Building in public
The Blankitt changelog
54 dated releases across the platform — the same feeds your team sees inside each product. Judge the pace for yourself.
Blankitt Edge
Explore Edge →Email: real clicks vs the delivery-hour scan
22 Aug 2026- newThe Email channel drill-down now shows every tagged send with its first 24 hours as a timeline: machine clicks against real recipients, hour by hour. Mailbox security software opens every link in an email as it is delivered, and that pattern is unmistakable at a glance: a tall machine spike in the delivery hour, then silence, while real clicks trail on for hours.
- newEach send carries a verdict. Delivery-hour scan means benign email security software, and the panel says so plainly, together with the recommended response: verify your email platform's machine-click filtering, and do not block these networks, because blocking can hurt deliverability. Machine traffic that persists outside delivery windows is flagged for investigation instead.
- newEvery send shows its real clicks (235 of 1.49k, for example) so you can report email engagement on human numbers, and keep browse-abandonment triggers and retargeting audiences off the machine slice.
- improvedWhat it hit is now Links opened on the Email drill-down: spread across pages there usually reflects the links inside the send being opened once each, not browsing.
Offenders, Paths and IPs learn what traffic costs
22 Aug 2026- newNetworks whose addresses appear in your billed invalid ad clicks now carry a billed badge on the Offenders page, with a spend estimate when your channel rates are configured. Clicking the badge opens the channel that billed those clicks, with the evidence CSV and the paste-ready IP exclusion list right there.
- newThe IPs page gains a Billed column and filter (the addresses worth excluding first), plus Cloudflare's own classification of each address: known bad host, Tor exit, monitoring service and so on.
- newOffenders can now be filtered by acquisition channel (which networks pollute Google Paid, email or referral) and by declared identity: verified crawlers, AI agents, other declared bots, or nothing declared at all.
- newNetworks whose automation is email delivery-hour link scanning carry a scanner infra chip, so benign mailbox security never tops your offenders list looking like an attack.
- newThe Paths page now reads the landing data: filter paths by the channel that enters through them, and bot-only doors (pages with real landing volume and almost no human entries) are flagged in red.
- improvedQuick find pills are now shared between the Paths and IPs pages, and the list extends itself with your own site's highest-volume controllers.
Approve once: the standing challenge mandate
21 Aug 2026- newThe Protections page gains the standing challenge mandate. Approve one policy and Edge keeps a managed challenge current for the IP addresses behind your invalid ad clicks, the same evidence set as your Google Ads exclusion list. Challenged bots never load the page, so they never enter your retargeting audiences or analytics either.
- newEvery mandate starts in trial mode: it shows you exactly what it would challenge, and the live switch stays locked until you have reviewed a preview. Challenge only, never block. Blocks always remain a per-incident human decision.
- newThe mandate owns exactly one rule and never touches anything else on your zone. Every change is recorded in its activity feed and sent to your notification channels, and you can pause or revoke it at any time.
Channels: trends on campaigns, doors on pages
21 Aug 2026- improvedCampaign rows now carry a trend sparkline of their invalid share, so a code that started climbing on Tuesday reads as exactly that.
- newPaid campaign rows expand into their own drill-down: the networks, paths, browser identities and countries behind that campaign's invalid clicks, built from the same click log the Evidence CSV exports.
- newClick any landing page to see which channels enter through it, each with Cloudflare's verdict. A page that looks healthy in total can be one channel's favourite scripted entry point.
- newThe Geography map can be narrowed to a single channel, answering which markets that channel's invalid traffic claims to come from.
- newThe Detection section adds a per-channel method mix. Heuristics-heavy means crude automation; machine-learning-heavy means sophisticated and worth the evidence log.
- newReferrer domains running almost entirely bot-scored at real volume now carry a fabricated flag in the drill-down: invented referrers, not partners.
- improvedThe AI-assistant arrivals tile splits by assistant and links straight to what AI is citing on the Bots and agents page.
- fixedTimes on the invalid arrivals chart now display correctly on the 30 minute, 2 hour and 30 day ranges.
