Whether it is written into the contract or not, your clients assume you are watching their websites. When something breaks, "we didn't notice either" is not an answer an agency can give twice. The awkward truth is that at most agencies, monitoring means waiting for the client to phone.
This guide covers what monitoring client websites actually involves: the nine things worth checking, how often to check them, how to set up alerting that does not bury you in noise, and how to turn the whole thing from an unpaid anxiety into a paid service.
Why monitoring client sites is different from monitoring your own
Monitoring one site you know inside out is easy. Client monitoring is a different problem for three reasons:
- Scale. An agency looks after 20, 50 or 300 sites across different hosts, registrars, DNS providers and CMS versions. Anything manual stops happening within a month.
- You did not make every change. Clients edit pages, marketing teams install plugins, a different contractor touches DNS. You are accountable for a system you do not fully control, so you need to know when it changes.
- The stakes are reputational. When your own site goes down you lose sales. When a client site goes down and they find out before you, you lose the client.
The nine things to monitor on every client site
1. Uptime
The baseline. An automated check should request each site every few minutes from outside your network and alert you when it stops responding or starts returning errors. Good uptime monitoring also retries before alerting, because shared hosts and CDN edges throw transient errors that are not real outages.
2. SSL certificates
An expired certificate does not take the site down, it does something worse: every visitor sees a full-screen browser security warning. Renewal automation fails silently more often than most people think, so monitor expiry dates and alert well ahead, at 30, 14 and 7 days.
3. DNS records
DNS changes are rarely announced and often wrong. A record edited by a client's IT contractor can move mail flow, break subdomains or point the site somewhere else entirely. DNS monitoring keeps a baseline of every record and tells you exactly what changed, when.
4. Domain renewals
The most preventable disaster in the industry: a domain quietly expires because the renewal email went to an ex-employee's inbox. Track expiry dates for every client domain in one place, with alerts long before the deadline, whoever the registrar is.
5. Email deliverability
SPF, DKIM and DMARC records break when providers change or someone edits DNS carelessly, and the symptom is invisible: mail silently lands in spam. Email health monitoring catches authentication failures before the client notices their enquiry forms have gone quiet. You can spot-check any domain now with our free email deliverability checker.
6. Blacklists and malware
A hacked site often stays online and looks normal to the owner while serving spam or malware to others. By the time Google flags it, traffic has collapsed. Malware and blacklist monitoring checks each domain against the major blocklists continuously, and deeper security scans catch the weaknesses before they are exploited.
7. Content changes
Defacements, injected spam links, a client accidentally deleting half a page, a payment provider's embed disappearing: all invisible to an uptime check. Content monitoring watches keywords, metadata, links and the tech stack on pages you care about and flags unexpected changes.
8. Visual changes
A plugin update that breaks a layout returns a perfect 200 status. Visual monitoring compares the rendered page against a baseline and alerts when what humans actually see has changed.
9. Performance
Sites get slower gradually: an unoptimised hero image here, an extra tracking script there. Nobody notices day to day until rankings and conversions sag. Scheduled PageSpeed and Core Web Vitals checks turn the slow decay into a visible trend line you can act on, and bill for fixing.
How often should each check run?
Not everything needs a one-minute interval. A sensible tiering:
| Check | Frequency |
|---|---|
| Uptime | Every 1 to 5 minutes |
| SSL expiry | Daily, alerts at 30/14/7 days |
| DNS records | Hourly to daily |
| Domain expiry | Daily, alerts weeks ahead |
| Email authentication | Daily |
| Blacklists and malware | Daily |
| Content and visual | Daily, or hourly on critical pages |
| Performance | Weekly trend checks |
Alerting that does not drown you
The failure mode of most monitoring setups is not missing problems, it is alert fatigue. Fifty sites each sending well-meaning notifications quickly trains everyone to ignore the channel. Three rules keep alerting useful:
- Route by severity. Site down or blacklisted goes to push and email immediately. A AAAA record changing on a brochure site can wait for the daily digest.
- Mute per item, not per site. If one noisy record or one flaky third-party script keeps alerting, silence that specific item rather than switching off monitoring for the whole site.
- Demand retries before "down". Shared hosting and CDN edges return transient errors constantly. A monitor that retries before alerting saves you from chasing ghosts.
Make it part of the retainer
Monitoring is one of the highest-margin services an agency can sell, because the marginal cost per site is small and the value to the client is obvious the first time you call them about a problem they did not know they had.
Package it explicitly: name the checks, the alert response times and a short monthly summary in the client's language. "We watched your site 43,000 times last month, caught one certificate about to expire and fixed it before anyone saw a warning" is the easiest renewal conversation you will ever have.
Spreadsheets, point tools, or one dashboard
Most agencies drift into a patchwork: a renewal spreadsheet, a free uptime tool, an SSL checker someone bookmarks, and manual glances at the rest. Every extra tool is another login, another gap, another thing that only one person knows how to read. The alternative is consolidating the checks into a single dashboard with one alerting pipeline, which is exactly what TLDTrack does for agencies. For a concrete comparison against the single-check approach, see TLDTrack vs UptimeRobot.
Getting started this week
- List every domain you are responsible for, including the ones you inherited and the ones you only "sort of" look after. This list is always longer than expected.
- Record registrar, DNS provider, host and expiry dates for each.
- Switch on automated uptime, SSL and DNS monitoring for all of them. This is the highest value per minute of setup.
- Add blacklist, email, content and visual checks on the sites where breakage costs real money.
- Decide your alert routing and write down who responds, and how fast. If you need a starting point, we published a step-by-step outage response plan.
Once the checks run themselves, monitoring stops being the thing you feel guilty about and becomes the quiet backbone of every maintenance retainer you sell.
