Platform · Coming soon · Early access open

Every domain you own,
watched by one intelligent layer.

SSL, DNS, WHOIS, DMARC, blacklists, security headers — one platform, one alert stream, one AI fix. Purpose-built for teams that own more than one domain.

1 free domain forever No credit card
8
capabilities per domain
~130
blacklists watched
1h
DNS drift cadence
AI
fix for every alert

Domains break silently. You find out from customers.

!
A cert expires at 2am.
Auto-renew failed silently three months ago. The registrar's warning email went to an ex-employee's inbox. Checkout goes red in every browser.
Δ
A DNS record disappears.
Someone deleted the MX during a "quick cleanup". Mail dies for six hours before anyone notices — no audit log at the registrar, no alert anywhere.
Your DMARC is at p=none.
Which means spoofers can still send as you. Gmail flags your legitimate mail. The path to p=reject is a five-stage rollout you've been meaning to figure out for a year.

DomainScan Platform is one watch layer across everything a domain can go wrong at — SSL certificate expiry, DNS record drift, WHOIS hijacks, DMARC misconfiguration, blacklist listings, missing security headers, lookalike domains. Every alert ships with an AI-generated, paste-ready fix tailored to your DNS provider and registrar. If you already stitch together TrackSSL, EasyDMARC, UptimeRobot SSL, and MXToolbox — this replaces all four.

Eight capabilities. One bundle. One alert stream.

Every capability runs on the same shared probe substrate — one TLS handshake, one WHOIS query, one authoritative DNS resolution per domain — so cost stays flat as your portfolio grows from 1 to 1,000 domains. Cadence auto-escalates near deadlines (SSL expiring in 3 days? We recheck hourly). Full engine details in our learning hub.

6h SSL / TLS

Certificate lifecycle

Warn at 30 / 14 / 7 / 3 / 1 days. Detect unexpected rotations. Validate the whole chain — not just the leaf.

  • Expiry countdowns
  • Rotation classification
  • Chain + SAN validation
  • Auto-renew coverage
24h Domain Expiry

Registrar-agnostic renewal watch

Miss the registrar reminder in spam? We won't. Auto-renew failure inference and TLD-aware grace-period countdown.

  • 90 / 60 / 30 / 14 / 7 / 3 / 1d thresholds
  • Auto-renew miss detection
  • Grace-period timeline
  • Deep-link to renew
1h DNS Drift

Every record, continuous diff

Someone added a verify TXT? Someone deleted your MX? You know within the hour, with an AI verdict on intent.

  • A · AAAA · MX · TXT · NS · CNAME · CAA · SRV · SOA
  • Dangling CNAME takeover detection
  • Per-record severity
  • Maintenance windows
daily WHOIS

Registrant + hijack correlator

Registrar swap + NS change + transfer-lock removal within hours = hijack pattern. We correlate DNS + WHOIS in one timeline.

  • Field-level changelog
  • Lock-status tracking
  • Combined DNS + WHOIS timeline
  • Hijack-pattern alert
live DMARC Journey

p=none → p=reject, coached

The static checker is table stakes. The 5-stage enforcement journey with readiness gates is the moat.

  • RUA report ingestion
  • SPF 10-lookup analyzer
  • DKIM key age audit
  • Stage-by-stage advance gates
3h Blacklist

RBL + reputation, watched

~130 blacklists + Google Safe Browsing + PhishTank. Delisting requests auto-repolled hourly.

  • Mail-IP auto-discovery from DMARC
  • Delisting workflow
  • Safe Browsing + PhishTank
  • AI cause analysis
12h Security Headers

HSTS, CSP, and the rest

Grade your site's HTTP security posture. Alert when a header regresses in a deploy.

  • A+ → F grading
  • Header regression alerts
  • CSP diff view
  • Best-practice callouts
weekly Typosquat

Lookalike domains, surfaced

Homoglyphs, TLD swaps, brand+login combos. We surface, you decide. Not takedown — awareness that's honest about scope.

  • 500 permutations per domain
  • Screenshot side-by-side
  • AI verdict per finding
  • One-click report to Safe Browsing

From nothing to actively watched, in 90 seconds.