Channels: a watchdog for every campaign
21 Aug 2026- newEvery campaign code is now watched by its own detector. It compares a campaign's invalid share against that campaign's own weekly baseline, across every channel at once, because replayed campaign URLs usually arrive as Direct rather than on the channel that owns the code. When it fires, the campaign's row carries a badge linking straight to the alert.
- newPaid campaigns carry their own Evidence CSV and IP exclusion downloads. Ad platforms take credit claims and IP exclusions per campaign, so the artifacts now scope the same way.
- newDownload History CSV on the Channels table exports the banked weekly history, one row per channel per week, kept beyond the live analytics window. Ready for your own spreadsheets and dashboards.
- newOpen channel and campaign alerts are now drawn on the invalid arrivals chart at the moment each opened, so a spike and its alert line up visually. Click a marker to open the alert.
- improvedIf your Logpush job is not shipping the ClientRequestHost field, the Channels page now says so in a banner instead of quietly over-counting Referral arrivals. The source coverage panel lists the field as well.
The Channels page gets a section menu and faster loading
21 Aug 2026- improvedThe Channels page is now organised by a section menu: Channels, Campaigns, Landing pages, Geography, Timing and Detection. The headline tiles stay in view whichever section you are in, so the summary never disappears.
- improvedEach section loads its own data the first time you open it and keeps it cached afterwards. The page opens noticeably faster, and switching between sections you have already visited is instant.
Channels: the map, the doors, and the paste-ready fix
21 Aug 2026- newThe Channels page now opens with invalid arrivals over time: bot-scored landing views per interval with the invalid rate alongside. A volume spike with a steady share is a campaign going out; a rising share on flat volume is automation replacing shoppers.
- newWhere arrivals land: a world map of landing views by country with each country's own invalid rate. A market you do not sell to at a near-100% rate is fleet infrastructure, not customers.
- newTop landing pages shows the doors automation actually enters through, with exact per-page invalid rates. Platform controller URLs appearing here at all means bots are using entrances no shopper ever lands on.
- newHow Cloudflare caught it: each invalid arrival grouped by the verdict engine's own detection method (heuristics, machine learning, JavaScript fingerprinting). Threat types from the platform that saw every request, not from a tag.
- newIP exclusions, next to the evidence CSV on paid channels: a paste-ready list of the top invalid-click source addresses, capped at the 500 entries Google Ads accepts per campaign. Edge prepares the list; applying it is your click.
- newThe weekly report's Marketing channels section now opens with a short generated summary, clearly labelled, composed only from the week's own numbers. If generation is unavailable the section reads exactly as before.
Channels: see which marketing traffic is real
21 Aug 2026- newNew Channels page under Monitor: every acquisition channel, from paid search and email to affiliates, organics and AI assistants, with Cloudflare's verdict on each landing view. Classified server-side at the edge, so it includes the bot traffic your tag analytics never sees, and the counts are exact.
- newCampaigns table reads your own campaign codes (sourceCode, marketingCode, utm_campaign), so replay shows up at the level marketing plans at: one campaign running hot while its siblings stay clean is bots re-requesting that campaign's tagged URLs. Only those three parameters are ever read; nothing user-typed is stored.
- newSpend at risk: add cost-per-view estimates in Settings and invalid views become currency figures on every money channel and campaign.
- newEvidence export: paid channel drill-downs download a CSV of bot-scored clicks with their ad platform click IDs, timestamps, campaigns and networks. The attachment an invalid-traffic credit claim needs.
- newA channel-invalid-spike detector watches paid, email and affiliate channels and alerts when a channel's invalid share jumps against its own weekly baseline. It never suggests blocking a channel; real shoppers arrive through it too.
- improvedChannel drill-downs show who runs the invalid slice: networks, paths, claimed browsers, markets, referring sites (for Referral), and Cloudflare's own view of the addresses. The weekly bot report gains a Marketing channels section, and an hour-of-day strip shows when each channel's automation runs.
Every declared bot now tells you who is behind it
20 Aug 2026- newEvery name in the Other declared bots panel now carries an identity label: who operates it and what it does, from SEO crawlers (Ahrefs, Semrush, Majestic) to link-preview bots (Facebook, Pinterest, TikTok), ad checkers, uptime monitors, and archives. Hover for the fuller story.
