, local SEO suite, monthly reports, read-only API and MCP access.
  • Enterprise · $99.99/mo or $999.99/yrHourly cadence, unlimited automation, priority queue, API and MCP write access.

Plans are sold through Apple in-app purchase. DomainGuard is pre-revenue and the iPhone app is in beta, so today the free plan and the TestFlight build are what is actually usable.

Before you roll it out

Questions providers ask.

Is there a multi-tenant view, or one account per client?

One account holds every domain, grouped as personal, business or client, and the client grouping is what separates one tenant from another in the portfolio view. There is no per-tenant login handoff today. If a client wants their own account they create one and add their own domains, and the two accounts are independent.

How does the CVE alerting avoid drowning us in noise?

By re-asking the question against evidence. A KEV or NVD entry that name-matches something on the watchlist is only a catalogue match. DomainGuard then checks it against what scans actually observed on that account — scanner findings citing the CVE, components seen running with a version, service banners from open ports, and the published affected-version ranges — and labels the alert confirmed, possible, not affected, or unconfirmed. Unconfirmed means we have never observed the product, not that you are safe, and the interface says so in those words.

Can we pull this into our own reporting?

Yes, two ways. Pro includes read-only API keys and the MCP server, so an assistant or a script can read the account. Enterprise adds the write scope. PDF reports start at Starter if you would rather hand over a document than build one.

What happens to a tenant we stop managing?

Remove the domain. Nothing is deleted implicitly, and going over an automation cap never makes a domain read-only or drops it from the list — the oldest domains keep the automation and the rest scan on demand.

How much of this is free?

Every health module, on every domain, run whenever you ask: DNS and registrar records, SSL, SPF, DKIM and the DMARC record, uptime, blacklists, security headers, the website scan, the vulnerability scanner, tech detection and the compliance tracker. Free also keeps the five-minute uptime probe on three domains, one monitored address for dark-web exposure, and KEV/CVE alerts. Automation beyond that starts at $6.99 a month.

Start with one tenant

Load a client's domains and see what the first scan says.

The free plan needs no card and does not expire. The iPhone app is in public beta on TestFlight and uses the same account as the web dashboard.