Your company workspace

Welcome to Watch.Opening Watch…

Your company account. One sign-in for all your tools.

Checking your session…

Your Hub checks your access and brings you straight back here.

Access is managed by your company in the Hub.

DOMAIN MONITORING

Keep your domains in sight.

Changes to review. Risks to resolve. Everything else, quietly watched.

Loading monitoring status…
Loading domains…

DNS and domain security checks · What Watch checks ↗

← Domains

NEW DOMAIN

Start watching.

Add a domain or subdomain. Watch records its first answers and checks for changes.

Notifications & record types

Recipients use Hub notifications. Admin alerts follow your Watch settings.

Record types
Cancel

← Domains

DOMAIN

Loading…

DNS records

Review unexpected changes before accepting a new baseline.

Security checks

HISTORY

Activity

What changed, what was checked and what your team decided.

REPORTING

Reports & evidence

A record of your monitoring, ready for reviews and audits.

Monthly reports

Evidence export

Domains, events, checks and reports in one spreadsheet-safe CSV.

Current monitoring summary

Check history
WhenDomainsChangesCheck problemsStarted by

CONFIGURATION

Settings

Set the pace. Choose who hears about changes.

Monitoring & notifications

Domain watchers also receive alerts. Delivery uses Hub notifications and each person’s Slack preferences.

Trusted hosting operators advanced

New IP addresses belonging to a trusted operator are learned without an alert. Use specific operator names: matching is case-insensitive and accepts partial names.

App details
Loading settings…

Hub connection

Hub owners and admins manage Watch. A Watch Viewer can read all monitoring; other employees have no access by default. Manage access in Hub ↗

Connection checks

The test sends a notification to the current Watch admins and you. It does not change DNS records.

Admin activity
WhenWhoAction

A QUICK GUIDE

How Watch works

Know when a domain needs you. Keep the evidence of what you did.

01

Add your domains

The first check records the starting DNS answers. Add colleagues who should receive alerts for a domain.

02

Review what changes

Open a domain that needs attention. Accept an expected DNS change, or fix it with your DNS provider and check again.

03

Keep the record

Activity keeps the history. Monthly reports and CSV exports help explain your monitoring and decisions.

Know what needs action

Review change
A confirmed DNS answer differs from the accepted baseline. Check who made the change before accepting it.
Fix DNS
A name or its target no longer exists. Fix it with your provider; accepting a change cannot repair it.
Check unavailable / overdue
Watch could not verify current information. This is a monitoring gap, not proof that your website is down.
Review security
A mail policy, registrar lock or other check needs attention. Open the domain for the specific finding.
Paused
Scheduled checks are off. Previous findings remain visible on the domain page.
What is checked, and when?

DNS answers come from Cloudflare and Google every 5–120 minutes, as configured. Registry expiry, DNSSEC indicators, transfer locks, mail policies (DMARC, SPF, MTA-STS), CAA and public certificate logs are checked daily. Selected lookalike names are checked weekly.

A and AAAA keep a set of known IP addresses. During the first 48 hours, and for explicitly trusted operators, new addresses can be learned automatically. New addresses at the same known operator are learned with a notification to review them; unfamiliar operators require acceptance. Other record types use an exact accepted answer set. Resolver disagreement is shown while answers settle.

Only the record types you select are monitored. A domain has its own alert recipients; company-wide administrator alerts are controlled in Settings. Hub access is configured centrally.

Certificates, limits & data handling

Certificate dates come from public certificate transparency logs. They do not verify the certificate currently served by your website. Failed checks retain the last successful evidence and are marked unavailable; certificate retries are spaced by at least three hours.

Watch does not test website uptime, repair DNS or renew domains. DNSSEC is inferred from resolver validation flags. Registry data, mail-policy checks and lookalike coverage can be incomplete; findings need operator review.

HTTPS lookups send monitored domain names and IP addresses to public resolvers, RDAP services and crt.sh. Those names may reveal internal projects. Removing a domain stops monitoring but keeps its historical events for evidence.

Watch 0.9.0 · Release notes ↗