Know when your company email setup changes before it becomes a problem
ConfiguRadar watches the email configuration behind your domains and alerts you when something important changes. Those settings decide whether email providers can verify your messages, whether someone else can send as your company, and whether mail to you travels securely. Start with a free check of any domain, and see the exact settings behind every result.
- No account needed
- Usually takes a few seconds
- Reads only public settings
- Your report stays private
How it works
-
Check your domain
Type in your company domain. Nothing to install, no account, no access to your systems needed.
-
Read what we found in plain English
Every finding says what we saw, why it matters, and what to look at. The exact settings are there too if you or your IT provider want them.
-
Keep watching it
Settings drift as your company adds tools and changes providers. Monitoring tells you when something important changes instead of you finding out later.
A check tells you about today
Settings do not stay still. Someone connects a new tool, a provider changes an address, a record gets edited during unrelated work. The setup that passed this morning can be wrong by the end of the month, and nothing announces it. Monitoring is the part that keeps looking and tells you when something meaningful moves.
| Domain | Status | |
|---|---|---|
| acme.com | Healthy | Last checked 4 minutes ago |
| clientone.example | Approved senders changed SPF | Needs review |
| clienttwo.example | New sending service appeared SPF | HubSpot |
| clientthree.example | Impersonation protection changed DMARC | Needs review |
| clientfour.example | Healthy | Last checked 11 minutes ago |
What monitoring catches
These are the kinds of change monitoring is designed to detect. They are examples of change types rather than events from any real domain.
The list of approved senders changed
SPFA service was added or removed, or the list went over the limit receiving servers allow.
A new sending service appeared
SPF, DKIMSomething started sending as the domain that was not there at the last check.
Impersonation protection was weakened
DMARCA policy moved from rejecting failures back to watching them, or disappeared entirely.
Message signing changed
DKIMA signing key was replaced, withdrawn, or switched into test mode.
Mail routing changed
MXIncoming mail is being directed somewhere different from before.
Secure delivery policy changed
MTA-STSA policy became unreachable, dropped out of enforcing mode, or stopped covering a live mail server.
Delivery problem reporting stopped
TLS-RPTThe record that asks other servers to report failures was removed or broken.
Managing email settings for multiple clients?
An IT provider or email consultant can be responsible for dozens or hundreds of client domains. Each client runs a different combination of Microsoft 365 or Google Workspace, a marketing platform, a support desk, a billing system, a transactional email provider, and their own DNS host. Every one of those touches the settings that decide whether a client's mail can be verified.
Running a single check on a single domain is easy. The actual job is knowing when any client's setup changes, on the day it changes, without opening thirty tabs to find out.
- Every client domain in one place
- Which domains are healthy right now
- Which domains changed, and what changed
- Alerts when a setting that matters moves
- History you can point at when a client asks what happened
- Clients kept in separate workspaces
- Sending services visible across the whole book
- Access for the rest of your team
Monitoring is not built yet, so none of this is available to buy today. Planned pricing is published here.
Why email settings break
Most companies send email through several systems at once. A typical setup might include Google Workspace or Microsoft 365 for staff email, a marketing platform, a support desk, and whatever your product or billing system uses to send receipts. Every one of those needs to be listed in your domain settings, and those settings are edited by hand.
A new tool is connected
Someone signs up for a marketing or support platform and starts sending. Nobody updates the domain settings, so receiving servers cannot confirm those messages are really from you.
A DNS edit breaks something else
A record is added for one purpose and quietly replaces or duplicates an existing one. Nothing looks wrong at the time.
The sender list outgrows its limit
There is a hard limit on how many services your sender list can reference. Add one tool too many and sender checks stop working for all of them at once.
A sending service is set up wrong
A legitimate tool is connected but not authorised properly, so its messages fail the same checks that a fake message would.
Impersonation protection is missing or weak
No instruction is published telling receiving servers what to do when a message claims to be from your company but fails the checks, so each provider decides for itself.
Something that worked stops working
A certificate expires, a website moves, a provider changes an address. The setup that was correct last quarter is quietly broken now and nothing announces it.
What we check
Each of these has a technical name that you may or may not care about. We lead with what it actually does and keep the protocol name next to it.
| What it does | What it answers | Technical name |
|---|---|---|
| Sending identity | Which services are allowed to send email using your domain? | SPF |
| Message authenticity | Can receiving servers verify a message really came from your systems? | DKIM |
| Impersonation protection | What happens when someone sends email pretending to be your company? | DMARC |
| Mail routing | Where does email sent to your domain get delivered? | MX |
| Secure incoming delivery | Do you require other servers to use an encrypted connection when sending you mail? | MTA-STS |
| Delivery problem reports | Will you be told when another server fails to reach you securely? | TLS-RPT |
Who this is for
Managed service providers
You look after email for a book of clients, each with a different mix of providers and tools. Checking them by hand does not scale, and you usually hear about a broken setup from the client rather than from your own systems.
IT service providers
You own DNS for companies that keep adding tools without telling you. Monitoring shows you the change on the day it happens instead of during the next incident.
Email consultants and deliverability agencies
You are hired because a setup is wrong, and your work only holds if it stays right afterwards. Continuous checks give you evidence of what changed and when.
Internal IT and engineering teams
You look after several domains or brands. You get the parsed records, the full expansion of your sender list, and the exact rule behind each result, with a link to the source document so you can check our reading of it.
Running one company with one domain? That works too. The free check needs no account, and Starter covers a single domain when you want it watched.
What is free and what is paid
The check is free and always will be. It is a complete, honest look at your settings right now. What you pay for is knowing when they change, and the reports that receiving servers send back once you have verified the domain.
| What you get | Free check | Monitoring not built yet |
|---|---|---|
| One off check of your settings | Included | Included |
| Plain English findings | Included | Included |
| Exact settings and source documents | Included | Included |
| Automatic checks on a schedule | Not included | Included |
| Alerts when a setting changes | Not included | Included |
| History of past changes | Not included | Included |
| Reports collected from receiving servers | Not included | Included |
| Real list of every service sending as you | Not included | Included |
| Trends over time | Not included | Included |
| Several domains and team access | Not included | By plan |
Everything in the monitoring column is described honestly as not built yet. Nothing in it is available today, and you cannot pay for it. Planned pricing is published here.
What this does not do
This is a check of your settings, not a promise about results. It cannot tell you whether your email will land in someone's inbox, because that depends on your content, your sending history and rules that each provider keeps to itself. It also cannot see every message signing key, because those are stored under names that cannot be listed from outside. We say so in the report wherever it matters, rather than leaving you to assume otherwise.