PowerAlerts: Real-Time Domain Monitoring and Alerting

PowerAlerts monitors your domains 24/7 and notifies your team the moment something changes – DNS modifications, compliance drops, TLS failures, weak keys, or suspicious email activity. Configure custom rules across 5 alert categories, set severity levels, and deliver notifications via email or webhook.

3
Live alerts Live
DNS record modified domain1.com · DKIM selector removed
Critical
Failure rate threshold hit domain2.com · 12% in last 24h
Warning
Forensic report received domain3.com · RUF sample flagged
New
DKIM key expiring soon domain4.com · 10 days remaining
Info
99.9% Alerts delivered

Alert Categories

DNS Alerts configuration screenshot

DNS Alerts

What it does: Monitors changes to your email authentication DNS records and validation failures in real time.

Key capabilities
  • Notifies you the moment a record is added, modified, or removed
  • Notifies as soon as authentication validation fails
  • Covers DMARC, SPF, DKIM, BIMI, MTA-STS, TLS-RPT, A, MX, and NS records
  • Filter by event type, event trigger, and severity
  • Combine multiple conditions into a single alert configuration
Example: "Trigger a critical alert when my DMARC validation fails for domain domain1.com."
Threshold Alerts configuration screenshot

Threshold Alerts

What it does: Triggers when a compliance metric you define exceeds a custom limit, so you catch drift before it becomes a delivery problem.

Key capabilities
  • Set thresholds by absolute count or percentage
  • Define a time window (e.g., 5 failures in 1 day, or >2% failure rate over 7 days)
  • Choose aggregated (across all domains) or per-domain tracking
  • A live summary panel translates your rules into plain English before you save
Example: "Trigger critical alert if the percentage of sent emails is greater than (>) 10% in the last 1 day from all emails where: DMARC compliance failed evaluation per domain for domain1.com, domain2.com, and domain3.com."
Forensic Alerts (DMARC Failure/RUF) screenshot

Forensic Alerts (DMARC Failure/RUF)

What it does: Sends a real-time alert every time a DMARC failure (RUF) report arrives, so impersonation attempts don't sit unnoticed.

Key capabilities
  • Preserves all RUF data for investigation, including feedback and mail headers
  • Structured email notifications plus concise webhook payloads
  • User-selectable severity per alert
  • Automatic domain support, with optional manual control
Example: "Trigger an alert when a Failure (RUF) report is received for the selected domain(s) based on DMARC record configurations."
TLS-RPT Threshold Alerts screenshot

TLS-RPT Threshold Alerts

What it does: Monitors TLS delivery failures so you can catch encryption issues before they start blocking outbound mail.

Key capabilities
  • Set limits by failure count or percentage over a custom time window
  • Track passed or failed delivery states
  • Notification emails include the exact failure reason
  • Works alongside existing DNS-based TLS alerts as an additive, not a replacement
Example: "Trigger informational alert if the count of sent emails is greater than (>) 10 in the last 5 days from forensic emails evaluated per domain for domain1.com."
Security Health Alerts screenshot

Security Health Alerts

What it does: Proactively monitors background configuration risks that don't appear in active email traffic until they become problems.

Key capabilities
  • DKIM 1024-bit weak key detection automatically flags domains still using legacy key sizes
  • BIMI certificate expiration countdown — get alerted 90, 60, 30, or 10 days before VMC expiry
  • Multi-severity rules within a single configuration (e.g., Informational at 90 days, Critical at 10 days)
  • Dedicated log tab for security health events
Example: "Trigger a critical alert when an active DKIM key with a 1024-bit key size is detected."

Flexible notification delivery

Applies across all 5 alert categories.

Multi-channel delivery

Send alerts via email and webhooks.

Multiple recipients

Add multiple recipients and delivery channels per alert.

Notification groups

Route different alert types to different teams.

Centralized management

Manage every alert and channel from one configuration panel.

Incidents Coming soon

A new Incidents tab will consolidate and track alert-related events across all categories in one place, giving you a single view of active, acknowledged, and resolved incidents. Currently rolling out.

Active Acknowledged Resolved

How to set up PowerAlerts

1 Choose your monitoring entities screenshot

Choose your monitoring entities (domains or domain groups)

2 Select your alert type screenshot

Select your alert type (DNS, Threshold, Forensic, TLS-RPT, Security Health)

3 Set conditions screenshot

Set conditions (event types, triggers, severity levels, thresholds)

4 Choose notification groups and save screenshot

Choose notification groups and save

Monitor Your Domains with PowerAlerts