Everything you need to know
about DomainRisk.io
40 questions across 8 categories - from how the security score works to integrations, reports, billing and privacy. Can't find your answer?Contact us.
Getting Started
What is DomainRisk.io?
Do I need to install anything to get started?
Is there a free trial with no credit card required?
How quickly can I get my first scan result?
What types of domains can I monitor?
Domain Monitoring
How many domains can I monitor at once?
How often are domains automatically scanned?
What happens when I trigger a manual refresh?
Can I set different scan frequencies for different domains?
What happens when I reach my domain monitoring limit?
Security Scoring
How is the domain security score calculated?
What do the different security score ranges mean?
0-20 - Critical exposure. Severe findings requiring immediate action.
21-50 - High exposure. Significant findings that should be addressed promptly.
51-75 - Moderate exposure. Issues present that warrant review and scheduled remediation.
76-100 - Strong security posture. Few or no detected issues. Standard maintenance cadence is appropriate.
What is a security finding?
Why did my domain's security score change between scans?
What are security sub-scores and why do they matter?
How often is the scoring model updated?
Data Sources & Analysis
What WHOIS data is collected and analyzed?
Which DNS record types are monitored?
How is SSL/TLS certificate status analyzed?
What email security checks are performed (SPF, DKIM, DMARC)?
+all. DMARC is checked for presence and enforcement level (none, quarantine or reject). DKIM checks are selector-aware. Crucially, the platform distinguishes between three states: not configured, misconfigured (present but weak) and compliant - avoiding false reassurance from a present-but-ineffective record.How does subdomain attack surface discovery work?
What is a dangling CNAME and why is it dangerous?
Alerts & Integrations
What events trigger an alert?
How do I configure alert thresholds?
Alert sensitivity is configured per domain by selecting a minimum severity level: High, Medium, or Low. When a scan detects one or more findings at or above that level, an alert fires - by email, webhook, or both depending on your setup.
Choosing a higher level (High) reduces noise and ensures only urgent findings reach you. Choosing a lower level (Low) casts a wider net and includes all findings regardless of severity. You can set a different level per domain, so you can be strict on production assets and more permissive on secondary domains.
What does each alert severity level cover - and which should I choose?
The severity threshold filters which finding types trigger an alert. Here is exactly what each level covers:
Alerts fire only for the most severe findings: imminent SSL expiry (<= 7 days), DMARC entirely absent, nameserver change detected, domain expiring within 3 days, dangling CNAME with confirmed takeover risk, missing A record, unauthorized registrar change.
Best for: Production and brand-critical domains. Maximum signal-to-noise ratio - only actionable, urgent issues reach your inbox.
Everything above, plus: SSL expiry <= 30 days, DMARC policy set to none, SPF overly permissive (+all), registrar lock absent, very young domain age, DMARC in quarantine (not reject), new subdomains discovered, security sub-score drops of >= 10 points.
Best for: Most teams. Catches real threats and gradual degradation before they become critical - without excessive noise. Recommended default.
All findings at any severity - including informational observations such as WHOIS privacy enabled, SSL expiry <= 60 days, domain age under 1 year, or minor DNS record additions with no direct threat implication.
Best for: Audit-intensive environments, due-diligence monitoring of newly acquired domains, or testing your alerting pipeline.
Recommended starting point: set severity to Medium. This catches meaningful threats without flooding your inbox, and gives you a baseline you can tighten or relax per domain over time.
How does webhook delivery work?
What data is included in webhook payloads?
Which tools does DomainRisk.io integrate with?
Reports & Exports
What is included in a PDF domain report?
How do CSV exports work?
Can I generate a report at any time, or only after scheduled scans?
How are reports used for compliance and audits?
Plans & Billing
What is the difference between plans?
Can I upgrade or downgrade at any time?
What happens when my free trial ends?
Is there a plan designed for agencies managing multiple clients?
What payment methods are accepted?
Security & Privacy
Is my account and domain data secure?
What data does DomainRisk.io collect about monitored domains?
Can other users or accounts see my monitored domains?
Can I monitor domains I don't own?
Still have questions?
Our team is happy to walk you through any scenario. Or just start free and see the platform answer your questions directly.