Every check a client's domain needs, run every day.
Monitoring, hosted records, DMARC reports, alerts and a monthly report card, in one place and priced by domain count.
Nine checks, one grade.
Each domain is checked once a day at its own time. Every result comes with a plain-English fix. Checks that don't apply, like HTTPS on a domain with no website, are left out of the score rather than counted against it.
| Check | What we look at | Counts for |
|---|---|---|
| DMARC | Record exists and is valid, the policy (none, quarantine or reject), pct, and where reports go. | 30 points |
| SPF | One valid record, DNS lookups within the limit of 10, and no +all or ?all. | 15 points |
| DKIM | Your selectors, or common ones we look for. Key present and long enough. | 15 points |
| HTTPS certificate | Apex and www: expiry (warns at 21 days, fails at 7), a valid chain and a matching hostname. | 15 points |
| Domain registration | Expiry date from RDAP, including .uk domains. Warns at 30 days, fails at 7. | 10 points |
| Blacklists | Mail server addresses, and sending addresses seen in DMARC reports, against reputable blacklists. | 10 points |
| MTA-STS and TLS-RPT | Both records present, and the policy file served over valid HTTPS. | 5 points |
| Mail servers | MX records resolve and the servers answer on port 25. | Shown, not scored |
| DNS changes | Name servers, website, mail and TXT records compared with the day before, with every change logged. | Shown, not scored |
The part your clients see.
A two-page PDF for each client: overall grade, six-month trend, each domain's grade, what changed this month, the top 3 fixes and how much email passed DMARC. Preview it or send it now from the dashboard.
Starter
- Branding
- Your logo and colours, with a small line crediting us in the footer.
- Sent
- From our address under your agency name. Replies go to you.
- When
- 6am on the 1st of each month.
Agency
- Branding
- Your logo and colours, with a small line crediting us in the footer.
- Sent
- From our address under your agency name. Sending from your own domain is coming soon.
- When
- Any day from the 1st to the 28th, at the hour you pick. Hold them for review if you like.
Pro
- Branding
- Fully unbranded. Nothing on the report card mentions us.
- Sent
- From our address under your agency name. Sending from your own domain is coming soon.
- When
- Any day from the 1st to the 28th, at the hour you pick. Hold them for review if you like.
See everyone sending email as your client.
Each domain gets its own reporting address. Mailbox providers send their daily DMARC and TLS reports there, and we turn them into a list of sending sources and pass rates you can act on.
rua=mailto:[token]@rua.domainhealthhub.comWe keep daily totals only. Report files are deleted once read, and forensic reports are never accepted.
Set records once. Manage them from here after that.
Point a client's email records at us and change them from your dashboard. No more chasing a client for their DNS login each time they add a new mailing tool.
DMARC
Move from none to quarantine to reject in steps, with our report address always included.
SPF with flattening
Includes resolved to IP ranges and re-checked every 6 hours, so you stay under 10 lookups.
DKIM
Delegate _domainkey to our name servers. Import existing keys from DNS and DMARC reports.
MTA-STS
We serve the policy file with its own certificate. Start in testing, then enforce.
TLS-RPT
TLS reports arrive at the same address as DMARC reports and show beside them.
Told once, in the way you prefer.
Choose for each event: an email straight away, a daily digest, or nothing. Add signed webhooks to feed your helpdesk, chat or automation tool.
- Grade droppedA domain's grade got worse than the day before.
- DNS changedName servers, website, mail or TXT records changed.
- Domain expiringA domain expires within 30 days (and again within 7).
- Certificate problemA website certificate expires within 21 days or isn't valid.
- BlacklistedA mail server or sending server is on a blacklist.
- DMARC failures jumpMany more emails failed DMARC yesterday than usual.
{
"id": "…",
"event": "dns_changed",
"created_at": "2026-09-12T06:14:00Z",
"title": "DNS changed on harbourbakery.example",
"summary": "MX records changed.",
"url": "https://domainhealthhub.com/app/…",
"workspace": { "id": "…", "name": "Northgate Digital" },
"client": { "id": "…", "name": "Harbour Bakery" },
"domain": { "id": "…", "name": "harbourbakery.example" },
"details": { … }
}Organised the way an agency works.
Group domains by client, tag them, and invite your team. Import hundreds at once from a CSV with these columns:
domain, client, tags, report_emailBuilt for UK and EU data rules.
- Hosted on our own servers in the EU
- DMARC data kept as daily totals only; report files deleted once read
- Webhook secrets and mail credentials encrypted at rest
- Each workspace's data is kept strictly separate
- Export or delete a workspace's data yourself, at any time
Try every feature free for 28 days.
No card needed.