Skip to main content
Alignr’s built-in domain checks collect public DNS observations for SPF, DMARC, mail delivery records (MX) and nameservers. Use them to assess specific domain expectations. They do not scan ports or establish that every aspect of email security is configured correctly. Open Clients → select client → Domains. Viewing requires integration-read access; changing settings or running a check requires integration-management access, alongside access to the client.

Choose the domains

1

Review discovered domains

Under Domains from Microsoft, review verified custom domains reported by the client’s selected Microsoft connection. Untick any domain you want to leave out.If discovery is unavailable, follow Review Microsoft connection. A saved connection may still need authorisation and a successful sync before domain observations are available.
2

Add other client-owned domains

Under Other domains → Additional domains, enter one domain per line. You can use manual targets even when Microsoft discovery is unavailable.For example, a fictional Acme client might have its Microsoft-discovered domain and a separately managed marketing domain. Review both ownership and intended scope before including them.
3

Save the intended scope

Review Enable domain checks, then select Save domain settings. Confirm Domain settings saved before running a check.Checks support up to 50 selected domains. If more are discovered, exclude unwanted domains and reduce the manual list before enabling and saving. The target set combines discovered and manual domains, then removes exclusions.
4

Collect and evaluate

Select Check now. The button requires saved, enabled settings, at least one domain and no unsaved edits. Wait for Domain check completed and review Last check and any source error.Collection produces evidence ready for evaluation. Run the appropriate standard to obtain updated control results, then inspect their source and observation time.

Understand automatic checks

Saving a removed target or disabling checks withdraws this source’s current observations for those targets immediately; observations with another remaining source can survive. Retained domain choices are not retained evidence. Review the client’s coverage after changing scope, even before another DNS check runs.

Keep the milestones separate

Choosing a domain does not query DNS. A completed DNS check supplies observations; evaluating a standard compares them with your expectations. A missing or failed lookup must not be turned into a pass.

Investigate a problem

Checkpoint: you can name the domains being checked, explain how they were selected, and distinguish collection time from assessment time. Continue with the email and domain baseline for the observations, automated expectations and separate manual reviews.