Domain, DNS and email security management for IT teamsEvery company domain and system, finally in one place
Your company has domains at three registrars, DNS that marketing, IT and an agency all edit, certificates on services nobody documented, and servers at more than one cloud. InfraNest brings it into one place, checks the email and DNS security for you, and tells you when something changes.
Free plan · No credit card · Set up in minutes
- Made in Germany
- No migration needed
- Tokens encrypted at rest
- Export anytime, no lock-in
- yourcompany.comDMARC policy missing
- mail.yourcompany.comCertificate renews in 41 days
- vpn.yourcompany.comUp · 31 ms
- yourcompany-old.deExpires in 18 days
- shop.yourcompany.comUp · 210 ms
Every domain and system your company runs, whoever set it up.
The problem
The email that went to spam
On Monday sales tells you their quotes are landing in customers’ spam folders. You open the DNS, which turns out to be at a provider you did not know the company used, and find two SPF records. One was added by the agency that rebuilt the website, the other by the newsletter tool. Neither was wrong on its own. Together they break email authentication for the whole domain.
While you are there, you find a second domain that expires next month, registered on a former colleague’s credit card, and a certificate on an old VPN hostname that nobody remembered was still running.
Most company estates grow like this: a domain per project, a provider per decision, and records added by whoever needed them. InfraNest brings it into one place, checks the email and DNS security on every domain, and tells you when something changes, before it becomes next Monday’s problem.
The old way
- Domains at whichever registrar someone used in 2016
- SPF and DMARC typed by hand and never checked again
- DNS changes nobody remembers making
- Certificates on services nobody documented
With InfraNest
- Every domain and zone in one list, whoever registered it
- Email security checked on every domain, the right records recommended
- An alert with the exact record when DNS changes
- Certificates found from public logs and scans, and watched
How it works
How an IT team runs on InfraNest
Every company domain and zone, wherever it was registered
Connect each registrar and DNS provider the company uses, and every domain and zone appears with its renewal date, auto-renew, transfer lock and nameservers. The list leads with what needs attention: an expiry coming up, auto-renew switched off, or a domain pointing at nameservers that are not the zone you have been editing. Tags and custom fields record which department or project each domain belongs to.
- Domains and zones from every provider in one list
- Expiry, auto-renew and transfer lock watched on every domain
- “The zone you are editing is not the one in use”, caught and explained
- Tags and custom fields for owner, department or cost centre
Email security that is recommended for you, not guessed by hand
SPF, DKIM, DMARC, CAA and DNSSEC decide whether your email arrives and whether someone else can send as you. InfraNest checks every zone, explains in plain words what is missing, and recommends the exact SPF, DMARC and CAA records. For Google Workspace, Microsoft 365, Zoho Mail and many other mail providers, a built-in DNS template adds their records in one go; DKIM keys come from the provider, and InfraNest checks they are published. DNSSEC is one button, because InfraNest holds both the DNS provider and the registrar and does the steps in the safe order.
- SPF, DMARC and CAA recommended, DKIM checked
- Presets for Google Workspace and Microsoft 365
- DNSSEC switched on across provider and registrar in the safe order
- The exact values to paste where a provider’s API cannot write
Showing your stored records
Verify liveNothing tells receiving servers what to do with mail that fails your checks, so anyone can send as you and it will still land. Based on the records stored here.
What’s working
Your approved senders are listed. Your mail is signed.
What to fix next
- No DMARC record — nothing tells receivers what to do with failures. Add DMARC, monitor first
- Your SPF ends in ~all, a soft fail most servers deliver anyway. Make it strict
Show 4 passedHide passed
An alert when someone changes DNS behind your back
Marketing tools, agencies and colleagues all edit DNS. InfraNest keeps asking the public internet what each domain answers and compares it with what it has on file. When they stop matching, you get the exact record, its old and new value, and a choice to keep the change or put yours back. Every change is in the audit log with who made it and when.