- newWhere nobody credibly claims a name, the label says so. An unidentified crawler with real volume is worth more attention than a known SEO tool, and the panel now makes that difference visible at a glance.
- newPerformance testers are no longer invisible. Tools like GTmetrix and Lighthouse fetch pages with a real browser identity and never used to appear here; they are now classified and listed by name, verified badge included.
- improvedThe panel lists up to 40 names so a low-volume tool is not buried under the heavy crawlers, and the Bots over time chart plots named agents by default, with a toggle to add the unclassified catch-all line back.
Edge now flags browser versions that do not exist
20 Aug 2026- newEdge now watches for browser versions that do not exist. A fleet claiming a version newer than anything your real shoppers run is fabricating its identity, and the Impossible Browser Version alert names it, sizes it, and says how much of it Cloudflare already scores as automated.
- newThe detector calibrates itself from your own shoppers: whatever version your human traffic runs is the ceiling, so there is no version list to maintain and it never goes stale. Stores without Bot Management data simply never see a false alarm; without a real-shopper baseline the detector stays quiet.
- newEach alert carries a drafted challenge rule matched to the exact fabricated version string. It cannot touch a real shopper, because no real browser runs a version that does not exist. As always, the rule arrives disabled; nothing changes until you enable it.
- improvedIn the analytics gap drill, click any claimed browser version to pin the whole drill to that fleet: its networks, its paths, its POSTs. A new self-announced identities list also shows the in-app browsers and testing tools inside each slice.
See who is behind the traffic your tag analytics never sees
19 Aug 2026- newThe 'What tag analytics never sees' card on the Overview now drills. Click the headline percentage to open the whole never-tagged slice, or any tile for one segment, and see the networks behind it, the paths it hit (with POSTs and errors), and what it claimed to be.
- newThe claimed-identity column is the quick tell on report pollution: browser-shaped, bot-scored traffic concentrated on a single browser version is an automated fleet, not an audience. Every network listed clicks through to its detail page, where a challenge rule is one draft away.
- improvedThe declared bots and crawlers tile links straight to Bots & agents, that population's full drill-down. Drill numbers always use the same definitions as the card, so what you expand sums to what you clicked.
The weekly bot report now reads like the Bots & agents page
19 Aug 2026- improvedThe Monday weekly bot report has been rebuilt to read the way the Bots & agents page does, in the same priority order: crawler impersonation first, with a plain all-clear line when the week was clean, then what AI cited from your store, the AI agents with their intent labels, the search crawlers, and the other declared bots. Agents are named properly (GPTBot, ChatGPT-User) and every cited page appears exactly as AI fetched it.
- improvedThe report's numbers now come from the same per-bot data the page itself shows, so what lands in your inbox matches what you see on screen. Some heavy crawlers were previously under-counted in the report; that gap is closed.
- newThe report has its own recipients, separate from alert routing: a dedicated report email, and optionally a webhook that receives the same report as structured JSON for your own tooling. Both are set in Settings under the Weekly bot report switch; leave the email blank to keep using your default notification address.
- improvedWeek-over-week comparisons pause for one week while the upgraded dataset takes over, then resume automatically. The report says so itself rather than showing changes the traffic never made.
- newYou don't have to wait for Monday: Send report now in Settings sends the report on demand, to the same recipients, whether or not the weekly schedule is on. Pick a date and it sends the report covering the last completed week as of that date, so any banked week from the history is one click away.
AI citations now name the exact page
19 Aug 2026- improvedWhat AI is citing now records the real URL of every answer-time fetch. Long product pages used to collapse into a placeholder; now you see the exact page, product code and all. Query strings are never kept, so nothing personal is recorded. Applies to the live retrieval agents from 19 August onward; bulk crawls and AI-search indexing deliberately stay grouped by URL pattern, where the pattern is the right level of detail.
- improvedThe AI agents panel now carries an always-visible legend for the three intent labels: training crawl (reading your catalogue in bulk, to learn from it), AI search (indexing you for AI search results), and live retrieval (fetching a page to cite it in a live answer).
Zoom in on any burst of bot activity
19 Aug 2026- newClick a bar on a bot's When it hit timeline and the whole drill-down focuses on that interval: paths, content types, networks and the verified split all recompute for just that slice. A spike stops being a shape on a chart and becomes these pages, from these networks, in that hour.
