Owl Keeper

Website monitoring for the sites you look after

Most of what takes a site down answers 200.

90 days · two outages · one spell of refused checks

The certificate lapses on a Sunday. The domain quietly expires. A staging robots.txt ships to production and search traffic drains away over a fortnight. Owl Keeper watches uptime, certificates, domain registration, DNS and mail authentication on one page — and tells you before your client does.

Start monitoring — it's free

Ten sites free. No card, no trial timer.

Your monitors

Live
Up
Marketing site HTTP

https://example.com

24h

100%

Down
Billing API HTTP

https://api.example.com/health

24h

98.2%

Paused
Mail relay MAIL

smtp.example.com:587

24h

99.9%

Websites, mail servers and TCP ports — alongside certificates, domains, DNS and mail records, on one page.

Everything that can quietly break, on one page

An uptime check asks one question and gets one answer. None of the following would fail it, and every one of them takes a site off the internet or quietly stops it earning — which is why they are watched here rather than sold to you as four more subscriptions.

One check, one moment
Up

GET https://example.com

200 OK · 188ms

What it never asked

  • Needs attention The certificate expires in 12 days.
  • Problem SPF needs 11 DNS lookups. Ten is the limit, and everything past it is ignored.
  • Problem A noindex rule is live on every page.
  • Needs attention HSTS is not set, so the first visit of the day is over plain HTTP.
The uptime check passed. Everything under the rule is the same site, the same second — and not one of those would have failed it.

Certificates and domains

Expiry dates, the issuing authority, whether the chain is complete and whether the certificate actually covers the hostname. Domain registration is read from the registry, along with the registrar lock and DNSSEC — so a transfer someone did not authorise shows up as a change, not as a surprise.

Mail nobody trusts

SPF, DKIM, DMARC and MTA-STS decide whether your mail reaches an inbox or a spam folder. SPF lookups are counted through every include, because passing eleven is a silent failure that leaves the record looking perfectly reasonable.

Search engines shut out

A stray noindex or a copied "Disallow: /" takes a client's traffic to zero over a few days, and it is invisible until somebody notices the phone has stopped ringing.

Response security

HSTS, Content-Security-Policy, cookie flags and whether plain HTTP still answers without redirecting. Reported as findings you can read, not a letter grade you have to defend.

Ready for AI agents

Which of the conventions an AI agent looks for you actually publish — llms.txt, an MCP server card, Content Signals, an API catalogue. Recorded as facts, never as faults: publishing none of them is an ordinary site, not a broken one.

A record of what changed

Only changes are written down. A check that finds the same thing as yesterday records nothing, so the history is the list of things that actually moved — the issuer, the nameservers, the DMARC policy — instead of a year of identical rows.

What it does

Enough to answer "is it up, and how has it been lately?" without a dashboard you need training for.

One day of response times
00:00 — 186ms
01:00 — 181ms
02:00 — 178ms
03:00 — 184ms
04:00 — 179ms
05:00 — 190ms
06:00 — 203ms
07:00 — 214ms
08:00 — 226ms
09:00 — 241ms
10:00 — 268ms
11:00 — 297ms
12:00 — 334ms
13:00 — 372ms
14:00 — No data
15:00 — No data
16:00 — No data
17:00 — 205ms
18:00 — 192ms
19:00 — 188ms
20:00 — 183ms
21:00 — 180ms
22:00 — 177ms
23:00 — 182ms
The afternoon it slowed down, the three readings it never answered at all, and the recovery — drawn from the same heartbeats every uptime figure is counted from.

HTTP, TCP and mail checks

Check a URL for the status code you expect and a keyword in the body, open a TCP port to see if it answers, or greet a mail server and require STARTTLS. One tool for the three things that usually break.

Uptime history and response times

Every check is kept as a heartbeat, so you get uptime over 24 hours, 7 days and 30 days, a 90-day history bar, and a response-time chart with downtime shaded behind it.

Sites and tags

Every monitor hangs off a site, so a hostname carries its certificate, its domain registration and its mail records alongside its uptime. Tag the sites you look after and filter the whole estate down to one client.

Pause without losing history

Pause a monitor during planned maintenance and the scheduler skips it — no noise, no false incidents. You can still run a check by hand while it is paused, and nothing you have already recorded is thrown away.

Getting told, and telling everyone else

An alert is an interruption, and most monitoring earns yours cheaply. Nothing here is called down until it has failed the number of times you set, from more than one place — so the message that does arrive is one worth stopping for.

One alert, as it arrives
Down
Billing API HTTP

https://api.example.com/health

14:02

Down after 3 checks in a row. Frankfurt and Singapore could not reach it either, so this is the site rather than the route to it.

A single dropped packet never gets this far, and neither does one bad network path between us and the site.

Alerts that have earned the interruption

Nothing is called down until it has failed the number of times you set. A firewall answering 403 is reported as refusing the checker rather than as an outage, because the two are not the same thing and only one of them is your problem.

Webhooks to Slack, Discord or your own endpoint

Paste a Slack or Discord URL and messages are formatted for it. Anything else receives signed JSON, so you can put changes wherever your team already looks.

A status page you can send to anyone

Uptime, which services are answering, and when the certificate and registration renew — on an unguessable link that never shows monitor names, addresses or anything from the security checks. Withdraw it and the link stops working.

Readable in English and Spanish

The whole interface, including the alerts you are emailed. Set it per account, so one person can read it in Spanish while a colleague reads the same site in English.

Questions

How often is each check run?
You choose, from every minute to every hour. Certificates, domain registration, DNS and mail records move on the scale of months, so those are read once a day.
Will I be woken up by a single dropped packet?
No. You set how many checks in a row have to fail before anything is called down, so one bad response on a flaky network never becomes an alert.
Does it tell me before a certificate expires?
Yes — at 30, 14, 7, 3 and 1 days. Domain registration warns earlier, from 60 days, because recovering a lapsed domain is slow and expensive where a certificate can be reissued in minutes.
What happens if a site blocks the checker?
It is reported as refused rather than down. A firewall answering 401, 403 or 429 tells you nothing about whether visitors can reach the site, and calling that an outage is how people learn to ignore alerts.
Is it really free?
The free plan is free for good — ten sites, every check, no card and no trial timer running in the background. The paid plans buy more sites, faster checks and longer history, never a category of problem you are not told about.

Ten sites free, for real work

No card, no trial timer, and every check on every plan. Create an account, add your first site, and see what it finds.