Frequently asked questions
Do you need access to my clients' hosting, DNS or email accounts? No. Everything is observed from the public internet: DNS answers, the HTTPS certificate, the redirect and response headers of the site root. We never log in to anything.
How do you know I am allowed to monitor a domain? You prove control of each domain with a DNS TXT record or a file at a fixed path on the site. Proof is re-checked weekly. If it fails, monitoring on that domain pauses until you re-verify.
What counts as one domain? The apex and www website endpoints plus the email DNS records at the apex. A shop or app on another hostname uses another slot.
Is this uptime monitoring? It includes a light form of it: the site root is checked every five minutes from one vantage point, an incident is opened after two consecutive failures and closed after the next success, and the monthly report shows the reachable percentage. It is not a multi-region uptime service and it makes no uptime guarantee.
Do you check the domain registration? Yes. Expiry date, registrar, transfer-lock status and the nameservers at the registry are read from the public RDAP record. Expiry within 60, 30, 14 and 7 days becomes a registration action; a registrar change, a removed lock or changed registry nameservers become review changes.
What does "what to do" mean on a report? Each item carries a short, approved next step in plain English, such as "renew the certificate before the date shown" or "confirm the new sender with the client". It is a suggestion for the agency, not an instruction and not a promise of the outcome.
How often do you check? Every six hours. A change is reported after a second observation at least 15 minutes later confirms it, so a flapping record does not become a false alarm. This is configuration monitoring, not uptime monitoring.
Will I get an email every day? Only on days with a confirmed change, a certificate action or a coverage gap. Routine certificate renewals and CDN address rotations are kept in the monthly report, not the digest.
Which DKIM selectors do you monitor? The ones you tell us plus about thirty common ones we probe at onboarding and weekly. Randomised selectors used by some providers cannot be discovered; the report says which selectors are covered.
Does a "p=reject" DMARC record mean my client's email is protected? The report shows the published policy and where it comes from. It does not test message alignment, deliverability or whether reports are read, and the wording never claims protection.
Can I get alerts in Slack or Teams? Yes. Add an incoming-webhook URL under Notifications for Slack, Microsoft Teams or a generic JSON webhook (signed with a secret you choose). Digests and availability incidents are posted there as well as emailed.
Can I remove your name from the reports? There is nothing to remove. Reports carry your logo, name, colour and footer only.
Can my clients log in? Not in the pilot. You print or save the report and send it yourself.
What if a check fails? It is shown as unknown or stale, never as fine. Persistent gaps appear in the digest.
How do I cancel? From your account, in one click. Renewal stops; service runs to the end of the paid month. The first invoice is refundable in full within 14 days.
Where is my data stored and for how long? See the privacy notice. Observations and reports are kept for 90 days on a rolling basis; after cancellation you have 30 days to export.
Something else? cam@wlbr.app