- newDrag across several bars to focus a range instead. A live highlight shows the span as you drag; release to apply it, and Show whole window clears it.
- newTime and network focus combine. Select the burst, then click the network behind it, and you are looking at exactly what that network did in that window. If it is hostile, Draft rule is one click away.
See what AI is citing from your store
19 Aug 2026- newA What AI is citing panel on the Bots & agents page. Live retrieval agents (ChatGPT-User, Claude-User, Perplexity-User) fetch a page at the moment they cite it in an answer for a real person, so each fetch is your content appearing in generated output: the closest server-side signal to an AI impression. The panel lists those pages with the split per agent.
- newEvery AI agent now carries an intent label: training crawl (reading your catalogue in bulk), AI search (fetches powering AI search indexes), or live retrieval (citing you right now). Three very different things stop looking like one number.
- improvedClaude and Perplexity retrieval agents are now identified separately from their bulk crawlers, and the AI search fetchers Claude-SearchBot, ExaSearchBot and AzureAI-SearchBot are recognised names. Their history builds from 19 August 2026 onward.
- newEdge banks a weekly per-page summary of AI citation fetches and keeps it indefinitely, so the trend outlives the raw log window. Page paths only, query strings stripped, no personal data.
- improvedThe Bots & agents page now reads in priority order: impersonation first while there is any (a clean window gets a one-line all-clear instead of an empty threat panel), then AI visibility, crawlers, the unclassified group, and banked history. The tiles at the top jump straight to their sections, every bot timeline has a proper time axis, and drafting a challenge rule from an impersonation row is a one-click button.
Deeper bot drill-downs, plus alerts when the bots change
18 Aug 2026- newEvery bot drawer now shows where the traffic comes from, network by network, with the verified and unverified share of each. Click a network to focus the whole drawer on it. For a name like Googlebot this is the fastest honesty check on the page: the real crawler is one fully verified network, and every impersonator shows up beside it.
- newA when-it-hit timeline in each drawer shows when the bot crawled across your selected window, so a steady crawl and a sudden burst stop looking the same. Intervals that are mostly errors are tinted red, because a burst that is all errors is probing, not crawling.
- newUnclassified bots are now drillable. Expand any name in Other declared bots to see its networks, activity, paths and content types. Being unverified is normal in this group, and the drawer says so plainly instead of treating every SEO tool as suspicious.
- newTwo new always-on checks watch the bot population itself. New bot detected fires when a name that has never crawled your store arrives with real volume. Bot volume spike fires when a known bot runs at a multiple of its own usual rate. Both alerts link straight to the bot's drill-down, and both are detection-only: nothing is blocked without you.
- newOne click from a fake crawler row now drafts a challenge rule for that network. The rule is generated disabled, for your review. Nothing is applied until you decide.
- improvedAmazon's shopping crawlers (amazonproductbot, Amzn-SearchBot) are now recognised names with their own rows, verification status and banked weekly history.
Your bot history, kept for good
18 Aug 2026- newBots over time on the Bots & agents page. Every completed week, Edge banks a per-bot summary (requests, verified share, POSTs, errors, origin load) and keeps it indefinitely, long after the raw log window rolls off. The panel charts your busiest agents week by week with change against the prior week. The banked rows hold a bot name and counters only: no IPs, no URLs, no query strings, no personal data.
- newDownload CSV exports the same weekly history, one row per bot per week, ready for your own reporting tools. No log pipeline, no warehouse, no BI licence required.
- newOptional weekly bot report email. Turn it on in Settings and each Monday you get the previous week's agents with their week-over-week changes, sent to your notification address.
- newWhat it fetched: expand any bot to see its traffic split by content type. Pages and data mean the bot is reading your catalogue; heavy image and asset weight is the signature of media harvesting. Requires the EdgeResponseContentType field on your Logpush job; the help article shows how to add it.
Every outage, explained
18 Aug 2026- newMonitor detail pages gain an Outages panel. Every failure episode in the range is listed with when it started, an estimated duration, the cause (timeout, connection, TLS, or the HTTP status code returned), and the individual failed checks on expand. Previously a failure older than the recent-checks list was effectively invisible.
