ZeroHookZeroHook

How can we help you?

Search our knowledge base or browse by category

Getting Started

How does ZeroHook work?

Learn the basics of running your first DNS security audit (6 checks on Free, 35 on paid).

ZeroHook analyzes your domain's DNS records and security configuration in seconds. Free accounts get 6 core checks; paid tiers and trial run 29 additional checks (35 total) covering email authentication (SPF, DKIM, DMARC), transport security (MTA-STS, TLS-RPT), and infrastructure integrity (DNSSEC, Subdomain Takeover). You get a score from 0-100 and step-by-step copy-paste fixes for every issue found.

Getting Started

What is the Email Health Score?

Understanding our proprietary 0-100 security scoring algorithm.

Your score is calculated using our proprietary algorithm that weights up to 35 checklist checks (6 on Free) across 5 categories: Email Auth (40%), DNS Security (25%), Transport (20%), Reputation (10%), and Infrastructure (5%). A score >= 90 is an A (Excellent), while below 60 is an F (Critical).

Getting Started

Do I need a credit card to try it?

Run your first audit completely free.

No signup or credit card is required for your first manual audit. You can enter any domain and get an instant security report. We only require an account if you want to enable continuous monitoring, access historical data, or trigger automated remediation alerts. Paid subscription trials require a credit card on file.

Pricing & Plans

How does the pricing work?

Understanding ZeroHook's subscription tiers and on-demand audit limits.

ZeroHook uses a tier-based subscription model starting at $29/month. Paid subscribers get generous daily on-demand audit limits (25–500/day depending on tier). Pricing tiers also determine how many domains you can put under Continuous Monitoring.

Pricing & Plans

Subscription vs. Manual Audits

Flexible options for continuous monitoring and one-time checks.

The Free tier is perfect for one-time checks. The Deliverability tier ($29/mo) provides continuous monitoring for your core domain. The Agency/MSP ($89/mo) and Compliance Evidence Pack ($199/mo) tiers add priority support, API access, and advanced regulatory mapping (NIS2, SOC2, ISO).

Pricing & Plans

What are the on-demand audit limits?

Generous daily limits for every plan.

Each paid plan includes a generous daily on-demand audit allowance: Deliverability (25/day), Agency/MSP (50/day), Compliance Evidence Pack (100/day), and Enterprise (500/day). Limits reset daily. This replaces the old token-based system.

Pricing & Plans

Can I cancel or change plans?

Our flexible upgrade and downgrade policy.

Upgrades are immediate and prorated (you only pay the difference). Downgrades are scheduled for the end of your current billing cycle so you keep the features you already paid for. All subscriptions are non-refundable per our Terms of Service.

Security Audits

What checks are included?

Deep dive into our comprehensive security scan.

Free tier runs 6 checklist checks (email auth + core DNS). Paid tiers run 35 checks including SPF/DKIM/DMARC (full validation), BIMI/VMC, DNSSEC, CAA, MTA-STS, TLS-RPT, DANE, SSL Expiry, Subdomain Takeover detection, Zone Transfer risks, Nameservers health, Global Blacklist monitoring (50+ databases), and automated mapping to NIS2, SOC2, and ISO 27001 requirements.

Security Audits

How frequent are the automated scans?

Stay secure with continuous monitoring.

Free users get weekly scans. Deliverability, Agency/MSP, and Compliance Evidence Pack tiers receive daily automated scans of their monitored domains. If any record changes or a security gap is detected, we send an instant alert via Email, Slack, or Webhook depending on your tier.

Security Audits

Why is ZeroHook more accurate?

99.9% detection accuracy vs. basic tools.

Most tools only check if a record exists. ZeroHook validates the content against RFC specifications and cross-references results across multiple global anycast DNS nodes to prevent false positives and detect configuration drift that others miss.

Compliance

Does ZeroHook cover NIS2 requirements?

Pass NIS2 Article 21 audits with automated evidence.

Yes. NIS2 requires essential and important entities to implement security measures for their network and information systems. ZeroHook specifically automates the evidence collection for DNS security, email authentication, and continuous monitoring requirements. Fines for non-compliance can reach €10M or 2% of annual revenue.

Compliance

What is the Tamper-Proof Audit Log?

Cryptographically verified evidence for auditors.

For Compliance users, we maintain a 1-year tamper-proof log of all changes and audit results. Each entry is cryptographically hashed in a chain, ensuring auditors can verify that the security evidence has not been altered retroactively.

For Agencies & MSPs

White-Label Options for MSPs

Build your own security service on top of ZeroHook.

MSPs can use our Agency tier for white-labeling, including custom logos, brand colors, and custom fonts on all PDF reports. Bulk pricing allows you to manage client domains at a cost of $10-$15/month each, allowing for 300%+ margins.

For Agencies & MSPs

How do I generate branded reports?

Professional PDFs for QBRs and clients.

Agencies on Agency/MSP and Compliance Evidence Pack tiers can generate professional PDF reports with their own logo, brand colors, and company name. Upload your branding in Settings → White Label.

Technical

What are Copy-Paste DNS Fixes?

The fastest way to fix security gaps.

ZeroHook provides exact TXT/CNAME records tailored to your specific DNS provider (Cloudflare, GoDaddy, Namecheap, etc.). You just copy the value, paste it into your provider's dashboard, and the issue is resolved—no expert knowledge required.

Technical

Fixing SPF/DMARC/DKIM Errors

Resolve authentication failures in minutes.

We provide step-by-step guides for resolving SPF "too many lookups", DMARC "p=none" warnings, and missing DKIM selectors. Our guides are updated continuously as provider interfaces and security standards evolve.

Account & Billing

Managing your monitored domains

Scaling your security as you grow.

You can add or remove monitored domains directly from your dashboard. If you exceed your tier limit, you can purchase individual domain add-ons for $10-$15/month or upgrade to the next tier.

Account & Billing

Enterprise Billing & Invoicing

Options for large-scale deployments.

For Enterprise accounts with custom pricing, we support custom invoicing, NET-30/60 terms, and dedicated account management. We also offer annual prepayment discounts (20% savings).

Still need help?

Can't find what you're looking for? Our support team is here to help.

Average response time: <12 hours (SLA-backed)