Monitoring

Monitor SPF, DKIM and DMARC continuously

Mail lands in spam and nobody knows since when. Usually a change is behind it: a new newsletter tool, an SPF record with eleven lookups, DMARC back from reject to none. DomainWarn checks the email records of all client domains regularly and reports the change, not the complaint.

Every feature, no credit card, cancel monthly.

  • Hosted in Germany
  • GDPR compliant, DPA on request
  • Proper VAT invoice
  • Cancel monthly

What the alerts look like

  • SPF of client.com invalid: 12 DNS lookups, receivers evaluate permerror
  • DMARC policy of client.com weakened: p=reject → p=none
  • DKIM selector selector1 of client.com no longer resolves
  • MX of client.com changed: new mail provider since 09:12 today
  • Mail server IP 203.0.113.10 of client.com listed on Spamhaus ZEN

The records that decide delivery

Since Google, Yahoo and Microsoft require SPF, DKIM and DMARC from senders, the DNS zone decides about the inbox. The records are set quickly and break just as quickly: an extra include blows the lookup limit, a hosting move loses the DKIM key, someone sets DMARC to none for testing and forgets.

DomainWarn checks the records in the interval of the plan, evaluates them with the same rules as the free tools and compares them with the last state. Alerts arise on errors and on changes, each with before and after.

What is monitored

  • SPF: syntax, lookup count, qualifier, multiple records, changes to the mechanisms.
  • DKIM: resolvability and key length of the configured selectors, revoked keys.
  • DMARC: existence, policy, pct, reporting addresses, weakening of the policy.
  • MX: mail servers, priority, resolvability, provider change.
  • MTA-STS and TLS-RPT: policy file reachable, mode, MX hosts covered.
  • Blacklists: mail server and website IPs against Spamhaus, Spamcop, Barracuda and more.

DMARC monitoring without a report service

DMARC report services parse the XML reports and show who sends on behalf of the domain. That is valuable for rolling out p=reject. DomainWarn adds the other side: it monitors the record itself. The most common damage is not an unknown sender but a policy someone rolled back, or a record lost during a DNS migration.

For MSPs and agencies with many client domains

Clients, domains and notifications are separate: a client can get their own Slack channel, the morning digest sums up everything. New client domains can be imported, the monitors are created automatically. On the Agency plan a domain costs under 50 cents a month, a fraction of one hour of troubleshooting a spam problem.

Frequently asked questions

Does DomainWarn parse DMARC reports?
No, DomainWarn monitors the records and their changes. A report service is the right tool for parsing reports; the two complement each other.
Which DKIM selectors are checked?
Those detected when adding the domain and any you configure per domain. The check alerts when a selector no longer resolves or the key becomes too short.
How fast is a weakened DMARC policy noticed?
Within the check interval of the plan: SPF and DMARC are checked hourly on Agency and every three hours on Freelancer. The change is reported as critical.

Who DomainWarn is for

Web agencies, freelancers, web developers and IT service providers who look after many client domains and want to know when a client switches hosting, someone breaks the SPF record or a certificate expires. No server monitoring, no agents, no configuration at the client.

Try 14 days for free

More monitoring topics: DNS monitoring · SSL monitoring · Domain monitoring