R9 — Published policy drifted from approved baseline
← All help articles · Recommendation rules
Triggers when: the normalized current_published_policy (read live from DNS) differs from the approved_baseline_policy you deliberately set — and only once a baseline actually exists, since there's nothing to drift from before that. This is the same condition the daily alerting digest's policy-drift check watches, computed independently so it doesn't depend on this rule engine having run.
What to do: a mismatch means either someone changed the DNS record outside your normal process, or DNS itself was tampered with — treat it as worth investigating promptly, not routine drift. If the change was intentional, re-approve the new policy as the baseline once you've confirmed it.