Šis straipsnis kol kas prieinamas tik anglų kalba.
Pasiekiamumas, TLS galiojimas, PageSpeed, SEO regresijos, DNS pokyčiai, el. pašto autentifikavimas ir slapukai — kaip dažnai tikrinti kiekvieną.
Monitoring means something different to a small agency than it does to a large company. The large company has one system and a rota. You have thirty client sites, each on its own hosting, with its own domain, its own WordPress and its own person who switched something on two years ago. Nobody is paying you to watch them. And yet, when something falls over, the phone call comes to you.
So the question is not “what can be monitored” but “what is worth monitoring without generating noise”. Below is our answer — in the order we would switch things on, with an honest note about how often each check actually needs to repeat.
Nine things worth watching
| What | How often | Why that interval |
|---|---|---|
| Uptime | Minutes | A delay here costs money directly, minute by minute. |
| TLS certificate expiry | Daily | Auto-renewal breaks quietly; you want to know weeks out, not on the day. |
| Security headers | Weekly | They only change with a release or a server config edit. |
| PageSpeed | Daily | The measurement is noisy; the trend matters, a single run does not. |
| SEO | Weekly | Regressions arrive with content, not with code. |
| DNS records | Daily | An unexpected change is either somebody else’s work or a hijack. |
| Email authentication | Weekly | SPF and DMARC break when a new sender is added. |
| Cookies and consent | Monthly | It changes when marketing adds a new script. |
| Reputation and malware | Daily | A blacklisting stops email and search traffic. |
Uptime: more often is not better
The uptime check is the simplest one, and high frequency genuinely pays off there in a way it rarely does elsewhere. But the value is not in the ping — it is in the fact that results are stored. When a client says the site “was down all day yesterday”, you need history, not a feeling. On our side there are currently more than 44,000 uptime checks on record, and that history is what they are for.
Two things to set up straight away. First, check a page that actually does something: the home page can answer 200 while the cart is broken. Second, do not trust the status code alone — a page returning 200 with an empty body is technically working.
Certificates and headers: rarely change, expensive when they do
A TLS certificate expiring is the one incident you can see coming three months ahead and which still happens regularly. Let’s Encrypt automation breaks silently: the webroot path moves, renewal fails for two months, and nobody finds out.
Security headers are the same category. They do not change on their own, but they disappear along with a server migration. Our security scan checks HSTS, Content-Security-Policy, X-Frame-Options and the rest, evaluates the TLS configuration and produces a 0–100 score with a letter grade. Once a week is plenty — what matters is that somebody notices when the grade drops from B to D.
SEO regressions: the code is not the culprit
The most painful SEO failure we have seen is a single checkbox: a site going live with “discourage search engines” still enabled from development. Nobody notices until traffic has halved six weeks later.
Which is why an SEO audit should be treated as a regression test, not as consultancy. What it checks is boring on purpose: are the title and description still there, has the heading structure collapsed, does the canonical point where it should, is the page indexable at all, do images have alt text, do robots.txt and sitemap.xml answer. Weekly is enough, because these things are changed by the people writing content, not by the server.
DNS, email and reputation
DNS monitoring is a simple idea: record what the A, AAAA, MX and NS records are, and say something when they change. Nine times out of ten the change is legitimate — someone moved the hosting and forgot to tell you. The tenth case is the reason you watch it at all.
Email authentication is the close relative. SPF, DKIM and DMARC are not a set-once affair: they break the moment a client starts sending through a new system and nobody adds that sender to the SPF record. The result is that enquiry mail lands in spam, and the agency hears about it a month later. Weekly is often enough, unless you know somebody is changing something right now.
Blacklists and malware belong to the daily rhythm. If foreign JavaScript is injected into a site, or the domain lands on a reputation list, every day means lost traffic and blocked mail. Our malware scan renders the public page in a real browser and looks for exactly what tends to get injected: unfamiliar scripts, cryptominers, hidden frames and redirects. It is a black-box check — it sees what a visitor sees, not the files on your server.
Alert hygiene
Monitoring does not die from bad measurements. It dies from noise. If a page is down for an hour and the check runs every minute, a system that alerts on every check will send sixty emails — and next time you will not read them.
One rule is worth following: alert on the state change, not on the state. One message when a service goes from fine to broken, and one when it comes back. That is exactly how our alerts work, and it is the same reason the SMS channel is separate: a text message is more expensive and more intrusive, so it belongs to uptime rather than to an SEO warning.
Turning it into revenue
Monitoring by itself is not a product for a small client — nobody pays for a chart. But a monthly report showing that the site was up, the certificate renewed, the speed did not drop and no new issues appeared is the same maintenance retainer, only with evidence attached. The thirteen services in Bugzio exist for exactly that: each project switches on what it needs and the rest stays out of the way.
Somewhere to start without an account
Run the free website test against one client domain — security headers, SEO and performance in one report. If the result looks like work you would rather repeat every month, there is a 14-day trial.