All monitor types
Security checks

Domain Security monitoring

Who controls the domain, and whether that changed: registrar state, the DNS control plane, email authentication and reputation.

Every Domain Security monitor runs on the same spine as the rest of PulseTrace — probed from each region you pick, scored on every check, and streamed into one timeline where incidents open on their own, anomalies surface without a threshold to guess, and reports are generated for you. Point it at a target, choose an interval, and it's watched.

What each check verifies

  • Registrar / registration state
  • DNS control plane and nameservers
  • Email authentication — SPF, DKIM, DMARC
  • Domain reputation signals

The panel on the right is the real create-monitor screen — it fills itself in with a Domain Security example, exactly what you'd type.

When to use it

For every apex domain you own that matters: the product domain, the mail domain, customer-facing brands. It watches the registry record (expiry, registrar, transfer lock, nameservers), DNSSEC and SPF/DKIM/DMARC — the things that don't cause an outage today but cause a disaster in six months.

What an alert looks like

example.com domain grade dropped B → D — DMARC policy changed from quarantine to none; registrar transfer lock removed.

Questions about Domain Security monitoring

Do I need to give it registrar credentials?
No — everything comes from public sources: RDAP for the registry record, DNS for DNSSEC and the mail-authentication records.
What counts as a change?
Any difference in the registry record (expiry, status flags, registrar, nameservers), DNSSEC validation state, or the SPF/DKIM/DMARC records — each opens a change event with before and after.