Skip to content

Uptime, certificates & passive security

Know your website.Know what to do next.

Uptime, certificates and security signals in one place. Clear explanations when something needs attention.

Start free

One website free. No card. Nothing to install.

Illustration: a sample OrionCmd dashboard slice with example readings. All readings are invented.

How it works

Spot the issue. Understand it. Share the next step.

Three sample findings, put to you the way OrionCmd would: the reading, what it means, then what to do next. Run the check again to see what a fresh reading looks like.

  • Uptime
  • TLS certificates
  • Domain & DNS
  • Email authentication
  • Reputation & homepage changes
  • Internet exposure
  • Firewall reachability
Pick an example
Then
studio.example
Needs attention

Certificate expires in 18 days

The certificate served on studio.example is valid until 23 September — 18 days from now. No replacement certificate has been served yet. Whether renewal is automatic or something a person has to do depends on your host.

Expires
2026-09-23 · in 18 days
Issuer
Let's Encrypt R11
TLS grade
A
Observed
2 hours ago
Run the check again to see what a fresh reading looks like.
Uptime & incidents

See when a check caught it — and when it came back.

A day-by-day history you can point at, and the incident behind every dip: what the check saw, from where, when the notice went out, and when it cleared. Times come from the checks themselves, so trouble can begin shortly before the first failed one.

  • Thirty days of history on every site, kept as evidence.
  • Incidents open and close on observations, not guesses.
  • Slow-but-serving is recorded too, not just hard failures.
Illustrative dashboard · sample data
shop.example
Recovered
30-day uptime
99.4%
Downtime · 30d
4h 12m
Avg. recovery
18m
Last 30 days
30 days agoToday
HTTP 503 — service unavailable22 Aug · 02:14 → 02:32

Four consecutive checks failed. Recovered on its own after 18 minutes; a notice went out at 02:16 and an all-clear at 02:33.

18m
Slow response · 14 Aug · 06:40 → 07:05 — served, but above your threshold
Illustrative dashboard · sample data
TLS certificate
18 days
studio.example
Expires2026-09-23
IssuerLet's Encrypt R11
GradeA
Domain
214 days
studio.example
Renews2027-04-08
Registrar lockOn
NameserversUnchanged
Email authentication
SPF
Pass
DKIM
Pass
DMARC
p=none
MTA-STS
None

Anything that couldn't be measured is shown as unknown — never counted as a pass.

Certificates & domains

The quiet expiries, caught early.

Certificates lapse at 3am and domains lapse on a date nobody wrote down. OrionCmd tracks both, plus the email records receivers use to authenticate your mail.

  • Certificate expiry, issuer and TLS grade from the latest observation.
  • Domain renewal date, registrar lock and nameserver changes.
  • SPF, DKIM, DMARC and MTA-STS, with unknown shown as unknown.
Findings you can act on

A finding, its next step, and a way to hand it on.

Every item explains itself in plain English and ends with something to do. When the fixing belongs to someone else, take the brief, the PDF report, or give the site owner their own read-only portal.

  • Plain-English explanation with the observation behind it.
  • A concrete next step — never just a severity score.
  • Copy a brief, export a report, or share a read-only portal.
Illustrative dashboard · sample data
Needs attention
Observed 2 hours ago · studio.example

Certificate expires in 18 days

The certificate served on studio.example is valid until 23 September. No replacement certificate has been served yet — renewal may be handled by your host, or may be left to you.

What to do next
  1. 01Check your host's certificate settings to see how renewal is handled.
  2. 02Renew or reissue now rather than waiting for the expiry date.
  3. 03Re-check here afterwards — a new reading is what marks it resolved.
Problem brief
PDF report
Customer portal
Copy the brief — the site, what was observed, what's been tried, what to do next.
When something goes wrong

From “something's off” to “it's handled.”

Knowing a site is down is the easy part. These four are about what you do next — and how you know it worked.

01

What needs my attention

One short list instead of a wall of readings. Each item says what was observed, when, why it matters, and what to do next — with the evidence behind it. Things we couldn't measure are shown as unknown, never quietly counted as fine.

02

Check my recent change

Moved host, changed DNS, renewed a certificate, touched your email settings? Tell us what you changed and when, and we compare the readings from before and after — what got worse, what got better, and where we simply don't have enough to say.

03

“They say it's fixed” — check again

Your host or developer reports it's sorted. Run the check again and see whether a new reading actually supports that. If nothing new could be measured, it stays unverified rather than being marked resolved.

04

A brief for whoever fixes it

One page you can copy or download: the site, what was observed and when, what's already been tried, the open questions, and what to do next. Hand it to your host, developer, or IT provider instead of retyping the story.

Illustrative dashboard · sample data
shop.example
Recovered
30-day uptime
99.4%
Downtime · 30d
4h 12m
Avg. recovery
18m
Last 30 days
30 days agoToday
HTTP 503 — service unavailable22 Aug · 02:14 → 02:32

Four consecutive checks failed. Recovered on its own after 18 minutes; a notice went out at 02:16 and an all-clear at 02:33.

