Alerts
Ward emails you when something changes. You choose who receives the emails and which ones in Alerts, in the dashboard. There are three kinds:
Instant alerts
Sent as soon as Ward detects it, for what can't wait:
- A new finding, or one that gets worse, of high or critical severity. You can choose to be alerted only about critical ones.
- Someone registers a domain almost identical to yours, or gets a certificate for one: the usual first step of an impersonation.
- A new certificate is issued for a sensitive-looking subdomain of yours (admin, vpn, login…).
- Your domain's name servers (NS) or mail servers (MX) change, or your SPF record changes: if you didn't do it, someone may be taking over your domain or your email.
- A team account appears in a data breach or with a password stolen by malware.
Expiration alerts
For your domain and your certificates, at 30, 14, 7, and 1 days before they expire, and once more if they expire. An expired domain takes your website and email offline; an expired certificate makes browsers warn your visitors.
A certificate valid for 90 days renews on its own long before it expires, so Ward only alerts at 14, 7, and 1 days: a 30-day alert for it would be noise. If a certificate that should renew itself reaches those alerts, something is failing.
What to do: renew the domain with your registrar and turn on auto-renew; for a certificate, renew it with your hosting provider, or find out why it isn't renewing on its own.
Weekly summary
Every Monday morning, one email per domain with two blocks:
- Needs action: new findings or findings that got worse, of medium severity or above, and planned fixes whose date has passed and are still there.
- For your information: DNS changes, new senders that pass DMARC, new redirects, what was resolved and new low or informational findings.
Rules that apply to all of them
- Ward never sends the same alert twice.
- Findings marked as accepted risk, false positive or planned (until their date) don't send alerts.
- Only monitored domains generate alerts: verified domains with monitoring turned on.
- Each person receives the emails in their own language.
Who receives them
- By default, every member of your team.
- In Alerts you can add up to 5 shared addresses of your organization instead, such as security@yourcompany.com.
- Each shared address has to confirm before it receives anything.
- Every email has a link to unsubscribe.
- Each person also chooses in Alerts which kinds of alerts they want.
What each alert means and what to do
These are the labels you'll see in Activity and in the emails, and what to do when you get one:
- New
- A finding that wasn't there in the previous scan.Open the finding. If it's critical or high, follow its steps this week; otherwise, plan it.
- Got worse
- A finding that was already there and is now more serious.Read the history of the finding to see what changed, and move it up your list.
- Resolved
- A finding that has disappeared: fixed, or no longer visible.Nothing to do. If nobody on your team fixed it, check the finding's history: it may have stopped being visible rather than being fixed.
- Expiration
- Your domain or a certificate is about to expire, or already has.Renew it. If you get the 14, 7 or 1 day alert and it's still not renewed, treat it as urgent.
- New certificate
- A certificate has been issued for one of your domains or subdomains.If you or your provider requested it, ignore it. If you didn't, someone else obtained a certificate for your name: ask your provider.
- Lookalike
- A certificate has been issued for a domain that imitates yours.It's the usual preparation of a fake website or email. Don't enter any data there, warn your team and ask your registrar or provider how to report it.
- Lookalike domain
- A domain that imitates yours has just been registered.Often it's only a registration. Warn your team to be wary of emails from that name and keep an eye on it; if it's yours, mark it so.
- Exposed account
- A team account has appeared in a breach or with a stolen password.Change that account's password now, turn on two-step verification and change it anywhere else you reused it. If it was stolen by malware, check the person's device first.
- Email reputation
- The reputation of your outgoing email has changed at a large provider.Check recent mass mailings and that SPF, DKIM and DMARC are in order; ask your email provider if it persists.
- DNS change
- Something important has changed in your DNS (name servers, mail servers, SPF, DMARC…).If you made the change, fine. If not, contact your registrar or DNS provider today, change the access password and turn on two-step verification.
- New sender
- A new service is sending email as your domain and passes DMARC.Check that you recognize the service (newsletter, CRM, invoicing). If you don't, someone is sending email as you: tighten your DMARC policy.