Tell Me When Down
How it worksWhat we checkPricing
BlogFree toolsCompareDocs
Log inGet started
All posts
Security checks

Shipping securely on a budget

Free ways to check a site before and after launch — security headers, SSL, leaked secrets, and the launch checklist nobody hands you.

A hand holding a clipboard and document in dim light — the pre-launch review nobody is handed.
Security checks·July 18, 2026·6 min

The website launch security checklist nobody hands you

You get a deploy button, not a checklist — so most sites launch with the cert valid and nothing else checked. The four things to test from your URL in seconds, plus the code-side items that cost the most.

A weathered padlock on a dark iron gate — the certificate that secures a site, lapsed.
Security checks·July 18, 2026·5 min

Website down from an expired SSL certificate

An expired certificate is a full outage — every visitor hits a red warning, though the server's fine. Here's why auto-renewal still fails silently, why shrinking cert lifetimes make it likelier, and how to see it coming.

An unlocked padlock in low light — a site served without a private, secure connection.
Security checks·July 18, 2026·5 min

My website says "Not Secure" — what it means and how to fix it

The "Not secure" label looks like a hack but usually isn't — it means your site isn't using HTTPS properly. Here's what the browser is really saying, and the common causes in plain language, fixed one by one.

An ornate iron gate with a lock in low light — protections telling the browser how to behave.
Security checks·July 18, 2026·5 min

What are security headers? A plain-English guide

Security headers tell the browser how to behave safely — refuse HTTP, block framing, don't guess file types. Here's what each of the ones that matter actually does, and why almost every new site ships without them.

A control panel of switches in low light — protections configured to travel with every response.
Security checks·July 18, 2026·6 min

How to add security headers in Next.js (including CSP)

Next.js sends no security headers by default. The static ones are a config block; the hard part is a CSP that helps without blocking your own scripts. Here's the nonce approach, the report-only trick, and the version caveat.

A calendar page fading into shadow — expiry dates arriving faster than a manual reminder can track.
Security checks·July 18, 2026·5 min

SSL certificate expiry monitoring: why the calendar reminder fails

A calendar reminder assumes your renewal works. But auto-renewal is a background job that fails silently, and cert lifetimes are dropping to 47 days by 2029. Here's why manual SSL tracking breaks, and what to monitor instead.

A single cookie lit on a dark surface — a session token that's only as safe as the flags set on it.
Security checks·July 18, 2026·5 min

Secure, HttpOnly, SameSite: the cookie flags that matter

Three small flags — Secure, HttpOnly, SameSite — decide whether your session cookie is a locked token or the easiest thing to steal on your site. Here's what each closes, and how to check which your cookies set.

more topics
Free-tier sleepSilent cronStripe webhooksVibe securitySite down
Tell Me When Down

Uptime and security monitoring for people who'd rather ship than babysit servers. We watch so you can sleep.

product
How it worksWhat we checkPricingDocsBlogFAQ
free toolsWebsite security scanSupabase pause checkRender sleep checkMixed content checkerSecurity headers checkCookie security checkSSL expiry check
comparevs UptimeRobotvs Better Stackvs PingdomFor indie hackers
company
StatusAbout our botSupportPrivacyTerms
© 2026 TellMeWhenDown · tellmewhendown.com