1
Add a domain
Paste one, upload a CSV, or import from your registrar. We pre-flight against your plan quota and run a live six-check scan while you decide what to watch.
→ probes fire in parallel · results in ~8s
2
Choose what we watch
Eight toggles, per-capability cadence, per-severity alert routing. Recommended defaults for every plan — customize on Pro+.
→ SSL daily · DNS hourly · Blacklist every 3h · DMARC live
3
Get fixes, not alerts
Every event ships with a Prism AI remediation card — provider-aware, paste-ready, risk-tagged. No googling, no guessing, no bouncing between docs.
→ ack / resolve / snooze in one click

Not "what's wrong".
Here's the exact fix.

Prism knows your stack — your DNS provider, your registrar, your cert CA, your mail provider, your CDN — because we already probe for it. Every alert ships with a paste-ready remediation tailored to your stack, not a generic knowledge-base article.

  • Risk-tagged: safe · caution · destructive
  • Provider tabs — Cloudflare, Route53, GoDaddy, generic
  • Copyable DNS records + CLI commands, one-click
  • Lazy generation + 7-day cache — no wasted tokens
◆ CAUTION acme.io · DMARC
Your DMARC is at p=none. Move to p=quarantine pct=10 to start collecting enforcement signal.
1. In your Cloudflare DNS, edit the _dmarc TXT record.
DNS · TXT _dmarc.acme.io
v=DMARC1; p=quarantine; pct=10; rua=mailto:[email protected]; adkim=r; aspf=r;
2. Wait 24h, then check the aggregate reports feed at /platform/dmarc/acme.io/reports.
1. In Route53 → hosted zone → _dmarc TXT record, replace value:
DNS · TXT _dmarc.acme.io
"v=DMARC1; p=quarantine; pct=10; rua=mailto:[email protected]; adkim=r; aspf=r;"
1. Domains → DNS → find the TXT record where host = _dmarc → Edit → paste:
DNS · TXT _dmarc
v=DMARC1; p=quarantine; pct=10; rua=mailto:[email protected]
Publish this TXT record at _dmarc.acme.io:
DNS · TXT
v=DMARC1; p=quarantine; pct=10; rua=mailto:[email protected]
~3 min · quarantine 10% of unsigned mail Helpful? 👍 👎

The features that make this a platform, not a tool.

DMARC ENFORCEMENT

A five-stage journey, gated by real readiness.

Competitors show you a dashboard. We show you the path — with gates. You can't advance to p=quarantine until the readiness criteria pass: seven days of RUA data, sub-5% unknown senders, 95% pass rate for known senders. Move too fast, break your mail. We won't let you.

1
Discovery
p=none
2
Visibility
senders mapped
3
Alignment
≥95% pass
4
Quarantine
pct=10 → 100
5
Reject
pct=100
Readiness gate for stage 4:
  • ≥7 days of RUA data
  • <5% unknown senders (2%)
  • ≥95% pass on known senders (91% · 3 senders below)
HIJACK CORRELATOR

Every domain compromise leaves the same footprint.

Registrar swap. NS records change. Transfer-lock removed. All within 18 hours. Three separate events at three separate tools — or one WHOIS_LIKELY_HIJACK alert at ours, pinned red, with the whole attack chain in one timeline.

14:00 UTC WHOIS registrar changed: Namecheap → SuspRegistrar
15:42 UTC WHOIS transfer-lock removed
17:08 UTC DNS NS changed: ns.namecheap → ns.attacker
17:12 UTC DNS MX changed
17:15 UTC CRIT WHOIS_LIKELY_HIJACK — immediate action required
CHAIN INTEGRITY

Most monitors check the leaf. We probe the whole chain.

Missing intermediate, expired intermediate, weak signature algorithm, wrong SAN set — every failure mode surfaced with its exact position in the chain. Because when a cert breaks, it's rarely the leaf.

acme.io
Leaf · your certificate · expires in 74 days
R3 (Let's Encrypt)
Intermediate · valid
ISRG Root X1
Root · trusted

One bundle replaces four point tools.

What you'd stitch together today across TrackSSL + EasyDMARC + UptimeRobot + MXToolbox — plus the DNS drift and hijack detection none of them offer — in one platform, one bill, one dashboard. See detailed side-by-side comparisons with every major domain-monitoring vendor.

Capability
DomainScan
TrackSSL EasyDMARC UptimeRobot MXToolbox
SSL expiry + rotation × basic basic
DNS drift + AI verdict × × × ×
DMARC enforcement journey × partial × ×
WHOIS hijack correlator × × × ×
Blacklist + delisting flow × × ×
AI-generated paste-ready fix ✓ Prism × × × ×
One bundle, one bill × × × ×
Agency / white-label × ×

Priced for teams that own more than one domain.

