InfraNestInfraNest

Domain, DNS and email security management for IT teamsEvery company domain and system, finally in one place

Your company has domains at three registrars, DNS that marketing, IT and an agency all edit, certificates on services nobody documented, and servers at more than one cloud. InfraNest brings it into one place, checks the email and DNS security for you, and tells you when something changes.

Free plan · No credit card · Set up in minutes

  • Made in Germany
  • No migration needed
  • Tokens encrypted at rest
  • Export anytime, no lock-in
Your projects23 domains · 4 providers
  • yourcompany.comDMARC policy missing
  • mail.yourcompany.comCertificate renews in 41 days
  • vpn.yourcompany.comUp · 31 ms
  • yourcompany-old.deExpires in 18 days
  • shop.yourcompany.comUp · 210 ms

Every domain and system your company runs, whoever set it up.

The problem

The email that went to spam

On Monday sales tells you their quotes are landing in customers’ spam folders. You open the DNS, which turns out to be at a provider you did not know the company used, and find two SPF records. One was added by the agency that rebuilt the website, the other by the newsletter tool. Neither was wrong on its own. Together they break email authentication for the whole domain.

While you are there, you find a second domain that expires next month, registered on a former colleague’s credit card, and a certificate on an old VPN hostname that nobody remembered was still running.

Most company estates grow like this: a domain per project, a provider per decision, and records added by whoever needed them. InfraNest brings it into one place, checks the email and DNS security on every domain, and tells you when something changes, before it becomes next Monday’s problem.

The old way

  • Domains at whichever registrar someone used in 2016
  • SPF and DMARC typed by hand and never checked again
  • DNS changes nobody remembers making
  • Certificates on services nobody documented

With InfraNest

  • Every domain and zone in one list, whoever registered it
  • Email security checked on every domain, the right records recommended
  • An alert with the exact record when DNS changes
  • Certificates found from public logs and scans, and watched

How it works

How an IT team runs on InfraNest

Every company domain and zone, wherever it was registered

Connect each registrar and DNS provider the company uses, and every domain and zone appears with its renewal date, auto-renew, transfer lock and nameservers. The list leads with what needs attention: an expiry coming up, auto-renew switched off, or a domain pointing at nameservers that are not the zone you have been editing. Tags and custom fields record which department or project each domain belongs to.

  • Domains and zones from every provider in one list
  • Expiry, auto-renew and transfer lock watched on every domain
  • “The zone you are editing is not the one in use”, caught and explained
  • Tags and custom fields for owner, department or cost centre
How it works in detail
DomainsManage your registered domains, contacts, and registration settings.+ Add domain
DomainAttn
northwind-api.devOpenprovider · expires in 87d—
northwind-app.devNamecheap · expires in 94d—
northwind-cdn.netGoDaddy · expires in 117d—
northwind-docs.comCloudflare · expires in 340d—
northwind-labs.comUnlockedNamecheap · expires in 8d3
northwind-mail.comTransIP · expires in 264d—
Showing 6 of 20 domains
northwind-docs.comCloudflare · expires in 340d—
northwind-status.comCloudflare · expires in 259d—
northwind.orgCloudflare · expires in 319d1
nwcloud.devDynadot · expires in 155d1
nwcloud.ioDynadot · expires in 72d—
northwind-cdn.netGoDaddy · expires in 117d—
northwind-app.devNamecheap · expires in 94d—
northwind-labs.comUnlockedNamecheap · expires in 8d3
northwind.comNamecheap · expires in 17d1
northwind.ioNamecheap · expires in 209d—
nwcloud.appUnlockedNamecheap · expires in -7d3
nwcloud.coNamecheap · expires in 139d—
northwind-api.devOpenprovider · expires in 87d—
northwind.deOpenprovider · expires in 223d—
northwind.euOpenprovider · expires in 46d—
northwind-shop.comUnlockedPorkbun · expires in 204d1
northwind.cloudPorkbun · expires in 300d—
northwind.shopPorkbun · expires in 10d2
northwind-mail.comTransIP · expires in 264d—
northwind.nlUnlockedTransIP · expires in 181d—

Email security that is recommended for you, not guessed by hand

SPF, DKIM, DMARC, CAA and DNSSEC decide whether your email arrives and whether someone else can send as you. InfraNest checks every zone, explains in plain words what is missing, and recommends the exact SPF, DMARC and CAA records. For Google Workspace, Microsoft 365, Zoho Mail and many other mail providers, a built-in DNS template adds their records in one go; DKIM keys come from the provider, and InfraNest checks they are published. DNSSEC is one button, because InfraNest holds both the DNS provider and the registrar and does the steps in the safe order.

