Changes and alerts
This page answers two questions: what changed in this zone, and do I want to hear about it the next time it happens.
Where to find it
Section titled “Where to find it”Domains → your domain → Monitoring & protection → Changes, direct address:
dash.regfish.com/my/domains/<tld>/<sld>/alerts


The history
Section titled “The history”Every change appears with type, record and timestamp. Entries are rated, and the rating follows the question of what an attacker could do with it:
- Critical covers changes to nameservers, MX, SPF and DMARC. Bend those and mail can be redirected or delivery checks defeated.
- Medium is the rest of the security adjacent records.
- Info is ordinary record traffic.
The sign in front of the name tells you the kind: plus created, minus deleted, plusminus changed.
Turning alerts on
Section titled “Turning alerts on”Automatic alerts are off by default. That is the most important sentence on this page: the history is always kept, but you only get told once you switch it on.
When switching on you pick the threshold: from critical, from medium, or all. Notification goes by email, by default to your account address; further addresses can be added.
Critical is the sensible threshold for domains where little ever happens, and all only where you want to trace every change. Anyone writing records regularly through the API or DynDNS will generate a lot of mail at all.
How this differs from the domain guardian
Section titled “How this differs from the domain guardian”This page watches the contents of the zone. The domain guardian watches the domain itself: expiry, auto renewal, transfer lock and auth codes. Together they cover the two ways a domain gets away from you.