Focused solutions
One security engine. Clear jobs to be done.
Dedicated pages for each YAS direction, from managed domain monitoring to API-first email infrastructure intelligence.
Every solution is built on the same engine: outside-in inspection of the signals that are publicly visible for a domain — SPF, DKIM, DMARC, MX, MTA-STS/TLS-RPT, DANE/TLSA and TLS. Because the checks run from the outside, they reflect what the rest of the internet actually sees, not what an internal dashboard believes.
YAS reports externally observable evidence with timestamps — a before/after on every detected change, a severity, and a plain explanation of what to do next. It deliberately does not fabricate a "score" or claim that a single scan makes a domain compliant. If a control is missing, the report says so; if a result is ambiguous, it is labelled ambiguous.
The four solutions below are the same workspace viewed through different jobs to be done — an MSP watching client domains, an agency validating a sending portfolio before a campaign, an operations team tracking expiry risk, and a security team that needs reproducible evidence. Pick the job; the engine is shared.
Email & domain posture monitoring
DomainGuard
Continuously verify the outside-in posture of every client domain. Detect authentication drift, transport-security failures and certificate risk with actionable evidence.
Explore →
Pre-send infrastructure QA & Warmup
Deliverability Radar
Verify email authentication, warmup ramps, and transport posture across a sending-domain portfolio before—and during—a campaign.
Explore →
Certificate & domain expiry monitoring
CertWatch
Track certificate validity, hostname coverage and registration dates across client domain portfolios.
Explore →
External security evidence
PostureProof
Translate externally observable email, DNS and transport controls into an evidence-ready posture summary.
Explore →
BEC-focused vendor monitoring
Vendor Email Risk
Score the external email posture of supplier domains and surface deterioration before it becomes an invoice-fraud exposure.
Explore →
DNS drift & Subdomain Takeover Defender
DNS Change Sentinel
Build a history of DNS records, alert on consequential drift in mail and certificate controls, and detect dangling CNAME records.
Explore →
Developer API
Email Infrastructure API
A security-conscious API for normalized SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, DANE and TLS signals.
Explore →
Agency-ready posture reporting
White-Label Domain Audits
Create clear email, DNS and transport-security audit reports with executive risk scoring that help explain risk and remediation.
Explore →
Smart routing & destination monitoring
Link Compliance Monitor
Monitor redirect chains, edge geo-routing rules, destination TLS and target drift across large link inventories.
Explore →
Email & DNS cutover validation
Migration Verification
Compare a planned mail configuration with externally visible DNS during cutover and the critical days after.
Explore →
How the solutions relate
DomainGuard is the general-purpose posture workspace. Deliverability Radar narrows the same checks to the specific moment that matters for outbound email — before and during a campaign. CertWatch focuses on the time-bomb signals (expiry and coverage), while PostureProof packages findings as reproducible external evidence. Use one, or layer them; the data underneath is the same.
What YAS does not do
YAS is not a DMARC-report processing service and does not rewrite or repair DNS for you. It observes, timestamps and explains. When a check needs a change on your side — a TXT record, a TLS certificate, a DKIM selector — the report gives you the exact values and steps, but you remain in control of your own infrastructure.
About YAS.SH solutions
The solutions pages describe how the platform's pieces — short links, monitoring, the tools API and the intelligence features — combine for a specific job, rather than listing features and leaving the assembly to you. Each solution states the problem, the parts involved, and what the result looks like in operation.
These are descriptions of what the platform does today. Where something is planned rather than shipped, it is not listed here.
How to read these pages
Each solution begins with the operational problem it addresses, then the concrete mechanism, then the limits. If a solution depends on a paid plan or on configuration you have to complete yourself — a DNS record, an API key, a webhook endpoint — that dependency is stated up front rather than in a footnote.
Frequently asked questions
Are these packaged products or configurations?
Mostly configurations of the same underlying platform, described end to end. That is deliberate: the components are the same ones documented in the API reference, so nothing here is a black box.
Can I try a solution before paying?
The tools and the core link functionality are free to use. Features that require a paid plan are marked on the pricing page.