Frequently asked questions
Do you need access to my clients' hosting, DNS or email accounts? No. Everything is observed from the public internet: DNS answers, the HTTPS certificate, the redirect and response headers of the site root. We never log in to anything.
How do you know I am allowed to monitor a domain? You prove control of each domain with a DNS TXT record or a file at a fixed path on the site. Proof is re-checked weekly. If it fails, monitoring on that domain pauses until you re-verify.
What counts as one domain? The apex and www website endpoints plus the email DNS records at the apex. A shop or app on another hostname uses another slot.
Is this uptime monitoring? It includes a light form of it: the site root is checked every five minutes from one vantage point, an incident is opened after two consecutive failures and closed after the next success, and the monthly report shows the reachable percentage. It is not a multi-region uptime service and it makes no uptime guarantee.
Do you check the domain registration? Yes. Expiry date, registrar, transfer-lock status and the nameservers at the registry are read from the public RDAP record. Expiry within 60, 30, 14 and 7 days becomes a registration action; a registrar change, a removed lock or changed registry nameservers become review changes.
What does "what to do" mean on a report? Each item carries a short, approved next step in plain English, such as "renew the certificate before the date shown" or "confirm the new sender with the client". It is a suggestion for the agency, not an instruction and not a promise of the outcome.
How often do you check? Every six hours. A change is reported after a second observation at least 15 minutes later confirms it, so a flapping record does not become a false alarm. This is configuration monitoring, not uptime monitoring.
Will I get an email every day? Only on days with a confirmed change, a certificate action or a coverage gap. Routine certificate renewals and CDN address rotations are kept in the monthly report, not the digest.
Which DKIM selectors do you monitor? The ones you tell us plus about thirty common ones we probe at onboarding and weekly. Randomised selectors used by some providers cannot be discovered; the report says which selectors are covered.
Does a "p=reject" DMARC record mean my client's email is protected? The report shows the published policy and where it comes from. It does not test message alignment, deliverability or whether reports are read, and the wording never claims protection.
Can I get alerts in Slack or Teams? Yes. Add an incoming-webhook URL under Notifications for Slack, Microsoft Teams or a generic JSON webhook (signed with a secret you choose). Digests and availability incidents are posted there as well as emailed.
Can I remove your name from the reports? There is nothing to remove. Reports carry your logo, name, colour and footer only.
Can my clients log in?
No. Each account has one agency login. To give a client a report, create a client link from the Reports page: a read-only copy of that report at an unguessable address, in your branding, no login needed. Revoke it from the same page when you no longer want it readable. Or open the report and print it to PDF.
Is there one view of every client at once?
Yes. The dashboard shows every domain on one row: reachable now and over 30 days, days until the certificate and the registration expire, DNSSEC, SPF, DKIM selectors found, DMARC policy, MTA-STS, how many of the eight security headers are present, the HTTPS redirect, and blocklist status. Anything expiring inside 30 days (certificates) or 60 days (registrations) is listed at the top. The same summary arrives by email every Monday, and in Slack or Teams if you have a channel connected.
What is the blocklist check?
The site's address and the addresses of the client's mail servers are looked up on three public DNS blocklists (Spamhaus ZEN, SpamCop and Barracuda) at every observation. A listing is reported as a change with the list named, because mail from a listed server is likely to be rejected; the record shows when it started and when it cleared. One vantage point: where a list refuses queries from public resolvers, the report says "unavailable" rather than "clear".
Do you catch a staging noindex shipped to production?
Yes, and it is one of the reasons to have this running. Every six hours we read the home page and its robots.txt as a search engine would: a noindex in the meta robots tag or the X-Robots-Tag header, and a robots.txt that disallows every crawler. Either is reported as a change with the fix in plain English, and reported again when it clears. A site can otherwise sit unindexed for weeks before anyone notices the traffic is gone.
Do you check for mixed content?
Yes. Scripts, stylesheets and images loaded over plain http on an https page are listed by source. Ordinary links to http pages are not counted, because they are not mixed content.
Can Sequrit tell me if a client's home page breaks?
Yes. For each domain you can give text the home page must always contain (a heading, a phone number, a call to action) and text it must never contain ("Index of /", "Database error", "Coming soon"). Both are checked every six hours on the page as served to the public. A missing or unwanted phrase is reported like any other change, and reported again when it returns to normal. The page itself is never stored, only the verdict.
Can my clients check for themselves whether their site is up?
Yes. Publish a status page at an address you choose, carrying your logo, colour and footer and nothing of ours. It lists only the sites you add to it, whether each responds right now, and how much of the last 90 days it responded. No check results, no change history, nothing about your other clients. Unpublish it and the address returns a 404 at once. Ask your client before listing their site by name.
Can you watch a backup or a cron job that has no public page?
Yes, with heartbeats. Create one, give it a period and a grace window, and add a single line to the end of the job that calls its ping URL when the work finishes. If a ping does not arrive in time, you are told the same way as an outage, and told again when it starts reporting. Up to twenty per account. The job reports to us; Sequrit never reaches into the client's systems and cannot see why a job failed, only that it did not report.
Do you watch for certificates issued for my client's domain by someone else?
Yes, once a day, from the public Certificate Transparency logs. Every certificate ever issued for a domain is published there. Routine renewals by an authority that has issued for the domain before are recorded quietly. A certificate from an authority that has never issued for it is reported for review, because that is what an early domain takeover or a prepared phishing site looks like. If the logs cannot be read we say so; we never report "no certificates" because we could not ask.
Is there an API?
Yes, read-only, included. Create a token on the Notifications page and pull your domains, the portfolio, confirmed changes, availability incidents and heartbeats as JSON, so you can show them in your own dashboard or client portal. No endpoint can change anything, so a leaked token cannot be used to alter your account. Only a hash of each token is stored, which means we cannot recover one for you; revoke it and make another. 600 calls an hour per token.
Can colleagues or clients get the reports too?
Yes, up to five extra addresses per account. Each one confirms by its own link before anything is sent to it, and you can remove any of them at any time. Copies of every digest, incident notice and report go to them in your branding.
Can I add many domains at once?
Yes. On the Domains page, "Add several at once" takes one domain per line with an optional client label after a comma. Each domain still needs its own proof of authorisation before monitoring starts.
Is there an annual plan?
Yes: $495 USD a year, which is five months' money for twelve months of service, the same product and the same 25-domain limit. Monthly is $99. A monthly subscription can switch to annual from the billing page at any time; the unused part of the current month is credited. The 14-day refund on the first invoice applies to both.
What if a check fails? It is shown as unknown or stale, never as fine. Persistent gaps appear in the digest.
How do I cancel? From your account, in one click. Renewal stops; service runs to the end of the paid month. The first invoice is refundable in full within 14 days.
Where is my data stored and for how long? See the privacy notice. Observations and reports are kept for 90 days on a rolling basis; after cancellation you have 30 days to export.
Something else? cam@wlbr.app