Email incidents turn every issue into a story, not a stray alert. A raw feed of alerts tells you something happened; it doesn’t tell you whether this is the third time this month, whether your last fix held, or how long it’s been open. ToolTrusted turns each problem into a coherent lifecycle you can actually investigate — one that remembers its own history.
With email incidents you get email authentication alerts and email deliverability incident tracking — including DMARC change alerts — each with the exact fix attached.
Every one of these email incidents is immutable and time-stamped, so you can prove exactly when a problem began and when it cleared. ToolTrusted raises email incidents from the same continuous monitoring that scores your domain, and links each one to the ranked recommendations that resolve it.
How to track email incidents
ToolTrusted groups the change events for each issue on a domain into email incidents, each with a real lifecycle: opened → updated → resolved → reopened. Because it reads an immutable, replayable event history, each incident can derive its own lessons — is this issue chronic (keeps coming back), flapping (opens and closes rapidly), or was it first-pass resolved (the fix stuck)? That is context a mutable issue-tracker throws away.
What you get
- Open vs resolvedWhat needs investigation now, and what’s been put right — cleanly separated.
- Lifecycle & durationWhen it opened, how long it’s been open, whether it reopened.
- Auto-derived lessonsChronic, flapping and first-pass patterns surfaced from the full history.
- Drill-downInvestigate straight to the scan and evidence behind any incident.
Where it fits
Email incidents sit between watching and acting: they take the changes Monitoring detects and the patterns Analytics finds, and shape them into problems you can act on with Recommendations — or push straight to your team via Automation.
Which plan includes this
Pro · $29/mo
The Incident Center is part of the Pro and Agency plans. Every paid plan alerts you the moment something breaks; Pro adds the full incident lifecycle — how long it lasted, whether it recurred, and whether your fix held. It is independent, deterministic and evidence-backed — every incident is measured, never inferred, and we never claim to measure inbox placement (we track the infrastructure that determines it). See plans →
Email deliverability incident tracking, start to finish
A developer sets DMARC to p=none for a one-off test and forgets to revert it. Your domain is now publishing DMARC but no longer enforcing it — spoofers can send as you again, and standard checkers still show a green “DMARC present” tick. On its next scan ToolTrusted sees the policy move from reject to none, confirms it against your last snapshot, and opens an incident: what changed (the policy tag), why it matters (enforcement lost), and the fix (restore p=reject).
The incident has a lifecycle — it stays open until a later scan confirms the record is back at enforcement, then it resolves on its own, carrying the lesson with it. Degraded or momentary scans neither open nor resolve an incident, so transient DNS noise never creates false history. Over months, that lifecycle becomes an investigable record: every regression, when it happened, how long it lasted, and how it was fixed — the opposite of a checker that only ever shows “now”. Incidents are part of the Pro plan.
Frequently asked questions
What is an incident in ToolTrusted?
When monitoring confirms a meaningful change — a policy weakening, a new blacklist listing, an authentication break — it opens an incident: a tracked item with what changed, why it matters, and the fix, that you can work and then resolve.
How are incidents different from alerts?
An alert notifies you; an incident is the tracked lifecycle around it. Incidents give each issue a beginning and an end, plus the lesson, so you can see how your posture has been managed over time, not just that something pinged.
Which plan includes incidents?
Incidents are part of the Pro plan ($29/mo), which also adds daily monitoring, analytics, benchmarking and API access on top of Starter’s monitoring and guided recovery.