Skip to content
Sitewatch by Engilane

Certificates, registries, spoofing

Find the problem before your client does.

Paste every domain you look after. Sitewatch reads the certificate each site is really serving, when the registration runs out, and whether anyone can send email as that domain. No account, no setup.

Up to 50 domains. Nothing is stored.

What each check means

Three questions, asked of public records.

Each one is a different source with a different failure mode, so each is reported separately rather than rolled into one score.

TLS

The certificate actually being served

Sitewatch opens a connection to port 443 and reads the certificate the server hands back, then reports who issued it and the day it stops being valid. It is the certificate a visitor's browser would be given, not one looked up in a database.

A site behind a proxy is reported as proxied rather than as a reading, because the party serving that certificate is also the party renewing it, and there is nothing for you to act on.

Registry

When the registration lapses

The expiry date held by the registry itself, with the registrar the domain sits at. A lapsed registration takes the site and the email down together, and it usually happens because a card on file expired rather than because anyone decided.

Some registries publish no date, and a few rate-limit lookups. Those come back as unread rather than as fine, because reporting a silence as a pass is the one failure that matters here.

DNS

Whether the domain can be spoofed

SPF and DMARC as published in DNS, read the way a receiving mail server reads them: whether they exist, and whether they actually instruct anyone to reject a forgery.

This says whether the records would stop a forgery, not whether your own mail is currently arriving. A domain that passes here can still have a misconfigured sender inside a passing policy.

What it cannot do

A check that fails quietly is worse than one that fails loudly.

This is a snapshot, not monitoring. It tells you the state of a list at the moment you asked, and it has no memory of the last time you asked. If a certificate expires next Tuesday and you last ran this on Monday, nothing here will tell you.

It does not test whether a site is up, whether it is fast, whether its content is correct, or whether its mail is currently being delivered. It reads three specific public records and reports what they say.

When a source cannot be read, the result says so rather than passing. An unread registry looks like could not be read, never like a clean bill of health, because the failure that costs you a client is the one that reported health on something it never looked at.

Who it is for

Anyone holding a list of domains that are not theirs.

Agencies, freelancers and in-house teams who look after sites they did not register, on registrars they do not control, with renewal notices going to an address nobody reads. The expensive version of this problem is a client calling about a browser warning you could have seen coming.

Built and maintained by one person, as part of Engilane. Wrong results are worth more to me than polite silence: karim@engilane.com.