# Domain monitor schedules and alerts

Create a saved [domain monitor](/docs/domain-monitor/) before adding alerts. Choose a check interval that fits how quickly your team needs to detect a DNS or sender change. Use an immediate run after an intentional configuration change instead of waiting for the next scheduled check.

## Enable a schedule

Set `schedulingEnabled: true` and `intervalSeconds` when creating or updating the monitor. For example, `86400` requests a daily interval. Turning scheduling off pauses future scheduled checks; an explicit run-now request is still permitted.

[API endpoint: `updateDomainMonitor`](/docs/api/#updateDomainMonitor)

Keep one history for the domain when changing its interval. Creating a new monitor for every check makes it harder to compare the same sender over time.

## Choose an alert destination

An alert sink belongs to one monitor. It specifies a destination type, target, minimum severity and enabled state.

| Destination | Setup |
| --- | --- |
| Email | Use an address monitored by the people responsible for the sender. |
| Webhook | Use an HTTPS receiver in your operations system. |
| Slack or Teams | Configure the destination required by the monitor's alert settings, then select the severity. |

Start with `HIGH` when only urgent findings should interrupt the team, or `MEDIUM` when the channel is used for regular sender review. The supported thresholds are `LOW`, `MEDIUM`, `HIGH` and `CRITICAL`.

```javascript
// Add an alert sink and get the verification address for observed auth samples.
const alertSink =
  await mailslurp.domainMonitorController.createDomainMonitorAlertSink({
    monitorId: monitor.id,
    createDomainMonitorAlertSinkOptions: {
      type: "EMAIL",
      target: YOUR_ALERT_EMAIL,
      severityThreshold: "MEDIUM",
      enabled: true,
    },
  });

const verification =
  await mailslurp.domainMonitorController.createDomainMonitorEmailVerificationAddress({
    monitorId: monitor.id,
  });

console.log({
  alertTarget: alertSink.target,
  verificationAddress: verification.emailAddress,
  verificationStatus: verification.status,
});
```

This example uses the `mailslurp` client and `monitor` from the [setup page](/docs/domain-monitor/). Set `YOUR_ALERT_EMAIL` to your team address. It creates an email sink and a verification address for receiving authentication samples.

[API endpoint: `createDomainMonitorAlertSink`](/docs/api/#createDomainMonitorAlertSink)

[API endpoint: `getDomainMonitorAlertSinks`](/docs/api/#getDomainMonitorAlertSinks)

## Investigate a missing alert

Check that the monitor's schedule is enabled, a run has completed, the alert sink is enabled and the finding meets the severity threshold. Inspect the actual run: an unchanged or lower-severity result may not be the event you expected. Confirm the destination configuration before broadening the alert threshold.

Use [notification settings](/docs/notifications/) for account and device-render notifications. Domain-monitor sinks have their own monitor-specific configuration. Read [monitor results](/docs/domain-monitor-results/) to investigate the evidence behind an alert.
