30tools
Your AI agent gets your DNS zone, not your invoice.
Explore the MCP Suite

Domain guardian

Lost domains are rarely stolen.

Usually a transfer lock simply drops and nobody checks any more, or a renewal notice lands in the mailbox of someone who left long ago. The guardian checks once a day what moved on your domains, and holds critical changes until a second person agrees.

Create an accountSee the plans

Part of the Pro plan, €9.00 a month incl. VAT, for the whole account.

Losing a domain starts quietly.

A domain rarely disappears because somebody attacked it. It disappears because a transfer lock dropped during a migration and nobody noticed. Because the auth code sits in a ticket that forty people can now read. Because the renewal notice went to an address nobody has opened in two years.

By the time you find out because the website is gone, you no longer have a DNS problem. You have one with deadlines, with the registry and, in the bad case, with a new owner.

What makes it expensive

Getting it back is a procedure, not a click
For most endings a redemption period starts after expiry; for .de the DENIC procedure applies instead. The registry sets the fee we incur. What you pay is in your price list, and it is well above the renewal price.
The mail leaves with the domain
The MX record hangs off the same name. Once the domain belongs to someone else, password resets for every connected service run through the new owner.
Afterwards nobody can say who did it
Without a log of account, access path and timestamp, all that remains after an incident is a guess, and a guess convinces nobody.

How it works

Compare, report, hold.

The comparison runs once a day. The guard rules, by contrast, take effect the moment somebody triggers the change.

  1. 1

    It remembers the last state

    For every domain it remembers the last state of the transfer lock, the renewal setting and the auth code. Those three, and no more: nameservers and DNSSEC have checks of their own.

  2. 2

    It reports the deviation

    If the lock drops, the renewal setting changes or an auth code is in circulation, a notice goes to your account address the next morning.

  3. 3

    It holds critical changes

    Seven rule classes, three levels each: off, two-factor required, or approval by a second person. Set per domain or for the whole account.

  4. 4

    Every issue lands in the log

    Whoever requests an auth code shows up in the log afterwards: with timestamp, the acting login and the access path. Over the API, additionally with the id of the key used.

Three paths, one rule

The agent cannot route around approval.

Guard rules do not only apply in the browser. They cover every path a change can take into your domain.

Interface
dash.regfish.de/my/guardian

Watched domains, detected risks and the drift watch events on one page.

API
403 Blocked by the Domain-Guardian

You set the rules in the interface today; there is no endpoint for that. They do take effect on every path though: a call a rule holds gets a 403 back, and the refusal lands in the log with its access path.

Agent
MCP: request_auth_code

An AI agent runs into the four-eyes rule too. Registration, transfer and cancellation are deliberately not available over MCP at all.

Nothing left out

Exactly what is watched.

So you know up front what the guardian does and what it does not do.

Rule classes
Zone change, record deletion, nameserver change, auth info and transfer, cancellation, DNSSEC, owner change.
Levels per rule
Off, two-factor required, or four-eyes approval. Configurable per domain or account-wide.
Exceptions
Individual API keys and DynDNS can be exempted so automation does not stall waiting for approval. The exemption then covers every rule in that scope, not a single one.
Approval window
60 minutes. After that the request expires and has to be raised again. Whoever raises it cannot approve it.
Audit log
Account-wide, with the acting login, access path (interface, API or DynDNS), action, outcome and a plain-text detail. Filterable by domain and outcome.
How often it compares
Once a day. Up to a day can pass between the change and the notice. The guard rules are independent of that and act immediately, because they hold the action itself.
Expiry warning
90, 30, 7 and 1 day before expiry, by email. Free for every account, with no plan at all.
When the plan ends
Guard rules you already set keep working. Pro is what you need to edit rules and to run the drift watch.
.de and every other ending
The guardian does not care about the ending. It works on every domain in the account, .de included.
Limit
The guardian only works on domains inside your regfish account. For outside names, the certificate watch reads the CT logs instead.

As of 22 September 2026. The registry sets the fee we incur; our price for it is in your price list.

Pro

One plan per account, not per domain.

Four domains cost the same as four hundred. The guardian covers all of them, with no counter and no top-up invoice.

Also included in Pro

  • Guard rules and enforced two-factor sign-in
  • Change alerts and audit trail per zone
  • DNS doctor with a plain-language explanation
  • Certificate watch across the CT logs
  • Team of up to five people
  • SEO and visibility suite
€9.00 / month

Incl. 19 % German VAT, €7.56 net. €90.00 paid yearly, €108.00 a year paid monthly.

Get ProAlready a customer? Activate it in the dashCompare all plans

Before you ask

What customers want to know here.

No. The drift watch compares today’s state of your domains with yesterday’s, so the domain has to be in your account. What does work across outside names is the certificate watch: it reads the Certificate Transparency logs and reports every newly issued certificate, wherever the name is managed.

Setting it up takes ten minutes. The incident costs more.

Opening an account is free, you only pay for domains. Add the guardian when you need it.