  • SPF, DMARC and CAA recommended, DKIM checked
  • Presets for Google Workspace and Microsoft 365
  • DNSSEC switched on across provider and registrar in the safe order
  • The exact values to paste where a provider’s API cannot write
How it works in detail

Showing your stored records

Verify live
Email deliverability
Spoofable

Nothing tells receiving servers what to do with mail that fails your checks, so anyone can send as you and it will still land. Based on the records stored here.

What’s working

Your approved senders are listed. Your mail is signed.

What to fix next

2 optional hardening record(s)CAA limits who can issue certificates for you; MTA-STS forces encrypted mail delivery. Neither affects whether someone can send as you.Review
DNSSECDNSSEC is off
Show 4 passed
NSNameservers match provider
Root domainRoot domain resolves
HTTPS redirectHTTP is redirected to HTTPS
TLS versionOnly modern TLS is accepted

An alert when someone changes DNS behind your back

Marketing tools, agencies and colleagues all edit DNS. InfraNest keeps asking the public internet what each domain answers and compares it with what it has on file. When they stop matching, you get the exact record, its old and new value, and a choice to keep the change or put yours back. Every change is in the audit log with who made it and when.

  • Checked against public resolvers, not only the provider’s API
  • The record that changed, with its old and new value
  • Restore or keep, one record at a time
  • Alerts by email, Slack, Teams or PagerDuty
How it works in detail

All 13 zones match what the internet answers

Checked continuously against public resolvers. You hear from us when one stops matching — not when you next think to look.

northwind-app.dev

7 records at Cloudflare · read from the provider 15m ago

Certificates and servers nobody documented, found and watched

InfraNest finds certificates from public certificate logs, scans of your hostnames and your providers, including the ones on subdomains and on services nobody wrote down. Certificates that renew themselves stay quiet until a renewal fails. Connect your clouds and every server gets a standing check: is there a firewall, is SSH open to the world, is there a restore point.

  • Certificates found on every subdomain, internal CAs included
  • A warning when a renewal fails, not on every renewal
  • Firewall, SSH and backup checks on every server
  • One firewall editor across your clouds
How it works in detail
CertificatesEvery SSL/TLS certificate we see across your infrastructure — discovered automatically from your monitors, with expiry tracking and alerts.+ Add certificate
All sourcesCloudflareDigitalOceanHetznerManualMonitorPublic log (crt.sh)TransIP
SubjectExpires
northwind.com5 certificates4 auto-renew · 2 discovered, not monitored
api.northwind.comLet's Encrypt (R3) · rsa 2048 · found by Monitorin 3 months
cdn.northwind.comWildcardCloudflare Inc ECC CA-3 · ecdsa 256 · found by Cloudflarein 10 months
docs.northwind.comLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 2 months
northwind.com+1Let's Encrypt (R3) · rsa 2048 · found by Monitorin 2 months
shop.northwind.comGlobalSign GCC R6 AlphaSSL CA 2023 · rsa 2048 · found by Public log (crt.sh)in 3 months
northwind-app.dev2 certificates2 auto-renew
northwind-app.devWildcardLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 21 days
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
Showing 7 of 11 certificates
northwind.com1 certificates1 auto-renew · 1 discovered, not monitored
cdn.northwind.comWildcardCloudflare Inc ECC CA-3 · ecdsa 256 · found by Cloudflarein 10 months
northwind-app.dev1 certificates1 auto-renew
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
northwind.cloud1 certificates1 auto-renew · 1 discovered, not monitored
*.northwind.cloudWildcardLet's Encrypt (R11) · ecdsa 256 · found by Hetznerin 2 months
vpn.northwind.example1 certificates1 discovered, not monitored
vpn.northwind.examplevpn.northwind.example · rsa 4096 · found by Manual12 days ago
northwind.com3 certificates3 auto-renew
api.northwind.comLet's Encrypt (R3) · rsa 2048 · found by Monitorin 3 months
docs.northwind.comLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 2 months
northwind.com+1Let's Encrypt (R3) · rsa 2048 · found by Monitorin 2 months
northwind-app.dev2 certificates2 auto-renew
northwind-app.devWildcardLet's Encrypt (R11) · ecdsa 256 · found by Monitorin 21 days
staging.northwind-app.devLet's Encrypt (R11) · ecdsa 256 · found by DigitalOcean, Monitornext month
northwind.com1 certificates1 discovered, not monitored
shop.northwind.comGlobalSign GCC R6 AlphaSSL CA 2023 · rsa 2048 · found by Public log (crt.sh)in 3 months
northwind-mail.com1 certificates1 auto-renew · 1 discovered, not monitored
northwind-mail.com+2Let's Encrypt (R3) · rsa 2048 · found by TransIPin 3 months
northwind.nl1 certificates1 discovered, not monitored
northwind.nl+1Sectigo RSA Organization Validation Secure Server CA · rsa 2048 · found by TransIPin 5 months

