Website Guardian watches uptime, SSL, domain expiry, DMARC/SPF, blacklist status, and security headers around the clock — and alerts you with exactly how to fix it, not just that something's wrong.
Results in seconds. No signup required for the free scan.
Health score
Checked 2 minutes ago
DMARC record missing
Fix: add the TXT record we generate to your DNS
Passive only — we never touch your server
Checks run on your schedule, down to 5 minutes
Every alert includes a fix, not just a diagnosis
Instant Telegram alerts, plus the in-app bell
Just the domain — nothing to install, no credentials to hand over. Six core checks turn on automatically.
Uptime, SSL, domain expiry, DMARC/SPF, blacklist status, and security headers — checked from the outside, same as any real visitor or DNS resolver.
In-app and Telegram, with plain-language explanations — for DMARC, we hand you the exact DNS record to paste in.
Every check is passive and read-only — we look at your site the way a browser, a search engine, or a DNS resolver would.
Uptime
HTTP checks down to every 5 minutes, with response time tracked over time.
SSL certificate
Alerted 14 days before expiry, not the morning browsers start warning visitors.
Core Web Vitals
Real-user LCP/CLS/INP field data from Chrome, no manual setup needed.
Lighthouse audits
Full performance/SEO/accessibility scoring on demand, without slowing down routine checks.
Blacklist / malware
Google Safe Browsing status, before "Dangerous site" shows to every visitor.
Security headers
CSP, HSTS, X-Frame-Options and more — the headers most sites forget to set.
Exposed files
Catches public .env, .git, and backup files before someone else finds them.
Mixed content
Finds insecure http:// resources on your https pages that browsers block or flag.
Certificate Transparency
Alerts when a new SSL certificate is issued for your domain you didn't expect.
Content defacement
Flags a sudden, drastic homepage change — an early signal of compromise.
Vulnerable plugins
Detects CMS/plugin versions and cross-references public CVE databases.
Open ports
Flags unexpected open ports on your server — a common early foothold for attackers.
Domain expiry
WHOIS renewal reminders — domains lapse more often than you'd think.
DMARC / SPF
Catches missing email spoofing protection, with the exact DNS record to paste in.
DNS ownership
Alerts the moment your nameservers or registrar change — the earliest sign of a hijack.
Typosquat domains
Finds newly-registered look-alike domains before they're used to phish customers.
Index coverage
Catches when Google can no longer index your homepage.
Search traffic
Flags a sudden week-over-week drop in Google search clicks.
Keyword tracking
Watch your own list of terms for sudden ranking or visibility changes.
No login, no admin access, no server agent, no plugin. Every check works the same way an outside visitor or DNS resolver would see your site.
Zero-touch by design
We never ask for hosting, CMS, or server credentials — nothing to revoke if you ever leave.
We never modify your site
Purely observational — no auto-fixes, no code pushed, no risk of us breaking something ourselves.
Checked on a schedule, not once
Recurring checks avoid false alarms from a single dropped packet — an issue has to actually persist to alert you.
Auto-resolves when fixed
An alert closes itself the moment the next check confirms the issue is gone — no manual cleanup.
Real fixes, not jargon
DMARC alerts come with the exact record to paste into your DNS provider — not a link to go figure it out yourself.
You choose how loud it is
Critical issues can hit Telegram instantly; lower-priority findings stay in the in-app bell so you're not spammed.
Every plan runs the same checks — plans differ by how many sites you can monitor at once.
Free plan covers 1 site, forever. No credit card required.
Start monitoring free