- Checked against public resolvers, not only the provider’s API
- The record that changed, with its old and new value
- Restore or keep, one record at a time
- Alerts by email, Slack, Teams or PagerDuty
Certificates and servers nobody documented, found and watched
InfraNest finds certificates from public certificate logs, scans of your hostnames and your providers, including the ones on subdomains and on services nobody wrote down. Certificates that renew themselves stay quiet until a renewal fails. Connect your clouds and every server gets a standing check: is there a firewall, is SSH open to the world, is there a restore point.
- Certificates found on every subdomain, internal CAs included
- A warning when a renewal fails, not on every renewal
- Firewall, SSH and backup checks on every server
- One firewall editor across your clouds
See your company’s domains in about fifteen minutes
Connect one registrar and one DNS provider. Nothing moves, and nothing changes until you ask it to.
Getting started
Your whole estate in about fifteen minutes
Nothing is moved, and nothing changes until you edit it.
Connect registrars and DNS
Add each registrar and DNS provider with an API token. Every domain and zone appears where it already lives.
Fix what the advisor finds
Review SPF, DKIM, DMARC, CAA and DNSSEC per domain and apply the records it writes for you.
Watch the rest
Add monitors for key services, connect your clouds and send alerts to your team channel.
How you actually do it
Step-by-step guides for the jobs on this page.
What you get
What changes on day one
41
Places to check domains and DNS
guessedchecked
SPF, DKIM and DMARC on every domain
surprisealert
When a DNS record changes
The cost of doing it separately
Buy each piece from a different tool and it adds up fast:
- Uptime monitoring
- ~€26
- SSL tracking
- ~€15
- Status page
- ~€26
- Across 3 separate tools
- ~€67/mo
Also in Pro, not counted above: 100 domains with DNS, servers across your cloud providers, 25 automations, Dynamic IP and Drop Catch.
Each line is that tool’s cheapest paid plan. Pro covers all of it: 50 monitors, 100 certificates and 3 status pages on your own domain.
Prices checked October 2026 · dollar prices at the ECB rate
Questions
Questions IT teams ask
Do we have to move our domains or DNS?
No. Domains stay at their registrars and zones stay at their DNS providers. InfraNest works through the providers’ APIs, and nothing changes until you edit something.
Which registrars and DNS providers work?
Cloudflare, AWS Route 53, Hetzner, DigitalOcean, IONOS, TransIP, GoDaddy, Namecheap, OVH, Porkbun, Dynadot and Openprovider, among others. The integrations page lists what each one supports.
Can it fix our SPF, DKIM and DMARC?
It checks every zone and says in plain words what is missing. For SPF, DMARC and CAA it recommends the exact record, and for Google Workspace, Microsoft 365, Zoho Mail and many other mail providers a built-in DNS template adds their records in one go. DKIM keys come from your email provider; InfraNest checks that they are published.
What happens when someone else changes a record?
InfraNest compares what public resolvers answer with what it has on file. When they differ, you get the exact record and both values, and you choose whether to keep the change or restore yours. Every change is in the audit log with who made it.
Does it find certificates we do not know about?
Yes. Certificates are found from public certificate logs, scans of your hostnames, your monitors and your providers, including the ones on subdomains. An internal CA can be tracked alongside the public ones.
Can several admins work in it?
Yes. Business includes ten team members and basic SSO, and every change is recorded in the audit log with who made it and when.
Can we keep a home office or branch reachable on a changing IP?
Yes. Dynamic IP keeps DNS records and firewall rules following a changing address, reported by the router you already have.
Which plan fits an IT team?
Business: unlimited domains, 200 monitors checked from several regions, ten team members and basic SSO. A small team can start on Pro: 100 domains, 50 monitors and three team members.
Not quite you?
Your company’s estate, under control.
Domains, email security, certificates and servers for your own organisation, in one place. Start free, no card needed.
Free plan · No credit card required · Set up in minutes