Start your 7-day free trial, card not charged until it ends

Case study · Customer zero

The agency that needed TLDTrack so badly, it built it.

FullyCoded runs 500+ client websites, from multi-million-pound e‑commerce to local government. TLDTrack is how one team stays in front of all of them, every day.

500+

client websites under daily management

18

years running the agency, learning the hard way

4

sectors: e‑commerce, government, charity, SME

1

dashboard where every site, check and alert lives

01 · The agency

Three hundred sites, each one somebody's livelihood

FullyCoded is a working UK web agency. Over 18 years it has become the team responsible for more than 300 client websites: e‑commerce stores turning over millions, local government services residents depend on, charities whose donation pages fund real work, and small businesses where the website is the business.

That mix matters, because every sector breaks differently. E‑commerce feels an outage in pounds per minute. Government feels a defacement in headlines. A charity feels a broken donation form in silence, nothing errors, the money just stops. And an SME often has nobody checking at all. Except us.

Nobody can look at 300 websites every day.
So something else has to.

02 · The problem

The patchwork always leaks

Like most agencies, we tried the patchwork: an uptime tool here, a renewals spreadsheet there, browser bookmarks for SSL checkers, and institutional memory for everything else. Even a superficial manual pass, is it up, is the certificate fine, does the homepage look right, takes minutes per site. Multiply by 300 and "we check everything weekly" is a full-time job that still misses whatever broke an hour after you looked.

The deeper flaw is structural. Each tool watches one layer, and real incidents live in the gaps between the layers: a site that is "up" with a hijacked DNS record, a store that is "up" behind a full-screen certificate warning, a page that is "up" and quietly hosting someone else's pharmacy links.

03 · The tool

Built between client projects, because nothing we could buy covered the job

TLDTrack started as internal tooling, written to watch the things that had actually burned us. That origin still defines it: every check exists because something once broke on a real client site. Uptime with retries, because shared hosting throws false alarms. DNS baselines, because third parties edit records and tell nobody. Renewal tracking, because expiry emails go to inboxes that no longer exist. Content and visual monitoring, because "up" and "right" are different things.

Eventually it was watching our whole portfolio better than any combination of tools we had ever paid for. So we productised it. But first, and still, it is how we run our own agency.

04 · The daily rhythm

What "daily tool" actually means

TLDTrack is open on our screens every working day. The rhythm, across 500+ sites:

The morning sweep

One dashboard answers the first question of the day: is anything wrong anywhere? Overnight alerts arrive pre-triaged by severity, so the day starts with facts instead of fifty tabs.

Alerts that interrupt properly

Down or blacklisted goes straight to push and email. Certificate warnings arrive in one digest email. Noisy items get muted individually, never a whole site switched off.

Renewals with no surprises

Every client domain and certificate expiry in one list, alerted weeks ahead, whoever the registrar is. A domain cannot quietly expire now without weeks of warnings first.

DNS with a baseline

A baseline of the main records on every domain (A, AAAA, MX, NS, CNAME and TXT), checked every 3 hours, and an alert naming the record that was added or removed when anyone edits one. DNS monitoring ends the archaeology.

Eyes on the pages that matter

Content and visual monitoring watch homepages, checkouts, donation forms and legal pages, so a broken embed is a same-day fix, not a client phone call.

Security on a schedule

Blacklist checks run twice a day and malware checks twice a week, and we run security scans on demand. For government and e‑commerce clients, "we would have noticed eventually" is not an answer.

05 · From the incident log

Four saves that paid for the whole system

Details anonymised. The patterns will be familiar to any agency.

01

E‑commerce

The certificate that "renewed itself", until it didn't

A high-turnover store's certificate automation broke silently after a hosting change. The 14-day expiry alert bought two calm weeks to fix the renewal chain, instead of an emergency at the moment every visitor hit a full-screen browser warning mid-checkout.
02

Local government

The DNS edit nobody mentioned

A third-party IT supplier changed DNS records on a council domain without telling anyone. The change alert landed within hours, naming the exact records, and mail flow was protected before anything bounced. Without the baseline, that becomes days of "what changed?" archaeology.
03

Charity

The donation page that failed silently

A CMS update knocked out a charity's third-party donation embed. The page returned a perfect 200; the giving just stopped. The content check flagged the missing widget the same day, ahead of a campaign weekend that would otherwise have run against a broken page.
04

SME

The hack caught before the customers saw it

A compromised plugin started injecting spam links into a small firm's site. Content monitoring flagged keywords that had no business being there; the site was cleaned, patched and through a Safe Browsing review before the client, or Google, would ever have noticed.

06 · The lessons

Eighteen years, three rules

Find out before the client does.

Almost any incident is survivable, and often relationship-strengthening, if your first message beats their first phone call. Detection speed is the whole game; everything else is process.

Silence is not safety.

The expensive failures were rarely loud outages. They were quiet drifts: records edited, embeds vanished, certificates lapsing, mail failing softly. Monitor only for "down" and you are watching for the least likely disaster.

Evidence ends arguments.

A recorded history of what changed and when, on every site, has settled more difficult conversations than any contract clause. "Here is the change, here is the timestamp, here is the fix" is trust, manufactured daily.

07 · Mark Grice

From the founder

“We didn't build TLDTrack to sell monitoring. We built it because we needed it, and after 18 years of running client websites we knew exactly what needed watching.”
FullyCoded

Mark Grice

Founder, FullyCoded

Full disclosure: TLDTrack is our product, and this is our own story. That is rather the point. We are the customer it was built for, and it runs our agency every day.

TLDTrack
FullyCoded
Mark Grice, founder of TLDTrack

Mark Grice, founder of TLDTrack. Runs FullyCoded, a Cornwall web agency, and built this to keep 500+ client sites in front of him every day.

What happens next

Run your agency the same way

Do it yourself

Start your free trial

Add your client sites and get the same nine layers of monitoring we rely on. Your card is not charged for 7 days.

Start your free trial

Talk it through

Arrange a call with Mark

If you would rather talk through how this works across every site you look after, we can go through it together.

Book a call

See TLDTrack for agencies