Skip to content
MailGuardHQ
Roadmap

What exists, what is being built, and what is honestly still an idea

MailGuardHQ is pre-launch. This page says where each piece actually stands rather than listing everything as though it shipped.

Pre-launch

Nothing on this page is generally available yet. Dates are deliberately absent - we would rather move an item between the sections below than miss a date we published. Sections are ordered by how close each item is to working.

  1. Being built now

    The free domain check

    Thirteen discrete checks across DNS, authentication and hardening, streaming to the browser as each one completes, each with a plain-language finding and a recommended action.

    • Live checklist UX - built, currently running against a demo fixture
    • Real DNS resolution behind the same event contract
    • Rate limiting and abuse protection on the unauthenticated surface
    • Shareable result links
  2. Next

    Report collection and the tenant dashboard

    The part that turns a one-off check into monitoring: you publish a reporting address, mail providers send us daily reports, and we turn the XML into something a human can act on.

    • Inbound report ingestion - never loses a report, even under load
    • Parsing, classification and source enrichment
    • Per-tenant dashboard: pass rate, volume, trends over time
    • Weekly digest email with what changed and what to do about it
    • Alerts on new sending sources and on repeat spoofing
  3. Next

    Accounts, teams and billing

    Sign-in with email or Google, invite your team, and pay for Pro. Eight seats are included; more on request.

    • Email and Google sign-in
    • Team invitations and role presets
    • Trial, plan changes and the usage meter
    • Spend cap that degrades service speed but never stops ingestion
  4. Planned

    API and MCP server

    Every capability in the product is an API endpoint - the dashboard is just another consumer, with no privileged back door. The MCP server is a thin wrapper over that same API, so an AI assistant can operate the product with the same permissions and the same audit trail as a person.

    • Published OpenAPI specification, versioned and maintained
    • Scoped tokens: read, write, admin, billing - never implied by one another
    • Remote MCP over streamable HTTP, with tools generated from the spec
    • dns:write deliberately excluded from the developer preset
  5. Planned

    Guided enforcement

    The step everyone stalls on: moving from p=none to quarantine to reject without breaking legitimate mail.

    • Readiness assessment from your own report history
    • Proposed DNS changes with a before and after diff
    • Human approval per domain - enforcement is never applied automatically
    • Zone snapshot before any write, kept as the rollback
  6. Later

    Beyond DMARC

    The same machinery extends to the rest of the mail-authentication surface. These are checked today and will become monitored over time.

    • MTA-STS policy hosting and monitoring
    • TLS-RPT report collection
    • BIMI, including the certificate prerequisites
    • DNSSEC posture tracking
Commitments

Things that will not change

The check stays free

The public domain check is the front door. It is metered so we can see abuse, and priced at zero.

We never change your DNS on our own

Every DNS action is proposed and approved. Auto-apply is opt-in per domain, revocable, and always preceded by a zone snapshot.

Not applicable is not a failure

A parked domain with no MX is configured correctly. We will not inflate a score by calling a correct configuration a problem.

Want something on this list sooner?

The roadmap is driven by what the first customers actually hit. Tell us what is blocking you and it moves.

Check your domain See pricing