Skip to content

Changes and alerts

This page answers two questions: what changed in this zone, and do I want to hear about it the next time it happens.

Domains → your domain → Monitoring & protection → Changes, direct address: dash.regfish.com/my/domains/<tld>/<sld>/alerts

The change history with severity rating and the alert settingsThe change history with severity rating and the alert settings

Every change appears with type, record and timestamp. Entries are rated, and the rating follows the question of what an attacker could do with it:

  • Critical covers changes to nameservers, MX, SPF and DMARC. Bend those and mail can be redirected or delivery checks defeated.
  • Medium is the rest of the security adjacent records.
  • Info is ordinary record traffic.

The sign in front of the name tells you the kind: plus created, minus deleted, plusminus changed.

Automatic alerts are off by default. That is the most important sentence on this page: the history is always kept, but you only get told once you switch it on.

When switching on you pick the threshold: from critical, from medium, or all. Notification goes by email, by default to your account address; further addresses can be added.

Critical is the sensible threshold for domains where little ever happens, and all only where you want to trace every change. Anyone writing records regularly through the API or DynDNS will generate a lot of mail at all.

This page watches the contents of the zone. The domain guardian watches the domain itself: expiry, auto renewal, transfer lock and auth codes. Together they cover the two ways a domain gets away from you.