Marchpost
Menu

Alerts and what triggers them

Alerts fire on change, not on state, so accepted risks do not become noise.

Alerts fire on change

After every rescan we compare the findings to the previous scan and record what moved. You are

alerted when something became true, not because it is true.

This matters. If a client has accepted the risk of not running DNSSEC, you should not be told

about it every week. But if their DMARC policy drops from reject to none, you want to know

that afternoon.

What we alert on

  • Regressions — a check that was passing is now failing.
  • New critical or high findings — including a certificate crossing into the 14-day window.
  • Score drops of more than five points.
  • Scan failures where a domain that used to respond has stopped responding.

What we do not alert on

  • Findings that were already failing at the previous scan.
  • Low-severity findings, unless you turn that on.
  • Improvements — those appear in the report, not in your inbox.

Resolving

Alerts resolve automatically when the underlying finding starts passing again. You can also

acknowledge an alert to take it out of the open list without fixing it, which is the right move

for a risk the client has explicitly accepted.

Still stuck?

Send us a message — include the domain and we will look at it.