- newShort blips are no longer lost. Episodes are rebuilt from the check history itself, so a failure that recovered before the alert threshold still appears, labelled below alert threshold. Three scattered failed checks and one fifteen-minute outage now read as the different situations they are.
- improvedEpisodes that did alert link straight to the alert, with the exact error message recorded at the time and, for journeys, which step failed.
- improvedThe uptime strip now distinguishes slow from broken: green means all checks passed, amber means slow but successful (still counted as up, matching the uptime figure), red means a failure. Red bars are clickable and jump to the matching outage.
Know exactly what every bot touched
18 Aug 2026- improvedExpanding a bot or crawler on the Bots & agents page now shows the paths it actually hit. Previously most of a busy crawler's traffic collapsed into a single catch-all row because bot paths competed with your whole storefront for space; bot traffic is now captured separately, so the detail survives. Where detail ends, the drawer tells you how many further requests it holds no per-path detail for, instead of hiding them.
- newThe Verified-bot impersonation panel opens with a plain-English summary: what the traffic claims to be, what network it really comes from, and whether any of it touched checkout, auth, or cart paths. It is written by AI from the same figures the panel shows. The numbers and any drafted rule come from the deterministic pipeline, and nothing is applied without your approval.
- improvedImpersonation rows now name the network next to its AS number, and each row's drill-down shows only that network's fake traffic, so two networks running the same disguise no longer blur together.
- newA new Other declared bots panel lists what is inside the unclassified-bots group by the name each bot gives itself, with its request volume and verification status.
- newEvery bot drill-down links to a forensic capture window scoped to that one bot: exact URLs as sent, query strings included if you ask, and the IPs behind the traffic.
See what traffic is actually costing you
17 Aug 2026- newNew Origin bot load column on the Offenders page. Automated traffic your cache serves costs your origin nothing, however much of it there is. Sort by this column to rank networks by the automation that actually reached you, so the ones costing you real capacity rise to the top even when they are not the largest by volume.
- newNew What changed page under Monitor. It compares the current window against the one before it and lists the networks, paths, countries and browsers that moved most, with a plain-English summary. Each row shows how much of the change reached your origin, so a large but cache-served increase is visibly different from a smaller one that cost you.
- newThe ASN detail page gains an Automation and origin load card, showing how a network's traffic splits between human and automated, how much of its automation reached your origin, and what that network cost your origin in milliseconds.
- improvedAlerts now show how long a condition has been firing continuously, and how many times it has stopped and restarted. The list is ordered by impact by default rather than by newest, so a long-running problem no longer sits below a page of smaller, more recent ones. Sorting by Newest is still available.
- improvedA condition that stops and restarts is now tracked as one alert with a flare count, instead of raising a new alert every time it comes back. Alerts also wait briefly before closing, so a brief pause no longer ends one prematurely.
- improvedTraffic spike alerts now require the spike to have actually reached your origin. A surge your cache absorbs no longer raises an alert, which removes a large share of spike alerts that never represented a cost to you. Networks genuinely reaching your origin alert exactly as before, and the threshold is adjustable on the Rules page.
Plain-English explanations
12 Jul 2026- newEvery alert now carries a plain-English brief of what happened: who is behind the traffic, what kind of network it came from, how it compares to your baseline, and whether the same network has been seen before.
- newEvery suggested rule now carries a note on exactly what it would and would not block, before you decide to apply it.
- newThe weekly comparison now opens with a written summary of your week in traffic, aware of the promo weeks you tagged.
- newThe AI only ever explains. Detection comes from the detectors, rules from the deterministic pipeline, and nothing is applied without your approval.
Campaign and drop windows
11 Jul 2026- newDeclare a sale, email send or product drop on the new Campaigns page and the volume detectors you choose hold their fire for the window. Every held alert is recorded, so you can see afterwards exactly what Edge suppressed and why.
- newSecurity detectors are never suppressed: credential stuffing, card-testing signals and probes stay live through every sale, because attackers hide behind them. Windows cap at 14 days.