18m
Slow response · 14 Aug · 06:40 → 07:05 — served, but above your threshold

OrionCmd reports what it can observe from the outside. It doesn't make changes to your site and can't promise a problem is solved — when the evidence isn't there, it says so plainly instead of guessing.

What we check

Three watch stations, and what each one can honestly see.

Passive-first monitoring, lightweight reachability probes, and optional authorized scans — each clearly identified as what it is, with its limits written next to it. These are the main checks rather than an exhaustive list, and your plan decides which of them run.

Monitoring & uptime

13
  • HTTP availability

    Timed status and keyword checks with anti-flap detection.

  • DNS resolution

    Continuous mapping of A, AAAA, CNAME and MX records.

  • Firewall endpoint watch

    External probes of expected or common TCP ports, plus an optional heartbeat if you configure a sender. Neither shows the appliance's internal health, and with no usable evidence the state is unknown rather than down.

  • SSL / TLS expiry

    Tracks certificate expiry and warns before the observed expiry; cannot guarantee renewal.

  • TLS grading

    Protocols, ciphers and chain analysis, graded A+ to F.

  • Domain expiry & integrity

    RDAP/WHOIS tracking plus nameserver and delegation change detection.

  • Email setup & blocklist checks

    Checks that your domain's mail records are in place and that it isn't on the Spamhaus or Barracuda blocklists. It does not test whether your email reaches the inbox.

  • Email authentication

    SPF and DMARC on Standard; DKIM, MTA-STS, TLS-RPT and BIMI on Pro.

  • Search indexability

    robots.txt and noindex header monitoring.

  • Homepage change detection

    Compares homepage hashes and reports content changed; it does not confirm defacement.

  • Threat reputation

    Looks your site up with Google Web Risk, falling back to Safe Browsing when that isn't available. If neither answers, the result is shown as unknown, not clean.

  • Passive web security

    CSP, HSTS, XFO, cookie flags and mixed-content validation.

  • Independent cloud check

    Optional separate evidence to compare with our own checks: a checker running on Cloudflare's network re-checks the targets you choose (up to 20) and reports back. It doesn't change your monitor status, uptime, grades or SLA — those come from the primary checks. You pair it in Settings, and it's one outside vantage point, not a worldwide probe network; when its evidence is missing or stale we say so.

Exposure & security scanning

12
  • Technology detection

    Identifies the software your site runs on from what it shows publicly. Versions aren't always visible, and anything we can't identify stays unknown rather than counted as safe.

  • Known-vulnerability matching

    Software we could identify precisely is looked up in public vulnerability databases (OSV.dev). Anything we couldn't pin down isn't matched, and isn't treated as clear.

  • Performance audit

    Lighthouse profiling via PageSpeed Insights.

  • Non-Intrusive Scan

    Comes with paid plans and stays off until you switch it on per site. Looks for exposed admin panels and misconfigurations; it never sends exploit payloads.

  • Passive Web Scan

    A deeper read-only OWASP ZAP review, on Pro. You switch it on per site and sign a scope authorization confirming the site is yours; we enable it before the first scan.

  • WordPress advisories

    If a site runs WordPress, the core version we can see from outside is checked for freshness and matched against Wordfence's published advisories. Plugins and themes the page refers to publicly are picked up too, and matched when their version is clearly readable; when it isn't, they're listed as found but unchecked rather than clear. Anything the page doesn't reveal stays invisible to us, and a feed we can't reach is reported as skipped. Runs with the paid scan layers once you switch scanning on for that site.

  • Internet-exposure watch

    A weekly look at what public internet-scan data (Shodan) already says about your addresses: services and ports visible from outside, and what changed since last week. It's someone else's observation, so a quiet week can mean nothing new was seen rather than nothing is exposed. Standard and Pro.

  • Subdomain discovery

    Passive OSINT — certificate-transparency logs and public sources are read weekly for names under your domain, so forgotten staging, admin and legacy hosts surface. Nothing is brute-forced, and a source that fails is shown as a gap, never as a clean result. Standard and Pro.

  • Lookalike-domain watch

    A weekly sweep for newly observed domains that look similar to yours. Looking similar doesn't establish abuse, so a match is a name to review rather than a verdict. The first sweep is a silent baseline; alerts start with names that appear after it. DNS decides what's real, so a name we can't resolve is inconclusive, not safe. Standard and Pro.

  • Candidate origin IPs

    For sites behind a CDN, we look for addresses that appear to answer for the site directly — possible origins to review. A candidate doesn't confirm it is the real origin or that the CDN can be bypassed. If a site isn't behind a CDN this simply doesn't apply, and it's never reported as safe. Standard and Pro.

  • Stealer-log exposure

    Checks whether your domain turns up in infostealer-malware logs — logins taken off infected computers, which is a different problem from a website being breached. It's a weekly check against a public source; nothing found means nothing was seen there, not that no device was infected. Standard and Pro.

