Features
Anything can tell you a server stopped answering. The failures that actually cost you — a certificate that lapsed on a Sunday, a domain nobody renewed, mail that quietly stopped being trusted, a noindex that shipped by accident — all answer a perfectly healthy 200. Owl Watch watches for those on the same page, for every site, on every plan.
The first two rows are the category. The rest is why this exists.
| The question | A typical uptime tool | Owl Watch |
|---|---|---|
| Is the site answering? HTTP, TCP and mail checks, on your schedule. | Yes | Yes |
| Is the certificate about to expire? And whether the chain is complete and actually covers the hostname. | Yes | Yes |
| Is the domain about to lapse? Read from the registry, not guessed from a WHOIS scrape. | Sometimes | Yes |
| Has the registrar lock come off? The signal that precedes a domain being taken. Also DNSSEC. | No | Yes |
| Will your mail reach an inbox? SPF, DKIM, DMARC, MTA-STS and BIMI — with SPF lookups counted through every include. | No | Yes |
| Is the site telling search engines to go away? A stray noindex or a staging robots.txt that shipped to production. | No | Yes |
| Are the response headers doing anything? HSTS, CSP, cookie flags, and whether plain HTTP still answers. | No | Yes |
| What changed since last week? Only differences are written down, so the history is the list of things that moved. | No | Yes |
Mail authentication
Mail authentication is the failure with the longest fuse: nothing breaks, nothing alerts, and invoices simply stop arriving. It is normally a separate subscription, from a separate vendor, at a separate price. Here it is one of the daily passes over every domain you add.
Every include is followed and the DNS lookups are counted on the way. Passing ten is a permanent error that leaves the record looking completely reasonable — it is the single most common way a domain that used to deliver stops.
Whether the selectors you publish resolve, and what your DMARC policy actually instructs a receiver to do. A policy of none is reported as what it is: published, and doing nothing.
The newer half — whether mail to you is required to travel encrypted, and whether your logo is allowed to appear next to it. Reported as facts, never as faults.
The records exist, the hosts behind them exist, and the mail server actually answers a greeting and offers STARTTLS.
Whether the domain or its sending host has turned up on a list receivers consult before accepting anything from you.
A broken record stays broken until somebody fixes it. You are told when it breaks, not every morning until you do — which is how a reminder becomes something people filter away.
Certificates and domains
When it expires, who issued it, whether the chain is complete, and whether it covers the hostname it is actually serving — including wildcards, which cover one level and not two. Warnings at 30, 14, 7, 3 and 1 days.
Expiry, registrar and status straight from RDAP rather than scraped from a WHOIS page. Warnings start at 60 days, because a lapsed domain is slow and expensive to recover where a certificate can be reissued in minutes.
A lock coming off is the step before a domain is moved. Seeing it as a change on a Tuesday is the difference between a phone call and a recovery.
Who is authoritative for the domain, and whether that answer has changed since yesterday. Recorded alongside everything else on the site, not on a page of its own.
Alerts
A monitoring tool is only worth having if you still read its messages in month six. Everything here is arranged around not spending your attention.
A firewall answering 401, 403 or 429 tells you nothing about whether visitors can reach the site. It is reported as the checker being turned away, in amber, and the alert names the user agent to allow so you can fix it in one step.
Nothing is called down until it has failed as many times in a row as you decided. One dropped packet on a flaky network never becomes a message.
You are told when it comes back and how long it was gone, so the incident closes itself rather than leaving you to check.
Paste a Slack or Discord URL and messages are formatted for it. Anything else receives JSON signed with an HMAC, so a receiver can tell our POST from anyone else who learned the address.
Alerts are written in the language of the account they are addressed to — so one person can be told in Romanian while a colleague gets the same alert in English.
Planned maintenance skips the schedule instead of generating a false incident, and nothing already recorded is thrown away.
Looking after other people's sites
A client with a website, an API, a mail server and a certificate is one thing to look after — and four billable rows in a tool that charges by the row. Here a site carries its certificate, its registration, its DNS and its mail records at no extra count.
Tag by client, by hosting provider, by whatever you actually think in, and pull sixty sites down to the four you are being asked about.
Uptime, what is answering, and when the certificate and registration renew — on an unguessable link that never shows monitor names, addresses, or anything from the security checks. Withdraw it and the link stops working.
A check that finds the same thing as yesterday records nothing. What you can show a client is the list of what actually moved — the issuer, the nameservers, the DMARC policy — instead of a year of identical rows.
No analytics, no tracking pixels, no advertising and no third-party scripts anywhere in the product. There is nothing here to put in a data processing agreement that you would rather not.
Nothing on this page is held back for a higher tier. The plans differ by how many sites you watch and how often, never by what is looked at.