The things that quietly kill a business online never announce themselves.
A certificate that fails to renew. A domain that lapses on an expired card. Quotes landing in spam because of an email record nobody set up. We check the invisible plumbing every week, state only what we can measure, and give you the fix in plain English.
You don't monitor your website every day. Hacker bots do.
40% of all web traffic is malicious bots
Thales 2026 Bad Bot ReportThe five ways businesses vanish
First, the scale of the thing. In 2025, 40% of all web traffic was malicious bots, the seventh consecutive year of growth, and one security vendor alone blocked 17.2 trillion bot requests over the year. Those bots are not attacking someone else: they sweep every domain on the internet, including yours, testing hundreds of weaknesses. Checking all of those is a penetration tester's job, and we do not pretend to do it. What we watch are the failures below: the most common ways small businesses actually get hurt, and the easiest to fix.
Don't know what these are? Don't worry, we've got you!
Your emails may already be going to spam.
Google and Yahoo now junk or reject mail from domains without SPF, DKIM and DMARC records. The cruelty is that you never find out: the customer just never replies to the quote. Most business owners have never heard these acronyms, and nothing in their inbox looks broken.
Strangers may be sending email as your domain, and getting you banned for spam.
Without those same records, anyone can put your domain in the from line. Their spam earns your domain the bad reputation: you get flagged for junk you never sent, and nothing tells you it is happening. Once a domain is marked as a spammer, that reputation is very hard to win back. You are not just losing emails; someone else may be spending your domain's good name.
Your certificate expires. Browsers block your site. Google follows.
When a certificate renewal quietly breaks, visitors stop seeing your website and start seeing a full-screen security warning, and your rankings follow it down. The first sign is usually a customer sending a screenshot. We count down expiry on your main domain and its www version separately, because they genuinely differ: we have seen a live business whose main domain had broken HTTPS for months while www worked fine. The owner had no idea.
Your domain lapses. Your website no longer exists.
A card expires at the registrar, the reminder goes to an old inbox, and the website and email die together, everywhere, at once. We watch registration health continuously.
Browsers judge you by security headers you have never heard of.
Missing security headers mark your site as risky to browsers, to scanners, and increasingly to AI systems deciding whom to trust and cite.
Fixed once is not fixed
These are one-minute fixes, and that is exactly the trap. A record that takes a minute to add takes a minute to lose, and nothing in DNS tells you when it happens.
- Records break silently all the time. A new email or hosting provider says “update your DNS” and old records get flattened. One website agency hands over to another and something gets tidied away. An SPF record still includes a service you stopped paying for. A certificate renewal quietly stops working after a hosting change.
- Attackers remove them on purpose. When a domain or DNS account is compromised, one of the quiet first moves is altering or removing SPF and DMARC so spoofed email sails through. Businesses have discovered a breach only after their customers started receiving convincing fake invoices from their own domain.
- The damage compounds while you are unaware. Every day a broken record goes unnoticed, the spam reputation deepens, and reputation is far harder to recover than the record was to fix.
The fix takes a minute. Knowing it is still fixed, every week, forever: that is the product.
Don't understand a finding? Ask your AI to walk you through it.
Connect the tracker to your AI assistant over MCP, the same one-minute connection that covers all your SEO data, and your security report stops being a checklist and becomes a conversation. The assistant arrives already briefed on your grade, every check and every finding, and answers in plain English with the exact fix.
Works with Claude, ChatGPT, Microsoft Copilot and more. The full story is in the Ask your data anything section.
Only what we can measure
Every check states a measurable fact. Anything we cannot measure is reported as unmeasured, never guessed, and there is no false “all clear”. Your site is graded A to F, with a fix-first list in plain English, re-checked on schedule with what changed laid out plainly. Professionals will recognise how rare that honesty is.
And it is included. Security monitoring is normally a separate product with its own bill. Here it comes with the tracker that already watches everything else about your visibility.