TLS certificates · Security headers · Cookies
Get an email when your TLS, headers or cookies get worse
We check the domains you've verified on a schedule and email you only when something regresses — a header dropped in Friday's deploy, a certificate nobody renewed. Uptime monitoring, but for your security config.
- Free for 1 domain
- No card
- No agent to install
- Set up in ~2 minutes
The problem
Every scanner tells you how you're doing today. None tell you when it changes.
You ran the free header scanner once. It said A. Then someone shipped a config change, a CDN setting moved, a certificate auto-renewal quietly failed — and nothing told you, because nothing was watching. The next time you find out is when a customer does.
A one-off scan tells you where you were that afternoon. We tell you the minute it changes — by email, while you can still fix it before anyone else notices.
How it works
Three steps, then you can forget about it
Prove it's yours
Add a domain and publish one proof — a DNS TXT record, a file under /.well-known/, or a meta tag. Nothing gets checked until ownership is proven, and we re-check that proof weekly.
We watch it
One ordinary HTTPS request on a schedule — every five minutes on a paid plan — from published, dedicated IP addresses you can allowlist. The first run becomes your baseline.
You hear from us rarely
Only when something moves away from that baseline, and only after it's confirmed on a second check. One email per site per run. Acknowledge it and the new configuration becomes your baseline.
What you get
One page per domain. Usually boring.
What each check looked at and what it currently sees, what it costs you if a failure sits there, anything open, and a history that only records the moments something changed.
On a good week there's nothing here you need to act on — which is the entire idea.
example.com
Verified · checked 3 minutes ago
The protection this header enforced in visitors' browsers is no longer applied.
TLS certificate ok
Expires in 68 days · Let's Encrypt · TLSv1.3
Security headers and cookies warn
missing hsts · 4 other headers present
What happens if this isn't fixed
A visitor typing the bare hostname is served over http first, and that request is interceptable.
Change history
Jul 26, 09:14 — security_headers — warn — 72
Jun 02, 11:47 — tls_certificate — ok — 100
Two rows in two months. Nothing else changed.
Coverage
What we check
Everything below comes from a single ordinary request to your site — the same one a visitor's browser makes. We read what you already serve publicly, and compare it to what you served last time.
TLS certificate
- Expiry — a warning at 14 days, urgent at 7
- Certificate replaced by a different issuer
- Intermediate certificates no longer sent
- Names dropped from the certificate
- Protocol downgraded below TLS 1.2
Security headers
- HSTS, CSP, X-Frame-Options, X-Content-Type-Options
- Referrer-Policy and Permissions-Policy
- COOP, COEP and CORP
- Integrity-Policy, enforcing and report-only
Removed or weakened — a policy that loses a directive counts, not just one that disappears.
Cookie flags
- A cookie that loses Secure
- A cookie that loses HttpOnly
- SameSite quietly weakened
Tracked per cookie name, so one loosened session cookie doesn't hide in the noise.
And then
What you get out of it
A check you can run from CI Pro and Agency
Call our webhook after a deploy and get a machine-readable verdict back — passed, or regressed with the specific changes. Findings from a deploy are framed as "your deploy changed this, was that intentional?" rather than paged at you.
Email authentication
We watch the DMARC and SPF records that stop strangers sending mail as your domain, and tell you when they weaken — a policy quietly relaxed to monitoring-only, or an SPF record that grew past the lookup limit and stopped being evaluated at all. Both leave a record in place that still looks configured, which is why nothing else catches them.
Findings and history
Every check says what it looked at, why that matters and what it costs you left unfixed — plus a change history that records a row only when something actually changed, so the log is the story of your posture, not a wall of identical rows.
Evidence you can hand over
A per-day CSV of every check we ran — including the days we didn't, stated outright. The artifact for the auditor who asks whether a control was actually monitored. It records what we observed, and never claims who changed anything.
On the roadmap Certificate renewal health, CAA, MTA-STS, DNS delegation health, registrar transfer-lock drift, and domain expiry. Not built yet — listed so you know where this is going, not so you buy it today.
Why it stays quiet
The hard part isn't noticing. It's staying quiet.
Any tool can diff two responses. The reason most monitoring gets muted within a month is that it can't tell a real regression from your own Tuesday deploy. Everything below exists to make sure the email you get is one you actually want.
Most weeks, nothing. That's the product working. The week something breaks, you find out in minutes instead of from a customer.
Compared to what you accepted, not to yesterday
Drift is measured against a baseline you've agreed to. Change something deliberately, acknowledge it once, and that becomes the new normal — we won't keep raising it.
Confirmed before it's sent
Deploys flap. A change has to still be there on the next check before we tell you, so a thirty-second blip during a rollout never reaches your inbox.
One email per site, per run
A deploy that changes six headers is one message listing six things, with a single button to accept them all — not six separate alerts.
Snooze, without pretending it's fine
Mid-migration? Silence an alert for a few hours without accepting the change as correct. It comes back when you asked it to, and closes itself if you fixed it meanwhile.
Reminders only for the serious things
An urgent alert you never acknowledged is repeated a few times, because one unread Friday email shouldn't lose you a week. Everything lower stays said-once.
Where the line is
We are not a scanner, and that's the point
Everything we do is an ordinary HTTPS request to a domain you've proven you own, plus the public DNS records that domain publishes. Nothing else. That's what makes this safe to run against production continuously, cheap enough to be worth $19 a month, and free of the legal paperwork an active scan drags along.
What we do
- Request your homepage the way a browser would, and read the response
- Check ownership before anything runs, and re-check it weekly
- Come from dedicated, published IP addresses you can allowlist
- Identify ourselves in the user agent, with a link explaining who we are
- Stop immediately if a domain is paused or ownership lapses
What we never do
- Port scanning, vulnerability probing, or anything resembling a pentest
- Crawling your site or submitting forms
- Logging in, or touching anything behind authentication
- Checking a domain you haven't proven you control
- Installing an agent, or asking for access to your servers
A passing check means the things we watch haven't got worse. It isn't a certification, an audit, or a claim that your site is secure — and we won't sell it as one.
Pricing
Pricing
Flat and public. No "contact sales", no per-scan pricing, no quote that depends on how big your site is.
Free
$0
One domain, checked weekly
- All checks included — nothing is paywalled
- Email alerts on regression
- Dashboard, findings and history
Pro
Recommended$19/month
Five domains, checked every 5 minutes
- Everything in Free
- Deploy webhook and CI verdict
- Twelve months of evidence history
Agency
$99/month
Twenty-five client domains, every 5 minutes
- Everything in Pro
- All clients under one login
- Three years of evidence history
Replaces the certificate-expiry alert and the header checker you're already paying for — and adds the part neither does: telling you when it changes.
Questions
Questions you're probably about to ask
Email, and only email. There's no Slack app or outbound webhook yet — if your team routes nothing to inboxes, this won't fit you today.
You can — the diff is the easy part. The work is not paging you for your own deploy: baselines you've accepted, a second check before anything is sent, grouping a six-header change into one email, and a snooze that doesn't mean "this is fine now".
On a five-minute plan, 288 requests per domain per day — one ordinary GET each, the same request a browser makes. On the free plan, one a week.
A user agent of securitycanaries-monitor/1.0 with a link back to us, from fixed addresses you can allowlist in your WAF. The addresses are published here.
Your homepage, over HTTPS. Specific paths and per-subdomain monitoring aren't supported yet.
Your domains drop to the free cadence. Nothing is deleted, and your history stays readable for the free plan's window.
Get started
Find out the next time it changes
Add a domain, publish one proof, and you're monitored. It takes about two minutes, and the first domain is free for as long as you want it.