How to use this tool

Site is OK? — User Guide
Table of Contents
1. Getting Started 2. Running Checks 3. Understanding Results 4. Account & Authentication 5. Saved Domains & Dashboard 6. Cached vs Live Checks 7. Email Alerts 8. Plans & Tiers 9. FAQ

1. Getting Started

Site is OK is a website infrastructure health checker. It scans any domain for common issues across HTTP, HTTPS, SSL certificates, DNS, email configuration (SPF/DMARC/DKIM), mail server blacklist reputation, domain registration, and security headers — then gives you a score out of 100.

You can run a check without an account. Just type a domain name and click Analyze.

Creating a free account lets you save domains, track their scores over time, and get a dashboard overview.

↑ Back to top

2. Running Checks

Quick check (no account needed)

From the dashboard (account required)

Tip: You don't need to type https:// or www. — just the domain name is enough.
↑ Back to top

3. Understanding Results

Score

The overall score (0–100) reflects the health of your domain across all checked categories:

Check Categories

Intrusive Checks

Some checks are marked ⚠ Intrusive because they actively probe the target server by requesting many paths (e.g. .git/HEAD, .env, index.php.bak). These checks are not run by default and are completely separated into their own ⚠ Intrusive tab. The scan page has two tabs — Standard and ⚠ Intrusive — placed above the scan input. Standard scans run by default; intrusive checks are a separate, manual action.

To run intrusive checks, first scan a domain in the Standard tab, then switch to the ⚠ Intrusive tab. Intrusive checks require a free account and a domain saved to My Domains — anonymous users cannot see or run them, and logged-in users can only see or run them for domains in their dashboard. A confirmation dialog explains the risks (extra requests, server stress, and the possibility that our scanner may be firewalled or blocked by WAF/CDN providers) and requires explicit consent before proceeding. Results appear in the same tab with a separate Intrusive Security score (out of 100) and categorized check sections with icons, similar to the standard scan.

Intrusive checks include:

Intrusive checks can trigger WAF alerts or rate limits on the target server, which may result in our scanner being firewalled or blocked. Only run these on domains you own or have permission to test. If our scanner gets blocked because of your scans, your account and anything connected to it may be banned from the site.

Intrusive checks are never run by scheduled (cron) checks — they are always a manual, one-time action. Intrusive results are stored separately from standard checks, so they persist independently. Cached intrusive results are only shown to logged-in users for domains saved to their dashboard.

Technology Detection

The tool also detects what technologies your site is built with (CMS, web server, etc.). Detected technologies are shown with a confidence badge:

Recommendations

At the top of the results, you'll see a summary of recommendations — actionable items sorted by severity. Click any recommendation to jump to the relevant check section for details.

↑ Back to top

4. Account & Authentication

Registration

Login

Password Reset

Invited Users (Admin-Created Accounts)

Email Verification

Account Settings

Click your email in the top right to access the Account Settings page, where you can:

Logout

↑ Back to top

5. Saved Domains & Dashboard

Adding a domain

Checking a saved domain

Removing a domain

Score badges

Each domain in the dashboard shows a colored score badge on the right:

Fleet Summary & Filters

At the top of the dashboard, a summary bar shows how many of your domains are healthy, warning, or critical, plus your average score across all checked domains. Use the filter tabs (All / Critical / Warning / Healthy) to quickly find domains that need attention. Domains are automatically sorted by urgency — critical issues appear first.

Graphs & Trends

Click the Graphs button on any domain to view visual trends over time:

Charts use server-rendered SVG — no JavaScript libraries — so they load instantly and work everywhere. The graphs page also shows an uptime percentage and average response time summary at the top.

Alert indicators

When issues are detected during scheduled checks, alert badges appear next to the domain name:

Email notifications use escalation tiers so you get reminded as the deadline approaches: SSL at 30, 14, 7, and 1 day(s); domain at 60, 30, 14, 7, and 1 day(s). Each tier crossing sends a new email.

These indicators update automatically after each scheduled check. Click the domain row to see full details.

↑ Back to top

6. Cached vs Live Checks

To avoid repeatedly pinging servers, the tool uses a caching system:

Note: Live checks take a few seconds because they connect to your server from multiple angles (HTTP, HTTPS, SSL, DNS, RDAP). Cached results load instantly.
↑ Back to top

7. Email Alerts

When email sending is enabled, the system sends automatic alerts for issues detected during scheduled checks:

Alerts are sent at most once per domain per alert type within a 24-hour window to avoid duplicate notifications. You'll receive an email at the address registered on your account.

Notification Preferences

You can customize how alerts are delivered from the Account Settings → Notifications section:

Deliverability: To ensure emails reach your inbox (not spam), make sure the sending domain has SPF, DKIM, and DMARC DNS records configured. Check your spam/junk folder if you don't receive expected emails, and mark them as "not spam" to whitelist the sender.
↑ Back to top

8. Plans & Tiers

There are three plans available. The plan determines how many domains you can save and monitor:

Anyone can scan any domain for free without an account. The tier limit only affects how many domains you can save for ongoing monitoring.

Plan details and prices are on the Pricing page; once signed in, your current plan, domain usage, and billing history are on the Billing page. You can upgrade, switch, or cancel your subscription at any time. Payments are processed securely via our payment provider.

When you reach your domain limit, the Add Domain form is disabled and an upgrade prompt appears on the My Domains dashboard.

Upgrading (Free → Paid): Click the "Upgrade" button on any paid plan card, choose monthly or yearly billing, and complete checkout on our payment provider's secure page.

Switching plans (Paid → different Paid): If you already have an active subscription, clicking "Switch to" or "Upgrade to" on another plan triggers an instant plan switch — no checkout page. The proration is handled automatically: upgrades charge the prorated difference immediately, downgrades refund unused time. You can switch plans at most once every 6 hours.

Cancelling: Use the "Cancel Subscription" button in the Manage Subscription section. Your subscription remains active until the end of the current billing period, then your account is automatically downgraded to the Free plan.

You will receive a confirmation email from us for each billing event: new subscription, plan switch, and cancellation. (Our payment provider also sends their own receipt and refund emails.)

Paid subscriptions have an expiration date. If your subscription expires or is cancelled, your account is automatically downgraded to the Free plan (1 domain). If you have more than 1 domain saved, the extra domains remain in your list but you won't be able to add new ones until you upgrade again.

Pro and Business plans also include change history — a timeline of what changed between checks for each domain (SSL issuer, DNS records, security headers, score, and more). Click the "History" button on any domain in your dashboard to view it.

The Business plan also includes weekly email reports — every Monday you receive a summary of all your monitored domains: current scores, SSL/HTTP/HTTPS/DNS status, any expiring certificates or domains, and all changes detected in the past 7 days. The report is sent to your notification email (or account email if no override is set).

↑ Back to top

9. FAQ

Do I need an account?

No. You can run one-off checks without registering. An account is only needed to save domains and track them over time.

Is my data shared?

No. Your account and saved domains are private. Check results are stored only for your reference.

How often should I check my domains?

Saved domains are checked automatically once a day via a scheduled job. You can also run a live check manually at any time from the dashboard or the scan page. Email alerts are sent automatically when issues like SSL expiration, domain expiration, DNS problems, or site downtime are detected.

The score changed between checks — why?

Scores reflect real-time conditions. SSL certificates expire, DNS records change, servers go down temporarily. A lower score on a live check vs a cached one usually means something changed since the last check.

My domain shows "no DNS records found"

This means the domain doesn't exist or has no DNS configured. Double-check the spelling — make sure you entered the domain without http:// or paths.

↑ Back to top