Know what changed across your clients' website and email settings.
Every six hours, Sequrit observes each client domain from the public internet and keeps a dated record of DNS, SPF, DKIM, DMARC, certificate, redirect and security-header changes. A digest only when something happened. Monthly reports that carry your brand and nothing else.
No installation. No access to client systems. Cancel any time; full refund of the first invoice within 14 days.
acme-bakery · ip4 192.0.2.128/25 via spf.marketingtool
acme-bakery · frame-ancestors dropped on redeploy
acme-bakery · "moved to Bigmail", marked by the agency
shop.harbour-goods · renew before 12 Sep
bluefin-legal · after 25 minutes
bluefin-legal · security headers
Four steps, then it runs.
- Add a client domain and prove you manage it. A DNS TXT record or a file on the site. Nothing is checked until you do.
- Sequrit observes. Every six hours: DNS records, DNSSEC and dangling aliases; SPF expanded to the actual permitted senders, DKIM selectors, DMARC with inheritance, MTA-STS, TLS-RPT and BIMI; the certificate and accepted TLS versions; the redirect, eight security headers and security.txt; domain expiry, registrar and transfer lock at the registry. Every five minutes: is the site reachable.
- Changes are confirmed before you hear about them. A second observation at least fifteen minutes later must agree. Flapping records and rotating nonces stay quiet.
- You get the record, and a next step. Every item carries a plain-English "what to do". A daily digest on days something changed, incidents the moment they are confirmed, in email, Slack or Teams, and a monthly report per domain with your logo, colour and footer.
Three things the usual monitors do not do.
No vendor branding on reports
Your logo, name, colour and footer. Nothing of ours, not even a footer line. Send the report to your client as your own work.
Security headers, per directive
Strict-Transport-Security, Content-Security-Policy, Permissions-Policy and five more, parsed and diffed. A removed frame-ancestors is a review change. A rotated nonce is silence.
Email authentication, properly
SPF expanded within the lookup limit so a new sender is named with the include that added it. DKIM selectors watched. DMARC evaluated with inheritance; a changed report address is flagged.
The registration, not just the records
Domain expiry with 60, 30, 14 and 7-day actions. Registrar changes, a removed transfer lock and registry nameserver changes are review changes, because that is how a domain walks away.
Reachability, confirmed
Every five minutes. Two consecutive failures open an incident and notify you at once; the monthly report shows the reachable percentage. One vantage point, stated as such.
A next step on every line
Each change, action and note carries an approved plain-English "what to do", so a client can act without a glossary and you do not have to write it.
What it is, and is not.
- A dated record of externally observable configuration
- Confirmed changes, with before and after values
- Coverage gaps shown as gaps, never as "all fine"
- Reports your clients can read without a glossary
- Not uptime monitoring
- Not a vulnerability scan or penetration test
- Not email deliverability testing
- Not a compliance certificate, and not remediation
It records what was observed and when. You decide what to do.
One plan.
- Up to 25 verified domains
- Checks every six hours
- Daily digest when something changed
- Monthly white-label reports
- Cancel any time · first invoice refundable within 14 days