Start your 7-day free trial, card not charged until it ends

Guide

How to monitor a website after a hack

To monitor a website after a hack, watch for the signs that came with the first attack: a Google malware flag, a changed DNS record, a new admin account, an exposed file or a page that looks different. TLDTrack checks each of these on a schedule once the site is clean.

Card not charged until your trial ends

01 · First

Before you start monitoring

  • Clean the site, or restore a backup from before the attack
  • Change every password: hosting, database, FTP and every admin account
  • Remove admin accounts you do not recognise
  • Update WordPress, plugins and themes, and delete the ones you do not use
  • If Google flagged the site, request a review in Search Console once it is clean

Monitoring tells you when something happens. It does not clean a site or block an attack.

02 · Steps

What to switch on

01

Malware monitoring

Your homepage address is checked against Google Web Risk twice a week for malware, phishing and unwanted software, with an alert when it is flagged and another when it clears.

02

Blacklist monitoring

The domain and its web server are checked against 12 spam blacklists every 12 hours, with an alert when either is listed.

03

DNS monitoring

Records are read every few hours. A changed A, MX or NS record raises an alert that names it.

04

The WordPress plugin

Alerts when an admin account is added, and when plugins are installed or removed.

05

Visual monitors on key pages

Compare the homepage and other key pages with a clean baseline, hourly to weekly.

06

Content checks

Alert when the login page is open to anyone, when debug output or placeholder text appears, or when a security header goes missing.

07

A security scan

Run one now the site is clean for a graded report on headers, TLS, exposed files and known vulnerabilities, and again after big changes.

03 · Signs

Signs it has happened again

Google

A malware or phishing flag

Browsers start warning visitors away from the site.

DNS

Records you did not change

A new A record, mail server or nameserver.

Admins

An account you did not create

Usually an administrator with an unfamiliar name or email address.

Pages

Content you did not add

Spam links, a new banner, a changed form.

Email

Mail landing in spam

A site sending spam can get its server blacklisted. TLDTrack checks the server your website runs on every 12 hours, and its email test shows whether the IP that sent a message is listed.

04 · Pricing

Simple, transparent pricing

Every paid plan starts with a 7-day free trial. Cancel during the trial and you won't be charged.

Free forever

Free

Monitor one site, free forever

$0/mo

1 website + 4 extra monitors

No credit card needed

  • Uptime checks every 5 minutes
  • Response time tracking
  • Domain expiry alerts
  • SSL certificate expiry alerts
  • Email alerts
Start free

7 days free

Starter

For individuals & small portfolios

$11/mo

Up to 5 websites

250 monitoring credits / month

  • Uptime, SSL, DNS & blacklist
  • Content & visual change monitoring
  • Accessibility (WCAG 2.2) monitoring
  • Email health & renewal alerts
  • PageSpeed & malware scanning
  • Free WordPress plugin
  • WHM & cPanel monitoring
  • Bulk import & export
  • Security, SEO & compliance scans
  • AI integration (Claude & ChatGPT)
Start free trial

Most popular

Pro

For active managers & agencies

$29/mo

Up to 25 websites

1,250 monitoring credits / month

  • Everything in Starter
  • Up to 5 team members
  • Client report builder
  • AI search visibility
  • Priority support
  • Security, SEO & compliance scans
  • AI integration (Claude & ChatGPT)
Start free trial

7 days free

Agency

For large portfolios & teams

$89/mo

Up to 100 websites

5,000 monitoring credits / month

  • Everything in Pro
  • Up to 20 team members
  • Agency CRM & white-label reports
  • Security, SEO & compliance scans
  • Dedicated support
  • AI integration (Claude & ChatGPT)
Start free trial

Bigger than 100 websites? Our Enterprise plan adds unlimited sites, custom data residency, an SLA, dedicated onboarding and custom integrations. Talk to us

*SMS alerts are an optional add-on on paid plans for UK mobile numbers, paid for with prepaid SMS credit packs. Prices exclude any applicable sales tax. Your card won't be charged during a paid-plan trial. Cancel anytime.

05 · Questions

Frequently asked questions

Will TLDTrack stop my site being hacked again?

No. It watches for the signs and alerts you, so you find out quickly. Prevention is down to updates, strong passwords, good hosting and a firewall.

Does it scan my files for malware?

No. It checks Google's threat lists for your domain. To look inside your files, use a malware scanner on the server.

How soon would I know?

DNS changes within a few hours, a malware flag at the next of the twice-weekly checks, a new WordPress admin at the plugin's next report (twice a day), and page changes on the schedule you set.

Should I run a security scan?

Yes, once the site is clean. It grades the headers, TLS, exposed files and known vulnerabilities, and the report lists the fixes. Scans are on Starter, Pro and Agency and use credits.
Mark Grice, founder of TLDTrack

Mark Grice, founder of TLDTrack. Runs FullyCoded, a Cornwall web agency, and built this to keep 500+ client sites in front of him every day.

What happens next

Keep watch on the site from today

Do it yourself

Start your free trial

Add the site, switch on the checks above and TLDTrack takes it from there. Your card is not charged for 7 days.

Start your free trial

Talk it through

Arrange a call with Mark

If you would rather talk through how this works across every site you look after, we can go through it together.

Book a call

See every check TLDTrack runs