- newEach window gets a report over its exact time range: requests, egress, the automated share of scored traffic, and how much of the campaign's traffic never reached your tag analytics.
Search abuse detection
11 Jul 2026- newNew detector: search abuse. Catches networks flooding your search and suggestion endpoints with bot-scored traffic, measured against each network's own baseline. Protects origin cost and the signals your search and personalisation tools learn from.
- newCloudflare-verified crawlers are excluded before detection, so Googlebot browsing your categories can never trigger it. Ships in tune-first mode; enable it from the Rules page.
- newEvery search-abuse alert carries a ready-to-apply, per-visitor rate limit for the search endpoint, challenge-first as always.
See what your analytics never saw
10 Jul 2026- newNew on the Overview: What tag analytics never sees. The share of your traffic that could never have fired an Adobe or GA tag (API clients, declared crawlers, no-user-agent scripts), split from browser-shaped traffic and its bot-scored slice.
- newExport Adobe Analytics bot rules from any network detail page: the offender's top observed IPs as a ready-to-import CSV for Admin, Bot Rules, Import File. Each rule carries a provenance description.
Alerts in Slack
10 Jul 2026- newSend alerts to Slack: paste an incoming-webhook URL in Settings and alerts arrive as formatted messages with severity colours, the affected network and path, and a link straight into Edge.
- newSame behaviour as Teams: correlated incidents post one message rather than a cascade, the pause switch silences it, and a Send test message button verifies the connection before you save.
Alerts in Microsoft Teams
10 Jul 2026- newSend alerts to Microsoft Teams: paste a Workflows webhook URL in Settings and alerts arrive as cards showing severity, the affected network and path, and a link straight into Edge.
- newCorrelated incidents post one card rather than a cascade, and the alerts pause switch silences Teams along with email. Webhooks keep firing for on-call tooling.
- newA Send test card button in Settings verifies the connection before you save.
Guided response: every alert carries its fix
9 Jul 2026- newEvery alert now includes the exact eCDN rule to stop the attack: the firewall or rate-limit expression, a ready-to-paste CDN Zones API call, and the Business Manager steps, challenge-first so real shoppers pass.
- newEdge never changes your WAF on its own. You review and approve every rule; one-click apply and opt-in automatic protection are on the roadmap.
- improvedAlert emails and webhooks carry the suggested rule as a one-line summary.
Traffic intelligence & threat detection
23 Jun 2026- newOverview, Offenders, Paths and IPs surface your edge traffic shape — worst-behaving ASNs and per-path 499, 4xx and cache-bypass rates.
- newProbe & scanner detection classifies reconnaissance (WordPress, secrets, git, SQL dumps, admin, tenant-targeted) by family.
- newSSL/TLS certificate inventory with expiry monitoring, plus configurable detector rules and alerts.
Blankitt DMARC
Explore DMARC →Gateway impact, security-gateway identification, and RFC 9989 tracking
2026-08-16- Gateway impact: grades now measure what you control. When a recipient's security gateway (Check Point/Avanan, Mimecast, Proofpoint) modifies your mail in transit and re-delivers it, so your own reject policy destroys it, those failures no longer drag down your grade. A Gateway impact panel names the gateway, the volume lost, and the fix.
- Security gateways identified by name. Traffic relayed through Check Point, Mimecast, Proofpoint, Barracuda, Cisco or Sophos gateways is now identified with confidence instead of showing as unknown.
- RFC 9989 transition tracking. DMARC became a full Internet Standard in May 2026. Every tag in your DMARC record is annotated with its spec status (current, new or deprecated) with guidance on hover.
- Spec migration checklist. Domains still carrying removed tags (pct=, rf=, ri=) are listed with a corrected record ready to copy. Deprecated tags never affect your grade.
Version 1.3.0
15 Aug 2026- newNew SPF IP usage panel — see which SPF entries actually send, which are dead weight you can remove, and which senders are missing from your record entirely.
- newNew Provider setup panel — each detected sending service checked against the DNS records it requires, with the exact missing entries and a one-click live re-verify.
- newTrack your sending subdomains so their DNS records are checked alongside the root domain.
- newThe DNS panel now grades each DKIM key's strength — weak 1024-bit and revoked keys are flagged.