See your company’s domains in about fifteen minutes

Connect one registrar and one DNS provider. Nothing moves, and nothing changes until you ask it to.

Getting started

Your whole estate in about fifteen minutes

Nothing is moved, and nothing changes until you edit it.

15 min

Connect registrars and DNS

Add each registrar and DNS provider with an API token. Every domain and zone appears where it already lives.

25 min

Fix what the advisor finds

Review SPF, DKIM, DMARC, CAA and DNSSEC per domain and apply the records it writes for you.

35 min

Watch the rest

Add monitors for key services, connect your clouds and send alerts to your team channel.

What you get

What changes on day one

41

Places to check domains and DNS

guessedchecked

SPF, DKIM and DMARC on every domain

surprisealert

When a DNS record changes

The cost of doing it separately

Buy each piece from a different tool and it adds up fast:

Uptime monitoring
~€26
SSL tracking
~€15
Status page
~€26
Across 3 separate tools
~€67/mo
InfraNest Pro — all of it, one login€24/mo

Also in Pro, not counted above: 100 domains with DNS, servers across your cloud providers, 25 automations, Dynamic IP and Drop Catch.

Each line is that tool’s cheapest paid plan. Pro covers all of it: 50 monitors, 100 certificates and 3 status pages on your own domain.

Prices checked October 2026 · dollar prices at the ECB rate

Compare all features →

Questions

Questions IT teams ask

Do we have to move our domains or DNS?

No. Domains stay at their registrars and zones stay at their DNS providers. InfraNest works through the providers’ APIs, and nothing changes until you edit something.

Which registrars and DNS providers work?

Cloudflare, AWS Route 53, Hetzner, DigitalOcean, IONOS, TransIP, GoDaddy, Namecheap, OVH, Porkbun, Dynadot and Openprovider, among others. The integrations page lists what each one supports.

Can it fix our SPF, DKIM and DMARC?

It checks every zone and says in plain words what is missing. For SPF, DMARC and CAA it recommends the exact record, and for Google Workspace, Microsoft 365, Zoho Mail and many other mail providers a built-in DNS template adds their records in one go. DKIM keys come from your email provider; InfraNest checks that they are published.

What happens when someone else changes a record?

InfraNest compares what public resolvers answer with what it has on file. When they differ, you get the exact record and both values, and you choose whether to keep the change or restore yours. Every change is in the audit log with who made it.

Does it find certificates we do not know about?

Yes. Certificates are found from public certificate logs, scans of your hostnames, your monitors and your providers, including the ones on subdomains. An internal CA can be tracked alongside the public ones.

Can several admins work in it?

Yes. Business includes ten team members and basic SSO, and every change is recorded in the audit log with who made it and when.

Can we keep a home office or branch reachable on a changing IP?

Yes. Dynamic IP keeps DNS records and firewall rules following a changing address, reported by the router you already have.

Which plan fits an IT team?

Business: unlimited domains, 200 monitors checked from several regions, ten team members and basic SSO. A small team can start on Pro: 100 domains, 50 monitors and three team members.

Not quite you?

Your company’s estate, under control.

Domains, email security, certificates and servers for your own organisation, in one place. Start free, no card needed.

Free plan · No credit card required · Set up in minutes