The domain record keeps itself honest.
Tick the checks you want on a Domain/DNS document and the worker runs them on their own clocks: who is answering DNS, when the certificate runs out, what the registry says about expiry, whether email is protected, and what the client's website says its brand looks like. When something changes, you hear about it once.
Five lookups, each on its own clock.
A, AAAA, MX, NS, CNAME, and TXT one per line with what each is for named: SPF, DMARC, DKIM, and the verification tokens of Google, Microsoft 365, Atlassian and the rest. Who is answering is compared with the DNS Host field, so a migration that half-happened shows.
The certificate on the domain: issuer, what it covers, whether the chain is trusted, and how long it has left.
The registry's own registration record: registrar, creation, expiry, transfer lock. Offered to the Registrar and Expiration fields with a Use this button.
Whether SPF, DMARC and DKIM are published and what DMARC enforces, as a table of check, finding, and the record itself. DMARC hosted elsewhere by CNAME is followed. A record can name its own DKIM selectors.
Reads the site's front page the safe way and keeps its title, theme color, icons and manifest. Nothing is applied by itself: the company's edit page lists what every website publishes and an administrator picks one to become the company's logo and accent.

Set once. Override where it matters.
How often each kind runs is a policy the instance sets, a company may change for its records, and a record may change for itself. Press Check now whenever you like; the schedule carries on regardless.
Admin → Settings sets what everything follows: DNS and the certificate daily, registration and mail posture weekly, a 30-day certificate notice. Zero turns a kind off everywhere.
A company can say otherwise for its records on its edit page: slower for a client who never changes anything, off for a kind nobody cares about there.
A record can set its own timings, say its certificate renews on its own so its expiry is no cause for alarm, or opt out of the worker and stay manual. A new record states nothing and follows its company.
Changes, not noise.
A run found something different from the run before: the name servers moved, the domain points somewhere new, mail is handled by someone else, a new certificate, a registrar change, DMARC gone. Each change is named with what it was and what it is now. Only facts known on both sides are compared, so a lookup that failed once is not a change.
A certificate inside its notice, or a registration within 60 days. Once per expiry date, so a weekly check does not nag weekly. A certificate marked as renewing itself is left alone unless the record asks for a notice anyway.
What the last check of every domain record flagged, across every company you can see. The same facts the webhooks carry, so nobody has to subscribe to one to find out.
# domain.changed { "event": "domain.changed", "data": { "domain": "example.com", "changes": [ { "what": "ns", "from": "ns1.godaddy.com, ns2.godaddy.com", "to": "dale.ns.cloudflare.com, serena.ns.cloudflare.com" }, { "what": "dmarc", "from": "reject", "to": "none" } ] } }
The client's site already knows its colors.
The fifth check reads the website's front page the way the knowledge base crawler reads a page and keeps what it publishes about itself: title, theme color, icons, manifest. On the company's edit page, Use as company theme makes that icon the logo and that color the accent, so the client's pages in Trove KB look like the client. With several websites, the one chosen is remembered.

Offered, never applied.
- →What it finds is offered, never applied. Accepting a registrar, an expiry date, a DNS host, or a website's look is an ordinary edit, with a revision and an audit entry.
- →A domain is typed by a person, so a lookup is untrusted: names are resolved first, anything resolving inside your network is refused, and the connection is made to the address that was checked. Icons from a client's site are fetched the same way, sniffed, and served through the record's own route, never hotlinked.
- →The worker runs only the kinds whose time has come, oldest first, within the same budget a person's clicks share. A record whose domain is empty or malformed is told so and put off until next time rather than retried every pass.
- →Reading a page costs no lookups. Every section shows its own age, and a run replaces only the sections it fetched.
Stop finding out from the client.
Expiry, certificate, mail posture, and name servers watched for you, announced once, kept in the record.