Getting started

What DomainGuard does (and does not do)

The checks DomainGuard runs on a domain, the rules every result follows, and the things it deliberately never does.

Updated · 3 min read

DomainGuard is a monitoring service from NHM LLC (330 Hosting & Consulting) in Northeast Ohio. It answers five questions about every domain you put in it: what needs my attention, what changed, was the change expected, what should I do next, and, when something costs credits, exactly what I will get and what it will deduct.

What it checks

Area What is read Where to learn more
Domain DNS records, nameservers, DNSSEC, the registrar's RDAP record and the registration expiry date Domain health scan
Certificate Issuer, expiry, chain trust and HSTS, from certificate transparency logs and the app's own handshake Certificate monitoring
Email SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT and BIMI, with the record to publish when one is wrong SPF, DKIM and DMARC checks
Website Security headers, cookies, exposed files, technology, blocklists, on-page SEO, accessibility and mobile readiness Security checkup
Uptime An HTTP probe every five minutes Uptime monitoring
Exposure Vulnerability scanners, open ports, the software your site runs and the KEV/CVE advisories against it Exposure scans
Impostors Lookalike domains somebody else registered, and whether they can receive mail Lookalike check
Breaches Mailboxes on your domain that appear in breach data Mailbox exposure monitoring

Rules every result follows

  • Status is a word, never a colour alone. Healthy, Review or Action on a domain; High, Medium or Low on a finding; Pass, Review or Fail on a record.
  • Nothing is invented. Anything the product has not measured shows as a dash, never a zero. A scan that is still running never paints a result.
  • "Nothing found" is not "you are safe." An impostor check always says how many variations it tried. A KEV entry that merely name-matches your software is labelled a name match until a scan confirms it.
  • Every plan is told what is wrong and how to fix it. The finding, why it matters, and the steps are part of the product on Free. What Enterprise buys with Ask NHM is a person doing it with you.
  • Every finding ends in a next action. For email authentication that is the exact TXT record with a Copy button.

What it deliberately does not do

  • It does not change DNS, renew domains, edit websites, or file registrar complaints. For a lookalike it assembles the evidence pack; the filing is yours.
  • It does not filter inbound mail or read mailboxes. DMARC aggregate reports carry counts and sending sources, never message content.
  • It does not run a malware scanner or a Lighthouse audit. SEO and accessibility are measured from the page's own HTML and axe; there is no speed score.
  • It does not install an agent, hold DNS credentials, or scan anything active without proof you control a domain on the account. See Scan clearance.
  • It does not offer an SLA, a takedown service, or dedicated infrastructure.

Where the two surfaces differ

The web dashboard is the full platform. The iOS app is where alerts arrive, where a domain is checked from a phone, and where plans are bought (Apple in-app purchase is the only storefront). Compliance records, PDF reports, two-factor setup and API key policy detail open the web dashboard with your session from inside the app.

Still stuck?

Ask the people who run the scanner.

Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.