Operations | Monitoring | ITSM | DevOps | Cloud

DNS Alerts over Syslog: TLS, CEF, and a Straight Line to Your SIEM

Enterprise teams can now add a Syslog alert channel: every DNS Spy alert delivered as an RFC 5424 message over TLS (or TCP/UDP), formatted as JSON or ArcSight CEF, with syslog priorities mapped from real alert severity. All deliveries originate from one documented static IP, so getting through your collector's firewall is a single allowlist rule.

DNS Spy Now Connects to GoDaddy. Every Domain, Every Record, Read-Only.

GoDaddy manages more domains than any registrar on earth, so it has always been near the top of our provider integration list. There was just one problem: in May 2024, GoDaddy restricted its API to accounts holding ten or more domains — fifty for some endpoints. Overnight, certificate renewals broke, dynamic DNS scripts died, and every small business with one or two domains was locked out of automating anything.

Send DNS Spy Alerts to Your SIEM: Introducing Webhook Alerts

Enterprise teams can now add a Webhook alert channel that POSTs every DNS Spy alert — DNS record changes, domain outages, security check failures, WHOIS updates, phishing look-alike detections — to any HTTPS endpoint as structured JSON. Requests are optionally HMAC-signed, every delivery is logged and retried, and a Send Test button verifies your integration end to end.

DNS Spy Now Connects to Amazon Route 53. Read-Only, Every Record, Always in Sync.

When we launched DNS provider sync with six providers, one name came up in nearly every "what about..." email: Amazon Route 53. That makes sense. Route 53 runs DNS for an enormous share of production infrastructure, and it does not support zone transfers — so until now, monitoring a Route 53 zone meant relying on autodiscovery's educated guesses. Today that gap closes.

Connect Your DNS Provider. Import Every Record. Stay in Sync.

When you add a domain to a DNS monitor, the first question is simple: which records should it watch? Until now there were two answers, and both had a catch. Autodiscovery probes hundreds of common names — www, mail, _dmarc, the usual suspects — and it catches most of what real zones contain. But if you named a record something unusual, no wordlist in the world is going to guess it.