What we watch

Six things that fail without telling you.

Every one of these is checked on a schedule from the day you enter your domain. You never configure any of it, and anything urgent reaches you the moment it is found, on every plan including the smallest.

Every scan is compared against the last

What changed, and when.

Checking a domain tells you what is true today. Comparing today against last week tells you what moved, who moved it, and on what date — which is the question nobody can answer after the fact.

Sent immediately, at any hour

Four changes mean somebody may be taking your domain, or that it is offline right now. These do not wait for the weekly email.

  • Your nameservers changed. Delegation moved. Whoever controls it controls your website, your mail, and therefore certificate issuance. This is what a hijack looks like from outside.
  • Your domain moved registrar. A transfer you did not start, while there is still a window to reverse it.
  • A hold or pending transfer appeared. clientHold and serverHold mean the domain is not resolving now. pendingTransfer means somebody started moving it.
  • Your mail servers changed, or disappeared. Redirected mail is the setup step for invoice fraud, and a domain with no MX silently loses every message sent to it.

In the weekly email

Changes worth knowing about, without interrupting your day.

  • Transfer lock removed — the protection that stops a domain being moved is no longer set.
  • SPF, DKIM or DMARC changed — including the previous value, so you can see exactly what it said before. These break during DNS edits made for unrelated reasons, and the failure is silent.
  • A certificate stopped covering a name — visitors to that name now see a warning.
  • Your certificate is from a different authority — expected if you changed provider, worth checking if you did not.
  • DNSSEC state changed, including the case where the zone is signed and the registry has no matching DS record. That one is severe enough to be sent immediately: for validating resolvers the domain simply does not exist.
  • Your CAA record changed or was removed — any authority may now issue certificates for you.
  • A new subdomain appeared — if you did not create it, somebody with access to your DNS did.
  • A subdomain stopped resolving — if the record still exists, it may now be claimable by somebody else.
  • New third-party scripts — anything your pages load has the access your own code has.

Recorded, never emailed

Some changes are good news. They belong in the history rather than in your inbox, because an alert that needs no action is how people learn to stop reading alerts.

  • Your certificate renewed — a new serial from the same authority. Evidence the automation was running on that date.
  • Your domain was renewed — the expiry moved forward.
  • A protection was added, or your site moved host.

None of this needs configuring. There are no thresholds to set and no rules to write, because every one of these is unambiguous: a record either changed or it did not. The comparison uses data we already read, so watching costs nothing extra beyond keeping it.

How the checks behave

Two kinds of message, and nothing in between.

The weekly email

Sent every week whether or not anything happened. It confirms the position, carries the number of days the record has run without a break, and lists anything that changed. Most weeks it says nothing broke, which is the point.

The urgent alert

Sent the moment something is found that has a deadline or has already failed. An approaching expiry, a certificate that stopped validating, mail authentication that broke. These are the same on every plan, because paywalling a warning is not something we are willing to do.

What you will not get

No alerts that need interpreting.

Plenty of monitoring tools report things that might be a problem. A page loaded slightly slower. A script appeared. A header changed. Each one arrives as a question rather than a fact, and answering it becomes your job.

We only report states that are unambiguously true. A date either passed or it did not. A record either validates or it does not. A subdomain either resolves or it does not. If a finding would need judgement to act on, we would rather not send it.

The practical effect is that you can trust the weekly email enough to skim it, and trust an urgent alert enough to act on it without checking first. That is the whole design.

See what is on your domain right now.

The first check is free and takes about ten seconds. No account, no card.

Check yours

See where your domain stands.

The free check finds everything at once, in about ten seconds. No account, no card.