Every plan includes the whole bundle — SSL, DNS, WHOIS, DMARC, blacklist, security headers, typosquat. Cadence and channels scale up. AI fix quota scales up. Agency layer unlocks white-label + multi-client.

Free
$0/mo
1 domains weekly cadence
  • 1 domain
  • Weekly cadence
  • Email alerts
  • 1 AI fix / month
Start free →
Starter
$5/mo
or $48/yr
5 domains daily cadence
  • 5 domains
  • Daily cadence
  • Email alerts
  • 100 AI fixes / month
Start with Starter →
Recommended
Pro
$18/mo
or $172/yr
15 domains hourly cadence
  • 15 domains
  • Hourly on critical
  • Email + Slack + Webhook
  • 500 AI fixes / month
  • DMARC RUA ingestion
  • Custom thresholds
Upgrade to Pro →
Business
$82/mo
or $787/yr
50 domains hourly cadence
  • 50 domains
  • All channels + PagerDuty
  • Escalation policies
  • 3,000 AI fixes / month
  • Audit log 365d
  • DMARC RUF ingestion
Talk to sales →
Agency
$179/mo
or $1,718/yr
200+ domains hourly cadence
  • 200+ domains (blocks of 50/100/250/500)
  • Multi-client workspaces
  • White-label reports
  • Per-client viewer access
  • Custom monitor templates
  • Audit-ready compliance reports
Talk to sales →
TRY IT · NO SIGNUP

Grade any domain in 10 seconds.

Public shareable link. Full transparency on methodology. Fair letter grades, no vanity inflation. Then decide if you want us to keep watching it.

Grade a domain →
A
cloudflare.com
SSL 96 · DNS 92 · DMARC 88 · Blacklist 100 · Expiry 100 · Typosquat 94

Frequently asked questions about DomainScan Platform

Do you edit our DNS? +
Never. We surface every problem with a paste-ready record. You paste it into your DNS provider on your terms. The one exception is optional provider-API integration (Cloudflare / Route53) on Business+, and even there, every change requires typed confirmation.
Do you take down typosquat / lookalike domains? +
No. Takedown is legal-heavy and out of scope. What we do is surface every lookalike, score its risk, and hand you pre-filled report links for Google Safe Browsing, PhishTank, and the offending registrar's abuse contact.
How do you avoid alert fatigue? +
24-hour deduplication on identical events. Digest mode for low-severity. Snooze windows for planned changes. Threshold customization on Pro+. Every alert has an ack / resolve / snooze button — and Prism generates the fix inline, so triage is one click, not fifty.
What about multi-instance / high-availability? +
The scheduler is horizontally scalable — atomic MongoDB lease claims mean N PM2 instances across M servers cooperate without a Redis queue. Every probe has a 90s lease; if a worker dies mid-probe, another picks it up automatically.
Data retention? +
Snapshots and events retained 7d Free · 30d Starter · 90d Pro · 365d Business · 365d+ Agency. Every plan gets a full audit trail within its window.
Can I bring my own AI key? +
Not yet. Prism runs on Vertex AI (Gemini 2.5) with model tier tied to your plan — Flash-Lite on Free/Starter, Flash on Pro, Pro on Business+. Prompt caching + Zod-validated output keeps cost bounded per fix.

Built for the people who catch the outage first.

Solo founder

You own five domains: your main site, your app, your marketing subdomain, a legacy redirect, and the one you registered for a side project. You need something that tells you when SSL is about to expire or DMARC starts failing, without setting up five different tools. Free + Starter ($5/mo) covers you.

Growth-stage SaaS

You've hit Gmail's Feb-2024 sender rules. You need DMARC at p=reject, no exceptions. You need to know the moment your primary or CDN cert rotates unexpectedly. Pro ($18/mo) unlocks per-monitor routing, DMARC RUA ingestion, and custom alert thresholds.

MSP / Agency

You manage 60 client domains. You need a branded monthly report per client, per-client access scopes for their internal team, and pricing that isn't "call for a quote". Agency ($179/mo) starts at 200 domains and stacks in blocks up to 500 more.

Sysadmin / SRE

You want authoritative-DNS drift monitoring (not resolver-side), a hijack-pattern correlator that joins WHOIS with DNS in one timeline, and webhooks that don't rot silently. Pro or Business ($82/mo) — depending on channel needs.

Your first domain is free. Forever.

Add one. See how much we catch. Add more when you're convinced. Cancel any time — we won't ask why.