- newTwo new alert thresholds — get emailed when your SPF record nears the 10-lookup limit or a published DKIM key is weaker than you allow.
- newZipped DMARC reports now import — some providers send .zip instead of .xml.gz, and both now work everywhere reports come in.
- improvedThe dashboard now loads instantly — data is precomputed and refreshed the moment new reports arrive.
- improvedA visual refresh across the whole app — clearer cards, smooth loading, an explanation on every panel, long lists that fold, and a domain page reorganised into a natural workflow order.
- fixedAlert threshold settings now save all fields correctly.
Smarter detection & guided fixes
15 Jun 2026- newFix Groups now names the exact record to add — the missing SPF include or unpublished DKIM selector — with a link to the vendor's setup guide.
- improvedSharper sender recognition: more email vendors identified automatically, and the list keeps improving without app updates.
- newPer-domain reporter analytics — see which providers send your DMARC reports.
- newThe DNS panel now shows DNSSEC status, zone delegation, and parent-domain records.
- newPer-domain alert thresholds with email alerts when alignment drops or failing senders spike.
- improvedA new volume-trend chart, a clearer compliance scorecard, and a redesigned policy simulator.
- newOpt in under Settings → Shared detection to help improve vendor recognition for everyone.
A richer DMARC workspace
14 Jun 2026- newPolicy Progression Wizard — readiness scoring to guide you none → quarantine → reject.
- newCompliance grade (A–F) plus a printable compliance report with recommendations.
- newNew Offenders page with search, filters and sorting.
- newGetting Started checklist and an in-app DMARC Guide.
- improvedDashboard now shows trends, policy mix and domains needing attention.
- newBuilt-in help: articles, an assistant, and contact — bottom-right.
Self-serve plans & domains
13 Jun 2026- newChange your plan (up or down) and add extra domains right inside Settings.
- newPer-domain data export before deleting, and a domain-cap-aware add flow.
Blankitt HR
Explore HR →2026-27 statutory engine, reform-ready
5 Jul 2026- newDay-one SSP under the reformed rules: no lower earnings limit, no waiting days, and a weekly rate of the lower of £123.25 or 80% of average weekly earnings.
- fixedStatutory rate tables re-verified against GOV.UK for 2024-25, 2025-26 and 2026-27 — every calculation now picks the right year's table automatically.
- newProvision users automatically from Microsoft Entra ID via SCIM.
US-ready records and a sidebar that knows who you are
3 Jul 2026- newUS employee support: worksites, federal and state tax fields, and US-specific onboarding alongside UK records.
- improvedThe sidebar now adapts to role and country — employees see their own workspace, and country-specific items only show where they apply.
Comms that reach the right people
26 Jun 2026- newAudience-scoped announcements — target by location or role instead of broadcasting to everyone.
- newPolls and @-mentions in the unified company feed.
- improvedRecognition controls tuned for busier feeds.
Rotas, time & attendance, and reports you build yourself
23 Jun 2026- newWorkforce management: rota builder with shift patterns, open shifts with approval flows, clock-in/out, and worked hours flowing straight into payroll.
- newNo-code report builder over eight HR datasets, with scheduled email delivery and CSV export.
- newCandidates can receive AI interview feedback via a secure magic link — with human review before anything sends.
Smarter recruitment and people analytics
20 Jun 2026- newRecruitment upgraded: interview scorecards, job-board posting, blind screening with a DEI view, a searchable talent pool, and interview calendar sync.
- newAI CV ingestion with candidate summaries and skill-match against the job spec.
- newSeven people-ops reports — headcount, turnover, absence and more — with scheduled delivery and point-in-time views.
- newAnnouncements, peer recognition, awards and length-of-service celebrations.
Learning management, end to end
16 Jun 2026- newCourse catalog, enrolments, quizzes, certificates and video lessons — with completion reporting and automatic reminders.
UK payroll, end to end
29 May 2026- newFull UK payroll engine: PAYE, NI, statutory payments, pension auto-enrolment, P45, P60 and P11D.
- newRTI submissions (FPS and EPS) generated with every pay run — live filing switches on with HMRC recognition.
- newSkills matrix and training-needs analysis in Learning & Development.
