You know first.
You know what to report.
When a client’s email or site breaks, you find out first — and you know exactly what to send your host.
What we check
The full signal set behind every verdict — grouped by area, so you can see exactly what we watch.
- MX records valid & resolvable
- SMTP on port 25 (timeout / refused / 5xx)
- Mail-server TLS cert (25 / 465 / 587)
- Reverse DNS (PTR) + FCrDNS
- SPF record & policy (+all / 10-lookup cap)
- DKIM key published
- DMARC policy (missing / p=none)
- Validity (expired / self-signed)
- Expiry reminder (≤14d / ≤7d)
- Hostname match (apex & www)
- Chain completeness
- HTTP(S) reachability (CDN-aware)
- Multi-location consensus
- HTTP 5xx server errors
- TCP service ports (FTP / SSH)
- WAF / challenge blocks
- Resolution & NXDOMAIN reason
- Nameserver change / migration
- Dangling A/CNAME & takeover
- Hosting pointing mismatch
- MX propagation & consistency
- Expiry reminder (≤30d / ≤7d)
- Registry hold / pending delete
- Registrar change
- Registrant change
- Google Safe Browsing
- Mail IP on DNSBL (Spamhaus)
- Domain on URIBL / SURBL
- Exposed files (.git / .env / backups)
- Defacement (content change)
- Injected malware / phishing
- Slow TTFB (>800ms)
- TTFB regression vs baseline
Who’s responsible for the fix — and what to send
Every problem tells you one thing plainly: who needs to fix it — you or your upstream provider. When it’s on their side, we hand you the exact message to send, with the facts already assembled under your name.
The problem is on your side. We name the exact change to make — e.g. “renew the SSL certificate in cPanel → SSL/TLS.”
The fault is on your host’s infrastructure. You can’t fix it — but you can escalate it fast with the ready-made message on the right.
When the facts don’t point clearly to one side, we don’t guess. We mark the fix as unclear and hand you exactly what we detected — status codes, timings, records — so you can judge which side the ball is on.
This isn’t another uptime monitor
Uptime tools tell you a light went red and hand you a ping. We tell you the mail is bouncing because the MX certificate expired two days ago, whose side it’s on, and give you the report to send your host. It’s not cheaper monitoring — it’s a layer you can bill for.
When a whole server goes down
You don’t want six panic alerts — you want one: what went down, that it’s your host’s side, and the message ready to send. Here’s what that looks like.
Sites behind Cloudflare hide their real server, so we flag those honestly instead of pretending we can group them.
What we don’t do
We detect and tell you what to do — we don’t log in and “fix” things on your servers.
The deep mailbox stuff — full inbox, IMAP, single-recipient issues — needs panel access. That comes later, once the tool has earned your trust.
A single 500 could be the app, a plugin, or the server. We won’t guess and blame the wrong side — you get the facts and a safe next step instead.
An honest “we’re not sure” protects your credibility. A confident wrong answer destroys it.
Pricing
Free tells you something’s wrong. Starter tells you what — and gives you the report to send and the weekly artifact to bill for.
Questions, answered
Point us at a domain — we’ll start watching it.
Enter a domain and create your free account. We scan it right away and keep re-checking it.