  • Breach & paste exposure

    Have I Been Pwned lookups for the addresses you add, plus a domain-wide search once HIBP has confirmed you own the domain. Until that confirmation the domain-wide half stays unavailable, and a lookup we can't complete is reported as unknown rather than clean. Pro.

Platform & reporting

07
  • Automated reports

    PDF and HTML exports with plain-English incident explanations.

  • Public status pages

    Subscriber notifications and downtime reporting for a status page you publish.

  • Operator alerting

    Slack, Discord and webhook dispatch with configurable quiet hours.

  • Scan safeguards

    Optional scans stay off until you switch them on for a specific site, and each needs the right plan. The Passive Web Scan also needs a signed scope authorization confirming the site is yours, and we enable it before it can run.

  • Customer portals

    If you look after sites for other people, you can invite a customer to a read-only view of their own sites and reports — nothing from your other customers, and no ability to change settings or start scans. Clearing the invite takes the access away again. No extra plan needed.

  • Your customer's branding

    Each customer can carry their own name and logo on their reports, so what you hand over looks like your work rather than ours. A saved report keeps the branding it was generated with. There's no separate white-label add-on to buy.

  • PSA & ticketing

    Alerts can open tickets in ConnectWise Manage, Autotask, Syncro or Halo alongside your other alert channels. You supply that system's credentials, which are stored write-only; there's no extra tier for it, and a PSA that refuses a ticket is recorded as failed rather than quietly dropped.

Guides

Start with what you need to watch.

Short, practical guides to three common monitoring jobs.

Plans

One website free. Paid workspaces when you need the full watch.

A workspace is one business, not one URL. Extra websites or firewall endpoints are $5/mo each on paid plans.

Free

$0forever

1 website and 1 firewall endpoint.

  • Uptime & keyword checks
  • SSL / TLS expiry & grading
  • Domain expiry & DNS integrity
  • Email alerts
  • Public status page for your site (when you publish one)
Start free

Standard

$29per workspace / month

Up to 5 websites and 3 firewall endpoints.

  • Everything in Free
  • Reputation & homepage change watch
  • Exposure, subdomain & lookalike watch
  • Technology/advisory mapping, Non-Intrusive Scan, reports
Start with Standard

Pro

$79per workspace / month

Up to 15 websites and 10 firewall endpoints.

  • Everything in Standard
  • Full email authentication
  • Breach & paste exposure
  • Passive Web Scan, priority support
Go Pro

Compare every plan in detail

Questions, answered

Questions about OrionCmd.

Do I need to install anything?

For websites, nothing at all. Those checks run from the outside, the same way your visitors reach your site — no agents, no plugins, no passwords to hand over. Firewall endpoints are watched from outside too. The one optional extra is a call-home heartbeat for a firewall, which only reports in if someone configures a sender on your network; plenty of workspaces never set one up, and website monitoring doesn't need it.

What's included for free?

Uptime checks, SSL certificate tracking, and domain-expiry watch on one website and one firewall endpoint — free, with no time limit and no card.

What do paid workspaces add, and what do they cost?

Standard is $29 per workspace per month and covers up to 5 websites and 3 firewall endpoints. Pro is $79 per workspace per month and covers up to 15 websites and 10 endpoints. Extra websites or endpoints are $5/mo each. Paid workspaces add the security layers: mail-record and blocklist checks, threat reputation, exposure and subdomain discovery, known-vulnerability matching, scanning, and automated reports. Pro adds full email authentication, breach exposure, and the Passive Web Scan.

Will the checks slow down or harm my site?

Routine monitoring is designed to be lightweight and runs from outside your network. Firewall reachability probes common or expected TCP ports; a silent host may be offline or stealth-filtered. The Non-Intrusive Scan comes with paid plans and only runs on sites you switch it on for. The Passive Web Scan (OWASP ZAP) is on Pro: you switch it on per site and sign a scope authorization confirming the site is yours, and we enable it before it runs. Neither sends exploit payloads.

How do I find out when something breaks?

Checks run around the clock; when one spots trouble — downtime, a certificate about to lapse, a DNS change — we send an alert, and a follow-up once a later check sees it recover. Email by default, with Slack, Discord, and webhook options. Notices go to the channels you've set up, hold for your quiet hours, and still depend on the destination accepting and delivering them — so they're prompt rather than guaranteed.

I look after websites for clients — is this for me?

Yes. Pick "Websites I manage" when you sign up: sites are grouped per customer, each customer can get their own read-only portal, and reports go out per customer. Pick "My website" instead and none of that appears — you get the same monitoring with none of the extra structure. You can switch between the two whenever you like, and it changes nothing about your plan, your price, or who owns what.

Do you fix the problems you find?

No — and that's deliberate. OrionCmd tells you what changed, why it matters, and what to check first. The fixing stays with you or your IT person, so our alerts never double as a sales pitch.

Who can see my monitoring data?

Only you — and a customer only if you explicitly invite them to their own portal, where they see just their sites. Monitoring data is never sold or shared.

Know your website.

Add one address and the watch starts. No card, nothing to install, and a plain-English answer whenever something needs you.