Self-service, e-signing and a help centre
25 May 2026- newEmployee self-service portal — payslips, leave and personal details in one place.
- newDocument e-signing built in — offers and policies signed without another subscription.
- new360° feedback and calibration for performance reviews.
- newA help centre with guides, FAQs and in-app support.
Blankitt HR opens in early access
23 May 2026- newCore HR: people records, leave management, documents and the org chart.
- newRecruitment, performance reviews, learning & development, and ER case management — included from day one, on every tier.
Blankitt Draw
Explore Draw →A public API, webhooks and incidents
3 Jul 2026- newPublic API with per-workspace keys and OpenAPI documentation.
- newIPAM data over the API — pull your address ledger into other tooling.
- newWebhook ingress with incident tracking, and signed webhook egress for change events.
Sharper insights, cleaner properties
29 Jun 2026- newA browsable Rules & Insights catalog under Help.
- improvedContextual tips no longer overstate — HSRP rules now check real redundancy before flagging.
- newOut-of-band management IP field on device properties.
- improvedConnection media badges reveal on hover or selection instead of cluttering the canvas.
IPAM-lite and team workflows
28 Jun 2026- newIPAM-lite ledger with smarter gateway insights and L3-switch awareness.
- newWorkspace audit log.
- newOrg-shared templates and invite-by-link for teams.
- newSCIM hook for directory-driven provisioning.
Blankitt Marketing
Explore Marketing →Campaigns, automation & analytics
15 Jun 2026- newCampaigns: turn a short brief into a ready-to-send email, target an audience, and track sends, opens and clicks.
- newOmni-channel — adapt a campaign into X posts and schedule them alongside the email send.
- newSequences: multi-step automated email follow-ups with enrollment and exit-on-reply.
- newAudiences: build static lists or dynamic segments with a live count preview.
- newReusable email templates, organised by category.
- newAnalytics: sends, opens, clicks and unsubscribes over time, per campaign and per sequence.
Marketing console is live
14 Jun 2026- newLead capture from the blankitt.com Mail Check assessment now flows straight into Contacts.
- newContacts: search, status filters, add, and CSV import.
- newDashboard with contact counts, sources and recent activity.
- newBuilt-in help and feedback — bottom-right.
Blankitt Finance
Explore Finance →Group consolidation for multi-entity businesses
29 May 2026- newConsolidate subsidiaries with ownership percentages and minority (non-controlling) interest handled properly.
- newIntercompany eliminations so group numbers aren't double-counted.
- newCurrency translation reserve for non-GBP subsidiaries.
- newEquity-method consolidation for associates, plus partial-VAT-relief apportionment.
Departmental permissions
26 May 2026- newDepartmental read-scoping across transactions, reports and lists — people see their department, not the company.
- newDepartmental dashboards and a department filter on P&L, balance sheet and aged reports.
- newOrg-chart hierarchy view and an audit log for cross-department actions.
Payment runs, remittances and bad-debt relief
25 May 2026- newFaster Payments single-pay with a bank-ready instruction PDF.
- newPer-supplier remittance PDFs emailed automatically, with per-supplier opt-out.
- newVAT bad-debt relief claimed automatically on write-off (Box 4), with the 4-year-6-month window enforced.
- improvedGoods-received notes as PDFs and an audit trail on purchase-order emails.
Fixed assets
22 May 2026- newFixed-asset register with a depreciation engine.
- improvedVAT returns now respect your VAT scheme.
Making Tax Digital VAT
17 May 2026- newMTD VAT returns prepared straight from the ledger.
- improvedEvery record is entity-aware — the foundation for running more than one business.
Real bank feeds
24 Apr 2026- newOpen Banking bank connections via TrueLayer — transactions flow in for reconciliation.
Invoicing, end to end
3 Apr 2026- newFull-lifecycle invoicing with PDF generation and your company branding.
- newInvoice templates and recurring invoices.
- newMulti-currency invoicing with Pay Now payment links.
Page generated 31 August 2026. In-product “What's new” panels update the moment an entry ships; this page refreshes with each site deploy.
The fastest way to judge a product is to watch it move.
Everything above is live — open a fully-loaded demo workspace and see it for yourself, no sales call.